Edit: my viewpoint is applicable to public APIs. If your client(s) and your backend are under your control, then GraphQL is useful.
> The solution to ad-hoc queries is to not use ad-hoc queries. Persisted queries are becoming common.
So, you either reinvent REST, or fall prey to ad-hoc queries with potentially unlimited complexity.
Also, persistent queries don't save you from unlimited complexity when those are automatically persisted, which is what Apollo offers.
> Caching is no harder in GraphQL than it is anywhere else. You define resolvers; if you want to put stuff in Redis, you're free to do so.
Putting stuff in Redis does not make it caching.
> You have complete control over what happens in a resolver, which includes authorising access and throwing an error/returning null/etc.
So, you throw an error in a deeply nested resolver in an ad-hoc query with unknown complexity, and .... this is "no harder"?