Home / Companies / Wundergraph / Blog / Post Details
Content Deep Dive

A GraphQL Federation directive for Subgraph-level compliance: @openfed__requireFetchReasons

Blog post from Wundergraph

Post Details
Company
Date Published
Author
Jens Neuse
Word Count
1,154
Company Posts That Month
5
Language
English
Hacker News Points
-
Post removed?
No
Summary

In the context of GraphQL Federation, the @requires directive poses a significant compliance risk by potentially allowing sensitive information to leak between subgraphs, undermining security controls. To address this issue, the @openfed__requireFetchReasons directive has been introduced, enabling subgraph owners to specify an allowlist of subgraphs that can access sensitive fields such as minimumPrice. This measure enhances compliance by making data access explicit and auditable, simplifying the process for organizations subject to strict data governance regulations. Unlike authorization, which controls user-level access, this directive focuses on ensuring that sensitive fields are not exposed across subgraphs without explicit consent, thereby turning compliance challenges into a manageable, declarative issue. This approach not only streamlines compliance audits by defining dependencies and rules directly within the schema but also highlights the importance of understanding service dependencies in microservice architectures.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.