You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Create a graphql endpoint with a security after resolver.
Impact
As this fallsback to security, the impact is there only when there's only a security after resolver and none inside security. The test at #6444 is probably broken.
Summary
A security check that gets called after GraphQl resolvers is always replaced by another one as there's no break in this clause: https://github.com/api-platform/core/pull/6444/files#diff-09e3c2cfe12a2ce65bd6c983c7ca6bfcf783f852b8d0554bb938e8ebf5e5fa65R56
https://github.com/soyuka/core/blob/7e2e8f9ff322ac5f6eb5f65baf432bffdca0fd51/src/Symfony/Security/State/AccessCheckerProvider.php#L49-L57
PoC
Create a graphql endpoint with a security after resolver.
Impact
As this fallsback to
security
, the impact is there only when there's only a security after resolver and none inside security. The test at #6444 is probably broken.