Skip to content
This repository was archived by the owner on Feb 13, 2022. It is now read-only.
This repository was archived by the owner on Feb 13, 2022. It is now read-only.

GraphQL authorization #419

Description

@gskierk

Hello,

What is recommended way to add authorization logic to Siler\GraphQL module? I'm aware of that authentication could be successfully done via route middleware, but the same cannot be done with authorization (or shouldn't... to achieve it anyway, you would have to parse request once more and fetch operation type, operation name and arguments recursively...).

For instance, package thecodingmachine/graphqlite offers @Security annotations that are handled by authentication and authorization services that you set in schema factory.

Are there any plans to implement similar feature to Siler\GraphQL? Or maybe solution already exists and I didn't manage to find it in documentation and source code? Maybe with dispatcher...?

I created actually a temporary workaround for this in Query class, but I wouldn't recommend it to anyone...

/**
 * @GraphQL\ObjectType(name="Query")
 */
class Query
{
    /**
     * @GraphQL\Field(name="user", description="Get user")
     * @GraphQL\Args(
     *     {
     *          @GraphQL\Field(name="id", type="Int")
     *     }
     * )
     */
    public static function getUser($root, array $args, $context, ResolveInfo $resolveInfo): User
    {
        return self::secure('_getUser', $args);
    }

    public static function secure(string $method, $arguments)
    {
        $user = \Siler\Container\retrieve(User::class);
        $request = \Siler\GraphQL\request()->toArray();

        $operationType = '...'; // check if operation type is 'query' or 'mutation', etc.
        $permissions = '...'; // load permissions for your role, specific $operationType and $method
        if (!isset($permissions['access']) || $permissions['access'] === false)
        {
            throw new Error('Access denied');
        }

        if (isset($acl['conditions']))
        {
            foreach ($acl['conditions'] as $condition)
            {
                // for example OwnUserCondition::class with method check($user, $args)
                // that verifies if $user->getId() === $args['id']
                
            }
        }

        return static::__callStatic($method, $arguments);
    }

    public static function _getUser($root, array $args, $context, ResolveInfo $resolveInfo): User
    {
        //...
    }
}

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions