INNER CODE UNIT · Python
resolve_users
The-Art-of-Hacking/websploit · additional-labs/GraphQL/app.py:69
def resolve_users(self, info):
# Returns all users but filters sensitive info in this view (mocking a "public" list)
# But if they query 'user(id: "1")' directly, they get everything!
safe_users = []
for user in users_db:
safe_users.append(User(
id=user["id"],
username=user["username"],
email=user["email"],
api_token="[REDACTED]", # Redacted in the list view
is_admin=user["is_admin"],
notes=user["notes"]
))
return safe_users
def resolve_system_status(self, info):
return SystemInfo(version="2.0.1-alpha", status="Operational", debug_mode=True)