graphql-dotnet / graphql-dotnet/authorization

Cannot use @include or @skip to strip unauthorized fields from a query

Open
#29 2 comments 1 reaction 0 assignees View on GitHub
enhancement
Dominant language
C#
Stars
160
Forks
38
PR merge metrics
No merged PRs in 30d

Description

Should `AuthorizeWith` report an error if a field the user isn't authorized for is excluded from the query via the `@include` or `@skip` directives? (It currently does.)

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.