Hello all! I'm just getting started with graph ql ...
# orm-help
m
Hello all! I'm just getting started with graph ql and prisma and wondering if anyone can point me in the right direction to understanding security best practices with a prisma / yoga back end ? I'm so used to rest and everything feels a little foreign right now. I'm starting a big project in a little over a month and I'd love to get to a point where I'm confident enough to use a graph-ql setup!
I just read through this which certainly clears up some questions. Is this the consensus approach? https://www.prisma.io/blog/graphql-directive-permissions-authorization-made-easy-54c076b5368e/
One thing I still don't quite understand is if for example we have a type of Courses which has relationship to user (the user who created the course). We want to allow unauthenticated queries from the front end that fetch a list of all courses as well as the name of the associated user, but not allow the user email / other private data to come through with the response. How would one go about this ? Apologies for the beginner questions. I'm still just trying to get my head around the core concepts :)
f
Hi! This might be useful if you want to do auth with directives: https://github.com/frandiox/vue-graphql-enterprise-boilerplate The frontend is in Vue. Backend is apollo v2 + Prisma