This is one of the most laughable critiques I've read.
> "First of all, GraphQL is almost the equivalent of allowing the frontend client to send SQL to the database. For crying out loud, we’ve got a name for that, and it’s called SQL INJECTION ATTACKS."
GraphQL is a specification, it doesn't imply an implementation.A GraphQL "resolver" is identical to the concept of an "endpoint", you have no idea what the business logic inside of an endpoint is. That's up to the implementer.
> "I know it is possible to apply security to your GraphQL endpoints, by amputating half of its features. However, security is one of those things you need by default. If some piece of tech doesn’t have “security by default”, you don’t expose it to anybody not having root access to your server infrastructure, period!"
No API specification I am aware of comes with "security by default", again, that's an implementation detail?It's to you to add AuthZ/AuthN to your REST/RPC/GQL etc API, by themselves the handlers are just dumb networked functions.
> "Second of all, GraphQL forces you to write business logic on the client. This implies that everyone with a Postman account can circumvent your business logic, and potentially empty your bank account, and transfer your entire holdings to their own account, in Bermuda, while publicly sharing images on Instagram that they’re drinking umbrella drinks from their hammocks on the beach."
I really don't have anything to say on this.I guess the implication is that you have somehow exposed your entire database with zero access controls via GraphQL and don't know how to write resolvers?
In that case, I'm more concerned for your employer than your angst against GQL, lol.