Hello,
What is recommended way to add authorization logic to Siler\GraphQL module? I'm aware of that authentication could be successfully done via route middleware, but the same cannot be done with authorization (or shouldn't... to achieve it anyway, you would have to parse request once more and fetch operation type, operation name and arguments recursively...).
For instance, package thecodingmachine/graphqlite offers @Security annotations that are handled by authentication and authorization services that you set in schema factory.
Are there any plans to implement similar feature to Siler\GraphQL? Or maybe solution already exists and I didn't manage to find it in documentation and source code? Maybe with dispatcher...?
I created actually a temporary workaround for this in Query class, but I wouldn't recommend it to anyone...
/**
* @GraphQL\ObjectType(name="Query")
*/
class Query
{
/**
* @GraphQL\Field(name="user", description="Get user")
* @GraphQL\Args(
* {
* @GraphQL\Field(name="id", type="Int")
* }
* )
*/
public static function getUser($root, array $args, $context, ResolveInfo $resolveInfo): User
{
return self::secure('_getUser', $args);
}
public static function secure(string $method, $arguments)
{
$user = \Siler\Container\retrieve(User::class);
$request = \Siler\GraphQL\request()->toArray();
$operationType = '...'; // check if operation type is 'query' or 'mutation', etc.
$permissions = '...'; // load permissions for your role, specific $operationType and $method
if (!isset($permissions['access']) || $permissions['access'] === false)
{
throw new Error('Access denied');
}
if (isset($acl['conditions']))
{
foreach ($acl['conditions'] as $condition)
{
// for example OwnUserCondition::class with method check($user, $args)
// that verifies if $user->getId() === $args['id']
}
}
return static::__callStatic($method, $arguments);
}
public static function _getUser($root, array $args, $context, ResolveInfo $resolveInfo): User
{
//...
}
}
Hello,
What is recommended way to add authorization logic to Siler\GraphQL module? I'm aware of that authentication could be successfully done via route middleware, but the same cannot be done with authorization (or shouldn't... to achieve it anyway, you would have to parse request once more and fetch operation type, operation name and arguments recursively...).
For instance, package
thecodingmachine/graphqliteoffers@Securityannotations that are handled by authentication and authorization services that you set in schema factory.Are there any plans to implement similar feature to Siler\GraphQL? Or maybe solution already exists and I didn't manage to find it in documentation and source code? Maybe with dispatcher...?
I created actually a temporary workaround for this in Query class, but I wouldn't recommend it to anyone...