One thing I still don't quite understand is if for example we have a type of Courses which has relationship to user (the user who created the course).
We want to allow unauthenticated queries from the front end that fetch a list of all courses as well as the name of the associated user, but not allow the user email / other private data to come through with the response. How would one go about this ?
Apologies for the beginner questions. I'm still just trying to get my head around the core concepts :)