Context#
Introspection (__schema, __type, field lists) is a first-class GraphQL feature. When it is exposed to low-trust callers in a production deployment, it becomes a complete machine-readable map of mutations, types, and custom scalars. This page is recon and surface mapping, not a substitute for per-field authorization testing.
Theory#
The schema shows which operations exist, including admin or internal-sounding fields. It accelerates BOLA and field-level testing by listing argument names and return types. Hiding introspection reduces casual mapping but does not fix missing authorization on resolvers; the offensive value is speed and completeness of the attack graph in scope.
Practice#
Run a minimal introspection query in a lab#
- POST the standard
__schemaquery body to the GraphQL HTTP endpoint with a test token. Save the response JSON for offline navigation of types and fields.
Diff schema against client bundle#
- Compare public schema to mobile or web client queries. Fields that exist only in introspection or in an internal client build are high-priority for missing checks.
Tools#
- GraphiQL (in lab only)
- curl
- Insomnia