{"_id":"@n1ru4l/graphql-public-schema-filter","_rev":"37-9524b9336cbce73e04bd32666ce94380","name":"@n1ru4l/graphql-public-schema-filter","dist-tags":{"latest":"2.0.0","alpha":"2.0.0-alpha-20230506190034-9763797"},"versions":{"0.1.0":{"name":"@n1ru4l/graphql-public-schema-filter","version":"0.1.0","description":"Filter your GraphQL schema into a public schema.","peerDependencies":{"graphql":"15.x.x"},"dependencies":{"@graphql-tools/utils":"^7.10.0"},"author":{"name":"Laurin Quast","email":"laurinquast@googlemail.com","url":"https://github.com/n1ru4l"},"license":"MIT","main":"index.js","module":"index.mjs","typings":"index.d.ts","typescript":{"definition":"index.d.ts"},"exports":{".":{"require":"./index.js","import":"./index.mjs"},"./*":{"require":"./*.js","import":"./*.mjs"}},"licenseText":"MIT License\n\nCopyright (c) 2019-present Laurin Quast <laurinquast@googlemail.com>\n\nPermission is hereby granted, free of charge, to any person obtaining a copy\nof this software and associated documentation files (the \"Software\"), to deal\nin the Software without restriction, including without limitation the rights\nto use, copy, modify, merge, publish, distribute, sublicense, and/or sell\ncopies of the Software, and to permit persons to whom the Software is\nfurnished to do so, subject to the following conditions:\n\nThe above copyright notice and this permission notice shall be included in all\ncopies or substantial portions of the Software.\n\nTHE SOFTWARE IS PROVIDED \"AS IS\", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR\nIMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,\nFITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE\nAUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER\nLIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,\nOUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE\nSOFTWARE.\n","_id":"@n1ru4l/graphql-public-schema-filter@0.1.0","dist":{"shasum":"6e780778e0b355e5ee95de2e952cdd730df6a566","integrity":"sha512-8xI5H/0lFyyC4h40dAqcDKIi4g69457In/MT1l4J0O/ZM0/4SmGHyR2Zrti/HpjO2m309bzn4XtR+W5uP4rsQA==","tarball":"https://registry.npmjs.org/@n1ru4l/graphql-public-schema-filter/-/graphql-public-schema-filter-0.1.0.tgz","fileCount":15,"unpackedSize":108882,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhAA8uCRA9TVsSAnZWagAAwPAP/jTTMKWZAHl0v/KPYGw5\nhHSj3hlyr2fTEKIVyZ8V+8tyrNUoBFsaSave2trnHzNsKLzqsdXXZuoY/3aQ\nnBOfETm/u5Id04R4C8VWQWj1JCcEU4+7RvPm9HiBNqhqH+clWbVrfLNleo3g\ntBe6hmd40KkBrXFy+hN103fBa/9J8Yv65Cs4gDwgpoKwuCwSNuu/0vJM5HI0\n+XIOEbzWhwgvuPtKzCwAbFILJCvrV+WrxkkkVB9TKg6fio2xWZFs7lh26IRM\nGdlQ0uw2Ktll3Wy4v81BqpLIhXveoR3KnIh5nZgRrmaJOUMRaQsHFUJFtnhX\n3MPce3lkxx/yMg8b8gWHmevkMeqUR+vxJOIns/neivqfCuBuXSoWnx3MsBLW\n0oSzRwW1eF6F0RVqDEVwx+9XioFgTVNXEhJpZ8JclscKjeH7vgbavni7s8wd\n0A9brngVFLvhSO/Nmvxf+qNiELucd78uwiSdFDljqildwgbe7sP8wnP+HYPP\nug++eocxJrgO1NQSD7qhqrlkI3q0vQu2QqSXCUo0wZfzP5hxf6qS0PLF4Byy\nsG6P0epq+62vCh/J0OZCkGNbHteAyen6LmFlWXHvaM8YpXpv8Ij7ybqbBmYF\nD09xIWs4rgChRWBWMJg8LO2LG6V7sRVLLbQl4ys40uwjhVyYcFkDvqOFH5yx\n/Y7b\r\n=qMPb\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIBbyAexaK3WmlpqNc9NqypTCmZwH11rxSA+gMmaWcnzHAiEAsZuc8Ajz3HrvL0xXUteaBG50oRHYiutWSndCSJPg1Wk="}]},"_npmUser":{"name":"n1ru4l","email":"laurinquast@googlemail.com"},"directories":{},"maintainers":[{"name":"n1ru4l","email":"laurinquast@googlemail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/graphql-public-schema-filter_0.1.0_1627393838548_0.8408501482670483"},"_hasShrinkwrap":false},"0.2.0":{"name":"@n1ru4l/graphql-public-schema-filter","version":"0.2.0","description":"Filter your GraphQL schema into a public schema.","peerDependencies":{"graphql":"15.x.x"},"dependencies":{"@graphql-tools/utils":"^7.10.0"},"author":{"name":"Laurin Quast","email":"laurinquast@googlemail.com","url":"https://github.com/n1ru4l"},"license":"MIT","main":"index.js","module":"index.mjs","typings":"index.d.ts","typescript":{"definition":"index.d.ts"},"exports":{".":{"require":"./index.js","import":"./index.mjs"},"./*":{"require":"./*.js","import":"./*.mjs"}},"_id":"@n1ru4l/graphql-public-schema-filter@0.2.0","_nodeVersion":"16.5.0","_npmVersion":"7.19.1","dist":{"integrity":"sha512-M7htBfbxqZ1qk1VkxLG4Z+KI5D4gvyXaeY+tiY6HTKOxkWXXAl0Uly+zgr9yDeHEkcF2rUamSd6kx+L3VGxAYQ==","shasum":"1ee2988d2c8cff80a10ec710635d88f001658e3a","tarball":"https://registry.npmjs.org/@n1ru4l/graphql-public-schema-filter/-/graphql-public-schema-filter-0.2.0.tgz","fileCount":14,"unpackedSize":53311,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhAOg9CRA9TVsSAnZWagAAjMYP/1shx64ZB69TJh3aMEyO\nQzNX5ap5aYVEBSWRdPNCu/0e4NS1eSIip/dyW9IKXqrTu5IQUAQrl4UmId92\nZiBisWSn2isWdujTxY8gHyfZsnXMtPTo6VOzLZYTKiS9Jsm0iitRbR9BJXm6\nZSty/FqgU16kjTCuP1FPBVckUteatVaBFXi3KdsJBD6oDhDohSQz9hVmingL\njUJ+RzwHKyzz9c8elWKePrl/00+w0aZN2VuS0YM994L0Gv6ZgZBo8lYYsj9b\nv/gJiFbU+pmS4Q8kliCAOfdzzAqMMwuUX2DYhyfVksVT2keFkgNFCYe3Yc7z\n/VWaAhpdrni6CYVdVkoyCQ821qXmXJdgfI74LX0zNI45KKgihQ/OD3Af017p\ni8f2RarTJSk5Xe/smEGMiOYhOpOSIsF+x5GU/1wLr5FB2JoUNbGcgFAGIXSn\ncXOAs5oBo2RtoCNmed9wWhKXgg+/fX7W/6HDutsJyP/aA5RUHOh0/8tHo+dx\nF0mqQRtvxUCAmEEwIjoeWK5j+7n3lDNypNsvjSOj1xNCGumjhEgV6Srd/BBy\nvZ680kEmzZrxAEFm5F1XhLdhLKwcMFYr4ASdcpXTagVq62Dt2t3PdvEXYWeb\n/hzCOs5A8ETR+RnxUJju+jf0nAcbiKIwqORZm6e76hSOXCAB/ybfAzUiyLFf\nZCD8\r\n=uxri\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIBEoP1Qg8G6cF+/JnchQe2FErhCxSII/5WeJf8eCsIAfAiBDrFyOFRGAHpxZ12MtyrTlCgO/dWURCJZPgRBhdLgjFg=="}]},"_npmUser":{"name":"n1ru4l","email":"laurinquast@googlemail.com"},"directories":{},"maintainers":[{"name":"n1ru4l","email":"laurinquast@googlemail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/graphql-public-schema-filter_0.2.0_1627449405668_0.41465256137238193"},"_hasShrinkwrap":false},"0.3.0":{"name":"@n1ru4l/graphql-public-schema-filter","version":"0.3.0","description":"Filter your GraphQL schema into