I do wonder how the rise of technologies such as GraphQL have impacted this over the years. It’s obviously a big problem with REST APIs as well but the way I would think about securing it is fairly well understood I think.
I don’t have the experience with GraphQL to know any better but from my brief exposure they seem like they might be particularly vulnerable to this kind of thing and I was hoping someone here might be able to tell me if that intuition is true or not.