GraphQL security
In GraphQL the client decides the shape and depth of every query, which moves a lot of control from the server to the caller.
That is the point of it and it means the server cannot predict cost. A single query can request deeply nested relationships that expand into an enormous amount of work. Depth limits, complexity analysis and cost budgets are not optional extras here; they are what replaces the constraint a fixed endpoint provided.
Checked against the primary source.