a public schema.","peerDependencies":{"graphql":"15.x.x"},"dependencies":{"@graphql-tools/utils":"^7.10.0"},"author":{"name":"Laurin Quast","email":"laurinquast@googlemail.com","url":"https://github.com/n1ru4l"},"license":"MIT","main":"index.js","module":"index.mjs","typings":"index.d.ts","typescript":{"definition":"index.d.ts"},"exports":{".":{"require":"./index.js","import":"./index.mjs"},"./*":{"require":"./*.js","import":"./*.mjs"}},"_id":"@n1ru4l/graphql-public-schema-filter@0.3.0","_nodeVersion":"16.5.0","_npmVersion":"7.19.1","dist":{"integrity":"sha512-xEl5p40fnETulXurhU69n017StIX7OR5T7ID6TkZK/I5qQY4RivhHarg/CU4Rj/lpStjXptbZfMMsoCSzK+CZg==","shasum":"8424dbd542cbcf1b7daf844c710410d18dc3d54d","tarball":"https://registry.npmjs.org/@n1ru4l/graphql-public-schema-filter/-/graphql-public-schema-filter-0.3.0.tgz","fileCount":14,"unpackedSize":40281,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhAPU0CRA9TVsSAnZWagAAn+cP/2sCrZcZr4J1sa6skOBu\nB57Qn4lHYd6iug86B8u9Coijn50dyDtlZ3Ne+Ks3WFg5EHjCsjqxdAOwoiEB\nCPGdz7K58C/Bk5gr2H7CzLgKAFXb5o9XiaimxtnKPeyfWR0bSrUmgLf+RgQJ\nBvCFGBDptf6czm4P4fCeG3mzEdK9mNjmI0pH48fvzEaOoJE6Losne/5QCAxe\nh3uVp5qHNejC5jTVvhdcqDoyMAABiVgC66H9ublZ9p6+7DOTIKD35+bTX8pQ\nncJ+waut0fTg6JvkS4DQt6FSURCYbgiL4k0S67W9NvFi8rc0e3xfAxqg03tO\nfUSlRHN+HkMny1uDnBBALI7wHYwKJQFRrdLOa/xe4LX0/UMSL251WkwtYaFO\nNyHrS9mIP9skN4eiOj59qwc//bSuhFZTD+xycmUK7N5aThTi6TjM3ABiSVHV\nTr7SQJgdJpcTU6lMb8qyj3HNRWmv1RKNuD4IUZu5eII+u+j71udSKZQIuX/I\no+k0XO0qJdnTq1ZwGu6T7KPiQuo0rXhAqj3bb8CwrwytYRXhc4zBXB9R8XIM\nCmcgWlV/m5Melt7VzSct39xpH+EdMqK87VgPmRVVE6Kt0ZEncspC6dUU0yBq\nHcNXXbYinPM2MC27GaIcbQD01V1Y6rTBXaXadWQircXAUobjkJ01p22UYXmZ\n1NeU\r\n=BWBJ\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQD0J42j6eWfZ/Mtxwi8gg2otcpU9RqN/foeePU/2TKdtwIgaaM4jtI2C+tn6oozqTsa3ibAeCeb7Q7H1z3GSZsGkuQ="}]},"_npmUser":{"name":"n1ru4l","email":"laurinquast@googlemail.com"},"directories":{},"maintainers":[{"name":"n1ru4l","email":"laurinquast@googlemail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/graphql-public-schema-filter_0.3.0_1627452724847_0.214382716898327"},"_hasShrinkwrap":false},"0.3.1":{"name":"@n1ru4l/graphql-public-schema-filter","version":"0.3.1","description":"Filter your GraphQL schema into a public schema.","peerDependencies":{"graphql":"15.x.x"},"dependencies":{"@graphql-tools/utils":"^8.0.0"},"author":{"name":"Laurin Quast","email":"laurinquast@googlemail.com","url":"https://github.com/n1ru4l"},"license":"MIT","main":"index.js","module":"index.mjs","typings":"index.d.ts","typescript":{"definition":"index.d.ts"},"exports":{".":{"require":"./index.js","import":"./index.mjs"},"./*":{"require":"./*.js","import":"./*.mjs"}},"_id":"@n1ru4l/graphql-public-schema-filter@0.3.1","_nodeVersion":"16.5.0","_npmVersion":"7.19.1","dist":{"integrity":"sha512-oqtav/8W0pMxgHcrqe3c5ZgWpk2nMjWWGpD8LyZ2VUW6d0R/MeQCrs7zQviZeVlsJGm8mhf84pAnnhe5tq8Wxg==","shasum":"dc11cca451aae259158df983630b487a0f2b1ce6","tarball":"https://registry.npmjs.org/@n1ru4l/graphql-public-schema-filter/-/graphql-public-schema-filter-0.3.1.tgz","fileCount":14,"unpackedSize":40280,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhAntnCRA9TVsSAnZWagAAiVkP/AwXMXK3s2XyX+to2Oy2\nkfzIbiw/ofw04dQfU3oWwf7Es1VnZJdGhc1G4sSmBQvco7ycUbLqmP3V+XIg\ny7dVPewaefKOPGkkTGhnjfS/ukUvAC/1QHKwvDQ6UVzAgHo/dFg0OkMwULJ1\nQQZiYMQS4PNesorz3a7ZFe+AfGEBNy42lKe6J0COpGnmm3vxhm7vERH6J6vg\nQJvoPb6HdYj1DetvDLtfQV9fYSbne0hq7PKYdSBpNcfd64zRtI6vcMSKjTG4\nS8grvmsfomrk/BMPojw3tYwlnpPkArBrqkB5wWeMJylOHXWafyeyL5X/SvBS\nMvWuFJloqLn4At/VkN10D6Gv24T5uHqMYViA0pjgrKDHH+4uoyyNcIZhepxM\nGef+LVoTBJgfedGaPkNCBQFVMdrezMVio5FuhCk9wVfiPlh653qgc/1KM0Co\ny1hPFfQxgHM0bxXvPYSyrgWqD/LYigkKk5z42a8U6If2ShOGxuhKegF39Fke\n/3odz7NDXMHOnKV49iwQp4sn6hGJqVlTbJCxBCEs2waqoqfi+vnoNjj1OjdE\nkn30DxJvw16PiPtAoKW6sPdt5OECab0J5Yh5b0b/cTsV0YYQg0A7HFq25vtz\nrw+pl+AdvpGZUi/Vq8xOkfMms2RufRzjtgyB1s+qRmrfT/PeIwiUyYHnc2ou\nljPs\r\n=1mR3\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIAOgU7JjCIAhA2bcpEU9N22wTYWp7uJ8OJW4dZ4h1kJmAiEAq3WokiYu1apHm93FK22CtnaymPlCfB5lFYMy7emWhnU="}]},"_npmUser":{"name":"n1ru4l","email":"laurinquast@googlemail.com"},"directories":{},"maintainers":[{"name":"n1ru4l","email":"laurinquast@googlemail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/graphql-public-schema-filter_0.3.1_1627552615001_0.5924877802102944"},"_hasShrinkwrap":false},"0.4.0":{"name":"@n1ru4l/graphql-public-schema-filter","version":"0.4.0","description":"Filter your GraphQL schema into a public schema.","peerDependencies":{"graphql":"15.x.x"},"dependencies":{"@graphql-tools/utils":"^8.0.0"},"author":{"name":"Laurin Quast","email":"laurinquast@googlemail.com","url":"https://github.com/n1ru4l"},"license":"MIT","main":"index.js","module":"index.mjs","typings":"index.d.ts","typescript":{"definition":"index.d.ts"},"exports":{".":{"require":"./index.js","import":"./index.mjs"},"./*":{"require":"./*.js","import":"./*.mjs"}},"_id":"@n1ru4l/graphql-public-schema-filter@0.4.0","_nodeVersion":"16.6.1","_npmVersion":"7.20.3","dist":{"integrity":"sha512-JmX+pmsySpLttIVkApUM9JbjlrpH3rEDBuzEjLPXnhluYaxNkqwz7wfGwCMESIzXFg1WVNao+k5uMKcDFl2ycA==","shasum":"566dd38a9627057b28ac16df5576e33770ce4f1d","tarball":"https://registry.npmjs.org/@n1ru4l/graphql-public-schema-filter/-/graphql-public-schema-filter-0.4.0.tgz","fileCount":14,"unpackedSize":44224,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhCkmXCRA9TVsSAnZWagAAz90QAJO6bLj+SzI36vFD47sv\naY9GerrYSx+70Xu6KlCLbbFulb3tBr3Ka/Jd3ZhRhDjAY1Q+exg0Z/+CyGDL\nv0332eKQukv2UWPx3mtY0JcZGNeSo8dT74On1/jFOeQpdKwQppj3y6+ktkVY\nnBBp1fQYxy+hM4f4BaxyVlZm+vijOUj0M3PAQm2h4xc8ZLw13d+b7Ji2qLr/\ntgy5aPXSWpNu+J+NiSiqUmUuxixD6k50Ov1jAcAHQlmpdw22FRhnMz6QSNke\nu6xTu1Lg+N7+FPVjnH1BprVWZqupMM2XzuAHdsIo8UZF9L/h58VgGLeZ1oLO\nLBFDFklNIwiwWIewTlWC0qzHIv3WXQO5CIhcjFlGIV/VkzFxtYdvzF4Ghli0\n+dnTRSELrfyoXCnYEmENMbhqcZoZknNPP7ev4WnetR