How does this access control play with cache? What happens when the access control rules change?
A while ago, I wrote a real-time REST-based plugin which solves all the problems and I use it in production, it's much simpler than GraphQL. See https://github.com/SocketCluster/sc-sample-inventory
I'm surprised that more libraries aren't following the REST-based model.