Restore granular token traversal in GraphQL type authorization
Problem
The type-level granular PAT authorization work in
!238311 (merged) and
!241225 (merged) moved granular
personal access token authorization in GraphQL from a per-field extension to
the object/type level. That move dropped the traversal behavior the field
extension provided: a granular token can no longer reach a child resource
through its parent boundary (for example group { groupMembers }) without
also holding the parent's read permission, even though the equivalent REST
endpoint allows it.
Proposal
Restore traversal at the type level:
- Inspect the fields selected on the object being authorized. When every selected field defers to an authorized, non-leaf child type, the object is reached only for traversal.
- In that case, the granular check verifies boundary visibility
(
read_boundary) instead of the object's own permission; the child types enforce their own permissions. - Reading the object's own data (scalar fields) still requires its permission. Leaf children (all-scalar types) also still require the parent permission, because an empty collection would otherwise bypass authorization.
- Resolve abstract (interface/union) return types to their concrete implementers.
Also remove the now-unused traversal: GraphQL directive argument and its
helper plumbing.
Implemented in !242976 (closed).
Related to #601728 (closed).