INNER CODE UNIT · Python
SystemInfo
The-Art-of-Hacking/websploit · additional-labs/GraphQL/app.py:44
class SystemInfo(graphene.ObjectType):
version = graphene.String()
status = graphene.String()
debug_mode = graphene.Boolean()
class Query(graphene.ObjectType):
user = graphene.Field(User, id=graphene.ID(required=True), description="Get a user by ID")
users = graphene.List(User, description="List all users")
system_status = graphene.Field(SystemInfo, description="Check the system status")
def resolve_user(self, info, id):
# Insecure Direct Object Reference (IDOR) equivalent in GraphQL
# No auth check here!
for user in users_db:
if user["id"] == id:
return User(
id=user["id"],
username=user["username"],