Looks very cool - How do you see permissions/roles/authenticated access being managed for APIs where say most gets are public but most puts and a few gets are private? (I apologize if I missed that in the intro)
The GraphQL data layer then ensures that the generated SQL query is intersected with those constraints for every node being resolved.
This is works out well for performance also because you don’t have to proxy to the GraphQL proxy.
The Graphcool Framework uses an approach similar to what Hasura is doing, but there are many use cases where this is simply not flexible enough.