9A5HI+kKX54SXXvgWC\nJTMpr4/sAV/PlhHWGQmp8w/3/atJVr5jvNWqPfXdglg1dlmgcv4lbY3IEgKQ\nkD6iA96GE5wfkhkwAslswuhjm0N7CfJfFqlmKty3VDb+oMkYuOl4Xje2kcK+\nl7jt1XE8TOkFthSIqRlzkheW3ZHXlrKv2HnVPAMR0yd07+QSI+3MUc8EHBnE\nSG0rov8Uaq4JyhKLfp5KaQczQSViWzlonmfdvKcdoqjBb1h1jFgEEJ82BUmZ\njlLi\r\n=6PXD\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIC0fhebimXHz5p+UJ78SPlYA7ZrPwK8x2CWPSZPuywooAiAJxD4u5+tnqaGBI6+IshIfQ4hXHnFVN4GrMm2Sxf7cbQ=="}]},"_npmUser":{"name":"n1ru4l","email":"laurinquast@googlemail.com"},"directories":{},"maintainers":[{"name":"n1ru4l","email":"laurinquast@googlemail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/graphql-public-schema-filter_0.4.0_1628064151666_0.01601950106981187"},"_hasShrinkwrap":false},"0.4.1-alpha-20220809154712-2549aa9":{"name":"@n1ru4l/graphql-public-schema-filter","version":"0.4.1-alpha-20220809154712-2549aa9","description":"Filter your GraphQL schema into a public schema.","peerDependencies":{"graphql":"15.x.x"},"dependencies":{"@graphql-tools/utils":"^8.0.0"},"author":{"name":"Laurin Quast","email":"laurinquast@googlemail.com","url":"https://github.com/n1ru4l"},"license":"MIT","main":"index.js","module":"index.mjs","typings":"index.d.ts","typescript":{"definition":"index.d.ts"},"exports":{".":{"require":"./index.js","import":"./index.mjs"},"./*":{"require":"./*.js","import":"./*.mjs"}},"gitHead":"2549aa97a181f0f150938dadf6f036ec62160966","readme":"# @n1ru4l/graphql-public-schema-filter\n\nThis library allows filtering an existing GraphQL schema down into a subset of the original schema. It supports both the code first development flow of building GraphQL schemas (via GraphQL extension fields) and the SDL first development flow (via schema directives).\n\nThe implementation is smart and warns the user if the processed annotations would result in an invalid schema such as:\n\n- Object Type without fields\n- Field whose type is not part of the schema\n\nIf such a scenario is encountered the implementation will propagate and hide all fields/types that use types that are not marked as public or that would be invalid.\n\n## Why would you need this?\n\nAs I have been building GraphQL APIs I often had the need to have both a private and public API.\n\nThe private API is used for in-house products. Breaking changes can and will occur. It also includes types and fields specific to in-house application built around the API. The public API, however, is used by individuals not part of our organization. We cannot simply roll out breaking changes on the GraphQL API for those. Furthermore, they should only have access to a subset of the whole GraphQL graph. By generating a subgraph out of the internal graph we can hide stuff, without having to maintain and build two GraphQL schema.\n\n## Install instructions\n\nThis library requires `graphql` as a peer dependency and has a runtime dependency on `@graphql-tools/utils`.\n\n```bash\nyarn add -E @n1ru4l/graphql-public-schema-filter\n```\n\n## Usage Instructions\n\nThis library is designed to be inclusive for anyone within the GraphQL.js ecosystem. It supports both the SDL `makeExecutableSchema` and code-first via extension fields flow.\n\nThere is no delegation or validation overhead when executing against the newly generated schema. It is highly recommended to built the public schema during server-startup and not on the fly during incoming requests.\n\n### Code-First\n\nAnnotate types and fields that should be public with the `isPublic` extension.\n\n```ts\nimport { GraphQLObjectType, GraphQLString } from \"graphql\";\nimport { buildPublicSchema } from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst GraphQLQueryType = new GraphQLObjectType({\n  name: \"Query\",\n  fields: {\n    hello: {\n      type: GraphQLString,\n      resolve: () => \"hi\",\n      extensions: {\n        isPublic: true,\n      },\n    },\n    secret: {\n      type: GraphQLString,\n      resolve: () => \"sup\",\n    },\n  },\n});\n\nconst privateSchema = new GraphQLSchema({\n  query: GraphQLQueryType,\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\nYou can also find this example within `examples/src/schema.ts`.\n\n### SDL-First\n\nInstead of using the extension fields, we use the `@public` directive.\n\n```tsx\nimport { makeExecutableSchema } from \"@graphql-tools/schema\";\nimport {\n  publicDirectiveSDL,\n  buildPublicSchema,\n} from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst source = /* GraphQL */ `\n  type Query {\n    hello: String @public\n    secret: String\n  }\n`;\n\nconst privateSchema = makeExecutableSchema({\n  typeDefs: [publicDirectiveSDL, source],\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\n## FAQ\n\n### Why `isPublic` and `@public` over `isPrivate` and `@private`?\n\nDeny-listing is more prone to errors than allow-listing. By adding a directive/extension field we explicitly set something to public. The other way around it is easier to forgot to add a `@private`/ `isPrivate` annotation, which would automatically result in the new fields being public. Being verbose about what fields are public is the safest way.\n\n### Why is the no more granular control that allows building multiple unique public schemas?\n\nI considered this at the beginning, but in practice we never had a use for this. Having multiple public schemas requires maintaining a lot of documentation. In our use-case we only have a public and a private schema. There is still role based access for the public schema. certain users are not allowed to select specific fields. Instead of hiding those fields for those users we instead deny operations that select fields the users are not allowed to select before even executing it with the [envelop `useOperationFieldPermissions` plugin](https://www.envelop.dev/plugins/use-operation-field-permissions).