GraphQL Security Analyzer
This project is starting as proof of conecpt to create a tooling which will check for you your GraphQL endpoint about security issues. The idea is to take the endpoint and check step by step all nodes and try to read from them. The good point is that graphql gives you the possibility to access the DOC :) So we can start with it.
To achieve this POC i will use Graphcool which gives you the possibility to easy create a schema with a complexe permission setup which is perfect to experiment with complex relations!