Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The guidance explicitly recommends collecting the full response including `errors`, exact documents, variables, and later suggests logging resolver parent objects. In GraphQL systems these artifacts often contain secrets, tokens, PII, authorization context, or tenant-specific data, so encouraging broad logging without redaction or scope limits can lead to sensitive-data exposure in logs and debugging tools.
