Posts

Showing posts with the label nested query

Enhancing security when using GraphQL

Image
Introduction In previous articles, I have provided guidance on using GraphQL in project development, however, the flexibility of GraphQL also comes with security risks that are not fully supported by default. In this article, I will guide you through two simple but effective ways to enhance security including Limit data : This applies not only to GraphQL but also to Restful APIs, this is the minimum necessary action to prevent Massive Data Retrieval attacks, because by default when querying data, it will fetch all records in the table, if your database has millions of records, it will cause your system to suffer an Out of Memory (RAM crash) immediately due to processing and parsing a huge amount of JSON data. GraphQL deep limit : Prevent Deep Nested Query attacks, in practical use cases, tables will always have relations with each other. If hackers discover this relationship, they can write nested queries 20-30 levels deep (such as users -> orders -> products -> order -> us...

Nested Query

Image
Introduction Subquery : A SELECT statement located inside another SQL statement (can be inside SELECT, FROM, WHERE, HAVING ). It supplies data for the main query. Nested Query : A term used to describe the structure of the query. When a Subquery resides inside a parent statement, this action is called nesting. Thus, Subquery can be viewed as the component (the child), while Nested query is the structural relationship (the parent containing the child). A statement that contains a subquery has its entire structure referred to as a nested query . Classification Non-correlated Subquery : This type of subquery runs completely independently of the parent statement. Postgres executes this subquery exactly once, using its result to apply to the parent statement. Example: SELECT name, salary FROM employees WHERE salary > (SELECT AVG(salary) FROM employees) Here, SELECT AVG(salary) FROM employees is an independent Subquery that only needs to run once to provide the value for the outer ...