← LibraryTechnique entry
W-GRAPHQL-AUTHZDiscovery
GraphQL Field-Level AuthZ Gaps
Top-level resolver checks auth; nested fields don't — query around the check via aliasing / unions.
§ Where this technique fits
W-GRAPHQL-AUTHZ is catalogued under the Discovery tactic of the offensive-security kill-chain. It appears in 1 approved dossier in the registry, typically at step 4 on average.
§ Dossiers chaining this technique
§ What commonly comes next
- 01Broken Object Level Authorization (API BOLA)seen 1×W-BOLA · Privilege Escalation