Home / Companies / Postman / Blog / Post Details
Content Deep Dive

Building secure GraphQL APIs at the NDC Oslo 2023 conference

Blog post from Postman

Post Details
Company
Date Published
Author
Meenakshi Dhanani
Word Count
718
Company Posts That Month
24
Language
English
Hacker News Points
-
Post removed?
No
Summary

At the prestigious NDC Oslo 2023 conference, a developer relations engineer for GraphQL at Postman delivered a session titled “Don’t Panic: A Developer’s Guide to Building Secure GraphQL APIs,” focusing on empowering developers with best practices for securing GraphQL APIs. The talk highlighted essential security measures such as implementing middleware for authentication and authorization, applying depth checks to limit nested query complexity, conducting query cost analysis to prevent server overload, employing persisted queries to reduce bandwidth and enhance caching, and disabling introspection and error suggestions in production environments to minimize vulnerabilities. Additionally, it emphasized the importance of validating and sanitizing input through custom scalars to protect against malicious data. These insights aim to equip developers with practical strategies to address the unique security challenges of GraphQL, ensuring robust protection for sensitive data.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.