A GraphQL resolver must authorize every field
Authenticating the HTTP request that carries a GraphQL query is not enough.
Each field resolver that returns sensitive data or mutates state needs its own authorization check for that actor, object, a
authbyexample.hashnode.dev1 min read