GRAPHQL-BASED
APPLICATIONS
-
Apollo and Others
Doyensec has developed a unique skill set for reviewing complicated queries and mutations. Our research-driven approach to GraphQL security is the culmination of our experience. We combine techniques and tooling to improve the efficiency of our security testing efforts.
By leveraging internal framework mechanisms, such as introspection, we ensure both code and attack coverage even in large deployments.We review all application queries and mutations to inspect results and perform extensive authorization testing to highlight insecure direct object reference problems.
While the language addresses some of the traditional web application vulnerabilities, it opens the door to information leakage and access control flaws. When reviewing GraphQL powered APIs, we particularly focus on those problems.
our research articles
Research is one of our founding principles and we invest in it heavily. All of our researchers have the privilege to use 25% of their time exclusively for self-directed research.
show more publications