hasura/graphql-engine

docs: examples of mutation by anonymous role

Open

#308 aperta il 24 ago 2018

Vedi su GitHub
 (5 commenti) (0 reazioni) (1 assegnatario)TypeScript (2787 fork)batch import
c/docshelp wanted

Metriche repository

Star
 (31.371 star)
Metriche merge PR
 (Nessuna PR mergiata in 30 g)

Descrizione

There are quite a few common use-cases around capturing mutations from anonymous users but without making it too easy for malicious users to spam the backend.

  1. Likes or visit counter
  2. other examples

Reasonable ways to determine a unique anonymous user:

  1. client generated session-id. Possible con: not terribly hard for a sophisticated user to fake
  2. IP based value. Possible con: users on a campus network might have UX issues with their likes getting rejected
  3. recaptcha based value. Possible con: ugh UX

(Via @thangngoc and @7777 on discord)

Guida contributor