\n\nYou can overwrite the `isPublic` function which is used to determine whether a field or type is public based on directives and extensions. This allows to fully customize the behavior based on your needs.\n\n```ts\ntype SharedExtensionAndDirectiveInformation = {\n  extensions?: Maybe<{\n    [attributeName: string]: any;\n  }>;\n  astNode?: Maybe<\n    Readonly<{\n      directives?: ReadonlyArray<DirectiveNode>;\n    }>\n  >;\n};\n\nexport const defaultIsPublic = (\n  input: SharedExtensionAndDirectiveInformation\n): boolean =>\n  input.extensions?.[\"isPublic\"] === true ||\n  !!input.astNode?.directives?.find(\n    (directive) => directive.name.value === \"public\"\n  );\n```\n\n## License\n\nMIT\n","readmeFilename":"README.md","_id":"@n1ru4l/graphql-public-schema-filter@0.4.1-alpha-20220809154712-2549aa9","_nodeVersion":"18.7.0","_npmVersion":"8.15.0","dist":{"integrity":"sha512-L9t2Z8mqv0uqJDH6abcL0MX/u8fjCjz10pyKyLTrtyYrkdQSbPpsR2Xf5o9Y2i2Bg1ojAt2P0SPJM4IOx+fW0w==","shasum":"abd5171c49e8310c3a40c448ad6f762d1af7b0a2","tarball":"https://registry.npmjs.org/@n1ru4l/graphql-public-schema-filter/-/graphql-public-schema-filter-0.4.1-alpha-20220809154712-2549aa9.tgz","fileCount":12,"unpackedSize":43512,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDkhxGcNzGVkEhKTY32VUBFkD9WKTuEhfvduDtifuVJEQIhAK3UnTdoZ5uqNWtv/7om/Qf6C1zitUjGAh6IRbRyFMa0"}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJi8oGIACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmp2xg/9HTtKKflBdJ2pZF0BxM6wKf+2XkJ35Yb+lC3Gj1U/OPqa+uNd\r\nQv8rv98+VF5DYejhwZ0XkhlncPWgiwEjfgVu9J5Fk5r0EQ5uAOFFhKd61JXH\r\nGb+Sc8tellNvzXDQW04+67/8sWD7mstFK4WrDMxEPlfK4oOffCt51G8Hzz44\r\nbLOpQ5sbqSbpEUJXIQs6wDhCOdrEkh2vrTEg8iswyrHU87HcO7BLT756YcY/\r\nJKALYWJFY6b4ggQzxnRR8SVBtUUrIvUZdB+KCT4PJUfzukhIDQH4IUcxvrGQ\r\nCombawxX5OmzSNBBvoPwv23EiZm+CcG0p8yaJG/rp0cD7sjUoqsmdFeQSNUR\r\naxPd6bibn6mYnXdsjZqoQPbhMH1ViYUvMn2I5rHE17BfAqKhMzeqABJsBCDU\r\nRwpmAEBbg68TlrBjRy0boqtjrxY+qVLdzTowvlksdJxzwhsU8Md1lx6onlXX\r\nQTE906jh92IAim1MPVCQBWHYX4RUq6SRnjv0hKSJYCWLR4nUeQykDTzStmTY\r\no5dlAsWKyjiB2C/bwg8b9e+NwciCbNk6fgUiq6Jj40u6NPFHAyECFSwdFxi9\r\nztZj1kjai7rWbzt7CAl/rq9zpTKHTKMD1c3l0j5iIQhWS/We6dli6QY/zcCn\r\nA5AVAmYcXDd8uekhbX0Pq9tDYnZS4VWdcO4=\r\n=k/WR\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"n1ru4l","email":"laurinquast@googlemail.com"},"directories":{},"maintainers":[{"name":"n1ru4l","email":"laurinquast@googlemail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/graphql-public-schema-filter_0.4.1-alpha-20220809154712-2549aa9_1660060040454_0.8242342454920824"},"_hasShrinkwrap":false},"1.0.0-alpha-20220928122146-5a2f3e3":{"name":"@n1ru4l/graphql-public-schema-filter","version":"1.0.0-alpha-20220928122146-5a2f3e3","description":"Filter your GraphQL schema into a public schema.","peerDependencies":{"graphql":"16.x.x"},"dependencies":{"@graphql-tools/utils":"^8.0.0"},"author":{"name":"Laurin Quast","email":"laurinquast@googlemail.com","url":"https://github.com/n1ru4l"},"license":"MIT","main":"index.js","module":"index.mjs","typings":"index.d.ts","typescript":{"definition":"index.d.ts"},"exports":{".":{"require":"./index.js","import":"./index.mjs"},"./*":{"require":"./*.js","import":"./*.mjs"},"./package.json":"./package.json"},"gitHead":"5a2f3e3f66f980fcce4986ea4ce1c6b2f9e39bc0","readme":"# @n1ru4l/graphql-public-schema-filter\n\nThis library allows filtering an existing GraphQL schema down into a subset of the original schema. It supports both the code first development flow of building GraphQL schemas (via GraphQL extension fields) and the SDL first development flow (via schema directives).\n\nThe implementation is smart and warns the user if the processed annotations would result in an invalid schema such as:\n\n- Object Type without fields\n- Field whose type is not part of the schema\n\nIf such a scenario is encountered the implementation will propagate and hide all fields/types that use types that are not marked as public or that would be invalid.\n\n## Why would you need this?\n\nAs I have been building GraphQL APIs I often had the need to have both a private and public API.\n\nThe private API is used for in-house products. Breaking changes can and will occur. It also includes types and fields specific to in-house application built around the API. The public API, however, is used by individuals not part of our organization. We cannot simply roll out breaking changes on the GraphQL API for those. Furthermore, they should only have access to a subset of the whole GraphQL graph. By generating a subgraph out of the internal graph we can hide stuff, without having to maintain and build two GraphQL schema.\n\n## Install instructions\n\nThis library requires `graphql` as a peer dependency and has a runtime dependency on `@graphql-tools/utils`.\n\n```bash\nyarn add -E @n1ru4l/graphql-public-schema-filter\n```\n\n## Usage Instructions\n\nThis library is designed to be inclusive for anyone within the GraphQL.js ecosystem. It supports both the SDL `makeExecutableSchema` and code-first via extension fields flow.\n\nThere is no delegation or validation overhead when executing against the newly generated schema. It is highly recommended to built the public schema during server-startup and not on the fly during incoming requests.\n\n### Code-First\n\nAnnotate types and fields that should be public with the `isPublic` extension.\n\n```ts\nimport { GraphQLObjectType, GraphQLString } from \"graphql\";\nimport { buildPublicSchema } from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst GraphQLQueryType = new GraphQLObjectType({\n  name: \"Query\",\n  fields: {\n    hello: {\n      type: GraphQLString,\n      resolve: () => \"hi\",\n      extensions: {\n        isPublic: true,\n      },\n    },\n    secret: {\n      type: GraphQLString,\n      resolve: () => \"sup\",\n    },\n  },\n});\n\nconst privateSchema = new GraphQLSchema({\n  query: GraphQLQueryType,\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\nYou can also find this example within `examples/src/schema.ts`.