Results will appear here.
What is GraphQL Introspection + Missing Field-Level Authorization?
GraphQL APIs expose a single endpoint that answers whatever query you send it. Introspection lets any client ask the API to describe its own schema — every type, every field. Missing field-level authorization means the API checks whether you're allowed to query a type, but never whether you're allowed to see a specific field — so anyone who asks for a sensitive field by name gets it back.
Why is This Dangerous?
Front-end applications only request the fields they display, which creates a false sense of safety. "The UI never shows that data" is not the same as "the API won't return that data." Anyone willing to bypass the UI and talk to the API directly can request fields the UI never asked for — including internal notes, audit flags, or data never meant to leave the backend.
How to Prevent This?
- Disable introspection in production environments
- Enforce authorization at the field resolver level, not just the type or endpoint level
- Treat every field in the schema as something a determined caller could request directly
- Never rely on the front-end's query shape as a security boundary