graphile / graphile/graphile.github.io

Recipe: Creating a viewer/"logged in user" root field

Open
#67 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
SCSS
Stars
27
Forks
126
PR merge metrics
No merged PRs in 30d

Description

Here's another proposal for a very simple recipe. Again, feel free to do what you want with this.

## Creating a viewer/"logged in user" root field
A lot of API:s use the "viewer" convention, putting a field on the root query that references the currently logged in user. If you have your authentication set up properly and a have a way of getting the currently logged in user's user id, you can do this very easily with Postgraphile:

```sql
create function my_schema.viewer()
returns my_schema.users as $$
select *
from my_schema.users
where id = current_user_id(); /* current_user_id is a function that returns the logged in user's id, usually by extracting it from the auth token used */
$$ language sql stable;
```

This will put a field (viewer) on your root query that returns the logged in user. Very convenient! Check out the docs on security for handling authorization and adding a current_user_id function.

Contributor guide

No contributing guide indexed for this repository

Research direction

Review this proposal alongside the existing security documentation it references and the site's current recipe organization. Add a recipe explaining the viewer root field, including the shown SQL pattern and its authentication assumptions; done means the recipe is published in the appropriate documentation location and links to the relevant security guidance.

Written by the indexing model from the issue text.

Assessment

Tech stack
graphql, sql
Domain
documentation
Issue type
Documentation
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.