\n\n### SDL-First\n\nInstead of using the extension fields, we use the `@public` directive.\n\n```tsx\nimport { makeExecutableSchema } from \"@graphql-tools/schema\";\nimport {\n  publicDirectiveSDL,\n  buildPublicSchema,\n} from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst source = /* GraphQL */ `\n  type Query {\n    hello: String @public\n    secret: String\n  }\n`;\n\nconst privateSchema = makeExecutableSchema({\n  typeDefs: [publicDirectiveSDL, source],\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\n## FAQ\n\n### Why `isPublic` and `@public` over `isPrivate` and `@private`?\n\nDeny-listing is more prone to errors than allow-listing. By adding a directive/extension field we explicitly set something to public. The other way around it is easier to forgot to add a `@private`/ `isPrivate` annotation, which would automatically result in the new fields being public. Being verbose about what fields are public is the safest way.\n\n### Why is the no more granular control that allows building multiple unique public schemas?\n\nI considered this at the beginning, but in practice we never had a use for this. Having multiple public schemas requires maintaining a lot of documentation. In our use-case we only have a public and a private schema. There is still role based access for the public schema. certain users are not allowed to select specific fields. Instead of hiding those fields for those users we instead deny operations that select fields the users are not allowed to select before even executing it with the [envelop `useOperationFieldPermissions` plugin](https://www.envelop.dev/plugins/use-operation-field-permissions).\n\nYou can overwrite the `isPublic` function which is used to determine whether a field or type is public based on directives and extensions. This allows to fully customize the behavior based on your needs.\n\n```ts\ntype SharedExtensionAndDirectiveInformation = {\n  extensions?: Maybe<{\n    [attributeName: string]: any;\n  }>;\n  astNode?: Maybe<\n    Readonly<{\n      directives?: ReadonlyArray<DirectiveNode>;\n    }>\n  >;\n};\n\nexport const defaultIsPublic = (\n  input: SharedExtensionAndDirectiveInformation\n): boolean =>\n  input.extensions?.[\"isPublic\"] === true ||\n  !!input.astNode?.directives?.find(\n    (directive) => directive.name.value === \"public\"\n  );\n```\n\n## License\n\nMIT\n","readmeFilename":"README.md","_id":"@n1ru4l/graphql-public-schema-filter@1.0.0-alpha-20220928122146-5a2f3e3","_nodeVersion":"18.9.1","_npmVersion":"8.19.1","dist":{"integrity":"sha512-1MFE+6QRRwdFv5XMk80Hy4JJU7LEIInzPUggNDJGwbS2dQCI4RRObQ9T2NlNqXl+rJPskXF56XozllHrtfOWYw==","shasum":"ed90bf6389305a1f78bdf3239210d50ae49c3e11","tarball":"https://registry.npmjs.org/@n1ru4l/graphql-public-schema-filter/-/graphql-public-schema-filter-1.0.0-alpha-20220928122146-5a2f3e3.tgz","fileCount":12,"unpackedSize":43552,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCpFNxsv85pNI80RoM6BQdXoCkfWsUCU2bHkYP/UWJR9gIhAIhHfrbqua8dyHL0z+R8RlCF7ReFNeYoUAp5UMyhz4h+"}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjNDxhACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqPQA/+KW8I59oHfVZo+/EfUWg7DOl26al0tMDEYtiXduiScd4KFFpz\r\nLM9wlgxUgg9kv258MbKj/hmL7FxccOHgxsN9SdOA4mFYOgh6cbEVdh94vB09\r\niiQUzqp4Luioi2nU6kaqeLTnZxOfU600smHGpUgVgFxGwNFmcAHZ4RrZnf+V\r\nOgtIAliX7t6qzbNGO8b5D0FPdD+yEJ5cUVaIGrTExh7O9kpsrlo9qjgTha7G\r\n180W5C9BHxREN/1GxsShvYCEV6L8o3eUVWkXfYgwkLDW0fVEpsN9n/v/lIBQ\r\nD5dGm/pm2b18UZmcovc8OJalTibSAVpXsiBY9Ar0ITgSmszsIbfmQ8F8axYR\r\nuDD77bDWZvkPWhtWt4d5erZV0I4cM90FUL91QTCjK+pKp+fOhXQNLovR/xsx\r\nCNq3G8ngAEzaH/WQtyFztG4KfNaT3ehbDzEQqqHSaaUVTzU29EJzmbgGzfxP\r\nPJUdoHnfQ8Ateqg4JfAOblZaPiHhakpaK6U3Rn2hk8b/cr6r/1/R3/YYao5R\r\nXvu7XzpAVjxyPgP24Z2LDtuO/aPTtJIRtdoNRycfUK9nVgTvmcsb6ZMfBRL/\r\nGcI0FItNDRBlBY9/D/scZiAiR+K1LusLAKfqEe5iWnOU7GBUgy0a1mo8XmLR\r\nGeAGcKMAmBNMNhdn91Z2ttkX5y3EKObSw3c=\r\n=AULC\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"n1ru4l","email":"laurinquast@googlemail.com"},"directories":{},"maintainers":[{"name":"n1ru4l","email":"laurinquast@googlemail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/graphql-public-schema-filter_1.0.0-alpha-20220928122146-5a2f3e3_1664367713335_0.25707495679833237"},"_hasShrinkwrap":false},"1.0.0-alpha-20220928122259-f3697d2":{"name":"@n1ru4l/graphql-public-schema-filter","version":"1.0.0-alpha-20220928122259-f3697d2","description":"Filter your GraphQL schema into a public schema.","peerDependencies":{"graphql":"16.x.x"},"dependencies":{"@graphql-tools/utils":"^8.0.0"},"author":{"name":"Laurin Quast","email":"laurinquast@googlemail.com","url":"https://github.com/n1ru4l"},"license":"MIT","main":"index.js","module":"index.mjs","typings":"index.d.ts","typescript":{"definition":"index.d.ts"},"exports":{".":{"require":"./index.js","import":"./index.mjs"},"./*":{"require":"./*.js","import":"./*.mjs"},"./package.json":"./package.json"},"gitHead":"f3697d20fb9c48fc2057be62c75ea29783aa1f29","readme":"# @n1ru4l/graphql-public-schema-filter\n\nThis library allows filtering an existing GraphQL schema down into a subset of the original schema. It supports both the code first development flow of building GraphQL schemas (via GraphQL extension fields) and the SDL first development flow (via schema directives).\n\nThe implementation is smart and warns the user if the processed annotations would result in an invalid schema such as:\n\n- Object Type without fields\n- Field whose type is not part of the schema\n\nIf such a scenario is encountered the implementation will propagate and hide all fields/types that use types that are not marked as public or that would be invalid.