Skip to content
This repository has been archived by the owner on Nov 14, 2023. It is now read-only.

Latest commit

 

History

History
68 lines (51 loc) · 2.07 KB

GraphQL-Security-Review.md

File metadata and controls

68 lines (51 loc) · 2.07 KB
layout title type owasp-project track technology related-to status when-day when-time location organizers participants invited
blocks/working-session
GraphQL Security Review
workshop
false
Research
Threat Model
done
PhotoBox
Anders Reeves

GraphQL is a query language for APIs and a runtime for fulfilling those queries with existing data. GraphQL provides a complete and understandable description of the data in an API, gives clients the power to ask for exactly what they need and nothing more, makes it easier to evolve APIs over time, and enables powerful developer tools.

Why

This Working Session aims to use the community attending the Summit to perform a security review to GraphQL (Threat Modeling, Code Review, Static Analysis, Pentest).

What

  • Perform Security review to GraphQL
  • Improve existing Security documentation and guidance

Outcomes

  • Revised security documentation and guidance

Who

The target audience for this Working Session is:

  • GraphQL developers
  • Security researchers
  • Companies using GraphQL

References


Working materials

  • Draft revisions to security documentation and guidance
  • Please add as much information as possible before the sessions

Content

... Add content ...