Closed frederikhors closed 4 years ago
Oh yes certainly @frederikhors , but that would dive far into the complexity side of things and I am refraining from that. Surely we can mint tokens and set it on the request context, but I want to keep this repo as lean as possible.
Ok.
Are you trusting client information here?
Shouldn't we use server-side authentication info?
https://github.com/oshalygin/gqlgen-pg-todo-example/blob/master/resolvers/todo.go#L46