\n\n## Why would you need this?\n\nAs I have been building GraphQL APIs I often had the need to have both a private and public API.\n\nThe private API is used for in-house products. Breaking changes can and will occur. It also includes types and fields specific to in-house application built around the API. The public API, however, is used by individuals not part of our organization. We cannot simply roll out breaking changes on the GraphQL API for those. Furthermore, they should only have access to a subset of the whole GraphQL graph. By generating a subgraph out of the internal graph we can hide stuff, without having to maintain and build two GraphQL schema.\n\n## Install instructions\n\nThis library requires `graphql` as a peer dependency and has a runtime dependency on `@graphql-tools/utils`.\n\n```bash\nyarn add -E @n1ru4l/graphql-public-schema-filter\n```\n\n## Usage Instructions\n\nThis library is designed to be inclusive for anyone within the GraphQL.js ecosystem. It supports both the SDL `makeExecutableSchema` and code-first via extension fields flow.\n\nThere is no delegation or validation overhead when executing against the newly generated schema. It is highly recommended to built the public schema during server-startup and not on the fly during incoming requests.\n\n### Code-First\n\nAnnotate types and fields that should be public with the `isPublic` extension.\n\n```ts\nimport { GraphQLObjectType, GraphQLString } from \"graphql\";\nimport { buildPublicSchema } from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst GraphQLQueryType = new GraphQLObjectType({\n  name: \"Query\",\n  fields: {\n    hello: {\n      type: GraphQLString,\n      resolve: () => \"hi\",\n      extensions: {\n        isPublic: true,\n      },\n    },\n    secret: {\n      type: GraphQLString,\n      resolve: () => \"sup\",\n    },\n  },\n});\n\nconst privateSchema = new GraphQLSchema({\n  query: GraphQLQueryType,\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\nYou can also find this example within `examples/src/schema.ts`.\n\n### SDL-First\n\nInstead of using the extension fields, we use the `@public` directive.\n\n```tsx\nimport { makeExecutableSchema } from \"@graphql-tools/schema\";\nimport {\n  publicDirectiveSDL,\n  buildPublicSchema,\n} from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst source = /* GraphQL */ `\n  type Query {\n    hello: String @public\n    secret: String\n  }\n`;\n\nconst privateSchema = makeExecutableSchema({\n  typeDefs: [publicDirectiveSDL, source],\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\n## FAQ\n\n### Why `isPublic` and `@public` over `isPrivate` and `@private`?\n\nDeny-listing is more prone to errors than allow-listing. By adding a directive/extension field we explicitly set something to public. The other way around it is easier to forgot to add a `@private`/ `isPrivate` annotation, which would automatically result in the new fields being public. Being verbose about what fields are public is the safest way.\n\n### Why is the no more granular control that allows building multiple unique public schemas?\n\nI considered this at the beginning, but in practice we never had a use for this. Having multiple public schemas requires maintaining a lot of documentation. In our use-case we only have a public and a private schema. There is still role based access for the public schema. certain users are not allowed to select specific fields. Instead of hiding those fields for those users we instead deny operations that select fields the users are not allowed to select before even executing it with the [envelop `useOperationFieldPermissions` plugin](https://www.envelop.dev/plugins/use-operation-field-permissions).\n\nYou can overwrite the `isPublic` function which is used to determine whether a field or type is public based on directives and extensions. This allows to fully customize the behavior based on your needs.\n\n```ts\ntype SharedExtensionAndDirectiveInformation = {\n  extensions?: Maybe<{\n    [attributeName: string]: any;\n  }>;\n  astNode?: Maybe<\n    Readonly<{\n      directives?: ReadonlyArray<DirectiveNode>;\n    }>\n  >;\n};\n\nexport const defaultIsPublic = (\n  input: SharedExtensionAndDirectiveInformation\n): boolean =>\n  input.extensions?.[\"isPublic\"] === true ||\n  !!input.astNode?.directives?.find(\n    (directive) => directive.name.value === \"public\"\n  );\n```\n\n## License\n\nMIT\n","readmeFilename":"README.md","_id":"@n1ru4l/graphql-public-schema-filter@1.0.0-alpha-20220928122259-f3697d2","_nodeVersion":"18.9.1","_npmVersion":"8.19.1","dist":{"integrity":"sha512-yvRTj1+9KDlsZInRProHa2b14SDEi9UOHy0mOxtDqoCsPD6yjKJ5q2SMyvnULm+8V4JrXOH2TDJYT36dahnZXA==","shasum":"59007a4867078f37d822913f4650812248306e40","tarball":"https://registry.npmjs.org/@n1ru4l/graphql-public-schema-filter/-/graphql-public-schema-filter-1.0.0-alpha-20220928122259-f3697d2.tgz","fileCount":12,"unpackedSize":43552,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIGkfEcE5Yufns+7MkuSaXz4MB6nJLno/XqDGiuvn6r72AiEAhTDiq6ouZww/EjB8LAI2l/bKU46O6/y2nRWZgWuOAbg="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjNDyqACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrMwA/+IUQBN9lW94mhGiiy5uIUBLk1nGKJtrrIpDauuxypaTflU8IU\r\n0AqauWu/zLqfBz/yc4LBJ3YtUiGTKicUaNQE1auPyVwEH9o/8ApaS7pBt6vf\r\nd3BFkXMIWA1xORXTYqkg1F1aA9TqFQAGnf0AUYOL1kM5NAHo/7thfWQgXlX7\r\ng4PabzyKdydJo3lW7cRGsxoFjmW4GBetgJVRmlYEKjdpQY2UdZr5MPEyHiO1\r\naH50EnDGBj/qyg0/kgFK6YFPatI2HeBd+h0pOBznW7ndWRO+ujtUJzEQ269y\r\nIrZU6bD369h5ihAQaVBho+oOvV0acrSckEtBYmnxfi3AHJHytWHUD4xXJotn\r\nY4mvakzm/Ieadv4XGESM86PWqRnBCLT8w/jkRwsEIkWkZHIbt07W1JHZ5RI2\r\nsJRCuIIfX63jioRsMD6c/v/AraN7Cwk2LbZtBSNHErHQaNE+/jIhesG4wOoM\r\nzDaxKTxk4dMqHlREhcP2jVUo6U7oUpw5BHHCsB0iKtQr1L7Ok+1TjvKwGIXc\r\nG1qYnXuX1RvxFoZaP48RGCFJ3/HvKC7azy7uYNur0nFAA+S7TtvJTR4K/Q0L\r\nPLbS6r4Ru4Jg700c/Q3GWfcZ5ZpOXOG7MV1iTjHNQvpziX7TCz//I2EGH97h\r\nIGBfHfF8hjtAXpZ4oLsh5MrDafZV9wLuJs8=\r\n=3fs7\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"n1ru4l","email":"laurinquast@googlemail.com"},"directories":{},"maintainers":[{"name":"n1ru4l","email":"laurinquast@googlemail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/graphql-public-schema-filter_1.0.0-alpha-20220928122259-f3697d2_1664367786194_0.41834634109245683"},"_hasShrinkwrap":false},"1.0.0-alpha-20220928122321-192fe3f":{"name":"@n1ru4l/graphql-public-schema-filter","version":"1.0.0-alpha-20220928122321-192fe3f","description":"Filter your GraphQL schema into a public schema.","peerDependencies":{"graphql":"16.x.x"},"dependencies":{"@graphql-tools/utils":"^8.0.0"},"author":{"name":"Laurin Quast","email":"laurinquast@googlemail.com","url":"https://github.com/n1ru4l"},"license":"MIT","main":"index.js","module":"index.mjs","typings":"index.d.ts","typescript":{"definition":"index.d.ts"},"exports":{".":{"require":"./index.js","import":"./index.mjs"},"./*":{"require":"./*.js","import":"./*.mjs"},"./package.json":"./package.json"},"gitHead":"192fe3f34dca7f4edb584326f8e0bca8ff765e10","readme":"# @n1ru4l/graphql-public-schema-filter\n\nThis library allows filtering an existing GraphQL schema down into a subset of the original schema. It supports both the code first development flow of building GraphQL schemas (via GraphQL extension fields) and the SDL first development flow (via schema directives).\n\nThe implementation is smart and warns the user if the processed annotations would result in an invalid schema such as:\n\n- Object Type without fields\n- Field whose type is not part of the schema\n\nIf such a scenario is encountered the implementation will propagate and hide all fields/types that use types that are not marked as public or that would be invalid.\n\n## Why would you need this?\n\nAs I have been building GraphQL APIs I often had the need to have both a private and public API.\n\nThe private API is used for in-house products. Breaking changes can and will occur. It also includes types and fields specific to in-house application built around the API. The public API, however, is used by individuals not part of our organization. We cannot simply roll out breaking changes on the GraphQL API for those. Furthermore, they should only have access to a subset of the whole GraphQL graph. By generating a subgraph out of the internal graph we can hide stuff, without having to maintain and build two GraphQL schema.\n\n## Install instructions\n\nThis library requires `graphql` as a peer dependency and has a runtime dependency on `@graphql-tools/utils`.\n\n```bash\nyarn add -E @n1ru4l/graphql-public-schema-filter\n```\n\n## Usage Instructions\n\nThis library is designed to be inclusive for anyone within the GraphQL.js ecosystem. It supports both the SDL `makeExecutableSchema` and code-first via extension fields flow.\n\nThere is no delegation or validation overhead when executing against the newly generated schema. It is highly recommended to built the public schema during server-startup and not on the fly during incoming requests.\n\n### Code-First\n\nAnnotate types and fields that should be public with the `isPublic` extension.\n\n```ts\nimport { GraphQLObjectType, GraphQLString } from \"graphql\";\nimport { buildPublicSchema } from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst GraphQLQueryType = new GraphQLObjectType({\n  name: \"Query\",\n  fields: {\n    hello: {\n      type: GraphQLString,\n      resolve: () => \"hi\",\n      extensions: {\n        isPublic: true,\n      },\n    },\n    secret: {\n      type: GraphQLString,\n      resolve: () => \"sup\",\n    },\n  },\n});\n\nconst privateSchema = new GraphQLSchema({\n  query: GraphQLQueryType,\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\nYou can also find this example within `examples/src/schema.ts`.\n\n### SDL-First\n\nInstead of using the extension fields, we use the `@public` directive.\n\n```tsx\nimport { makeExecutableSchema } from \"@graphql-tools/schema\";\nimport {\n  publicDirectiveSDL,\n  buildPublicSchema,\n} from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst source = /* GraphQL */ `\n  type Query {\n    hello: String @public\n    secret: String\n  }\n`;\n\nconst privateSchema = makeExecutableSchema({\n  typeDefs: [publicDirectiveSDL, source],\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\n## FAQ\n\n### Why `isPublic` and `@public` over `isPrivate` and `@private`?\n\nDeny-listing is more prone to errors than allow-listing. By adding a directive/extension field we explicitly set something to public. The other way around it is easier to forgot to add a `@private`/ `isPrivate` annotation, which would automatically result in the new fields being public. Being verbose about what fields are public is the safest way.\n\n### Why is the no more granular control that allows building multiple unique public schemas?\n\nI considered this at the beginning, but in practice we never had a use for this. Having multiple public schemas requires maintaining a lot of documentation. In our use-case we only have a public and a private schema. There is still role based access for the public schema. certain users are not allowed to select specific fields. Instead of hiding those fields for those users we instead deny operations that select fields the users are not allowed to select before even executing it with the [envelop `useOperationFieldPermissions` plugin](https://www.envelop.dev/plugins/use-operation-field-permissions).\n\nYou can overwrite the `isPublic` function which is used to determine whether a field or type is public based on directives and extensions. This allows to fully customize the behavior based on your needs.\n\n```ts\ntype SharedExtensionAndDirectiveInformation = {\n  extensions?: Maybe<{\n    [attributeName: string]: any;\n  }>;\n  astNode?: Maybe<\n    Readonly<{\n      directives?: ReadonlyArray<DirectiveNode>;\n    }>\n  >;\n};\n\nexport const defaultIsPublic = (\n  input: SharedExtensionAndDirectiveInformation\n): boolean =>\n  input.extensions?.[\"isPublic\"] === true ||\n  !!input.astNode?.directives?.find(\n    (directive) => directive.name.value === \"public\"\n  );\n```\n\n## License\n\nMIT\n","readmeFilename":"README.md","_id":"@n1ru4l/graphql-public-schema-filter@1.0.0-alpha-20220928122321-192fe3f","_nodeVersion":"18.9.1","_npmVersion":"8.19.1","dist":{"integrity":"sha512-DX5sYbP9rOIoPIasBLrkFawiBXb9TVJmYZK3m8LoFFLDSR5qkXi+CmvW72uBMcRi/R+XSzLF05TqNaje2c4J6g==","shasum":"3b79b90c88aa0849ceeb391ee210282cafb93319","tarball":"https://registry.npmjs.org/@n1ru4l/graphql-public-schema-filter/-/graphql-public-schema-filter-1.0.0-alpha-20220928122321-192fe3f.tgz","fileCount":12,"unpackedSize":43552,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIANfuUHSAjzeCtRtiNyJI8+1k+rA2/oNL63vGJSPuvEcAiEA7ZCjt/nBAu2cN+ljJjuHasKNDBVhzudpv5I7tJ1YKfM="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjNDzAACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmq9cRAAiTV27N6M3FU6HfeX0pRUqy8CpukOTy64qlJb1uusMcTXWi7b\r\nZ7xm8uKyiQGpF6M4DkICBb/6L9iFxdEoFEqFCf4W5Snm3+LljUHoUqkC1pW7\r\nnRxcQx9mbnCLB/niu1qjQE16hjbhF4Mzy+PwFjI5FVBpFhsonQvwVEcBCY7Z\r\n7L/gFl3xlXDDMSFyotbM/+xSzWjd2eOaIW7qf3lwIg7bbrpS4WbwIMKxq4lF\r\n2W5ADKbiumvZbx60VUY2ZGQvOhp1Ln3uCdsQQwmZ1yIshy/Ny0PNTlxAZVGb\r\nBNGHiqqbecr9ZlEXDsIw9k551e9EMfG6rwO9Vob6xYLnIpU3aLQCt4Uc6Tpf\r\nAEnxFsa7BROa6k0VNRNr5KkozK0b1uSXyF1UkxDxKuacT2feXTgqIK7QhuUp\r\n4g/2+eHhTbPcbX3zwQwiMGz21ZceVjFGy+crPE/HPmsHFJkOsawBGLL+JHzL\r\nKp4ptxfqWY0Qdl3/i+mzRr8io6z/qb1Ej8t2W71VBMp9AZXTxo6RI7PG6yH3\r\nozTfh/CcB1j/dvYM39R8VnfFnqqULk0+ig1pRdC3sCnWurUf0861gihBuOOJ\r\ne7XL5ehRzYvK85Obl/jXqvAafiOxoy030oeSDxoc3OidFT3N+0yUg+VeI9Fu\r\nvcp37PJM9YHxD0u6wFi7HoBjrKtG0WIdr2Q=\r\n=T8mQ\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"n1ru4l","email":"laurinquast@googlemail.com"},"directories":{},"maintainers":[{"name":"n1ru4l","email":"laurinquast@googlemail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/graphql-public-schema-filter_1.0.0-alpha-20220928122321-192fe3f_1664367808170_0.6620772428076107"},"_hasShrinkwrap":false},"1.0.0-alpha-20220928122357-14cc304":{"name":"@n1ru4l/graphql-public-schema-filter","version":"1.0.0-alpha-20220928122357-14cc304","description":"Filter your GraphQL schema into a public schema.","peerDependencies":{"graphql":"16.x.x"},"dependencies":{"@graphql-tools/utils":"^8.0.0"},"author":{"name":"Laurin Quast","email":"laurinquast@googlemail.com","url":"https://github.com/n1ru4l"},"license":"MIT","main":"index.js","module":"index.mjs","typings":"index.d.ts","typescript":{"definition":"index.d.ts"},"exports":{".":{"require":"./index.js","import":"./index.mjs"},"./*":{"require":"./*.js","import":"./*.mjs"},"./package.json":"./package.json"},"gitHead":"14cc304c1bb807038325f96600cfc8f410c3ca21","readme":"# @n1ru4l/graphql-public-schema-filter\n\nThis library allows filtering an existing GraphQL schema down into a subset of the original schema. It supports both the code first development flow of building GraphQL schemas (via GraphQL extension fields) and the SDL first development flow (via schema directives).\n\nThe implementation is smart and warns the user if the processed annotations would result in an invalid schema such as:\n\n- Object Type without fields\n- Field whose type is not part of the schema\n\nIf such a scenario is encountered the implementation will propagate and hide all fields/types that use types that are not marked as public or that would be invalid.\n\n## Why would you need this?\n\nAs I have been building GraphQL APIs I often had the need to have both a private and public API.\n\nThe private API is used for in-house products. Breaking changes can and will occur. It also includes types and fields specific to in-house application built around the API. The public API, however, is used by individuals not part of our organization. We cannot simply roll out breaking changes on the GraphQL API for those. Furthermore, they should only have access to a subset of the whole GraphQL graph. By generating a subgraph out of the internal graph we can hide stuff, without having to maintain and build two GraphQL schema.\n\n## Install instructions\n\nThis library requires `graphql` as a peer dependency and has a runtime dependency on `@graphql-tools/utils`.\n\n```bash\nyarn add -E @n1ru4l/graphql-public-schema-filter\n```\n\n## Usage Instructions\n\nThis library is designed to be inclusive for anyone within the GraphQL.js ecosystem. It supports both the SDL `makeExecutableSchema` and code-first via extension fields flow.\n\nThere is no delegation or validation overhead when executing against the newly generated schema. It is highly recommended to built the public schema during server-startup and not on the fly during incoming requests.\n\n### Code-First\n\nAnnotate types and fields that should be public with the `isPublic` extension.\n\n```ts\nimport { GraphQLObjectType, GraphQLString } from \"graphql\";\nimport { buildPublicSchema } from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst GraphQLQueryType = new GraphQLObjectType({\n  name: \"Query\",\n  fields: {\n    hello: {\n      type: GraphQLString,\n      resolve: () => \"hi\",\n      extensions: {\n        isPublic: true,\n      },\n    },\n    secret: {\n      type: GraphQLString,\n      resolve: () => \"sup\",\n    },\n  },\n});\n\nconst privateSchema = new GraphQLSchema({\n  query: GraphQLQueryType,\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\nYou can also find this example within `examples/src/schema.ts`.\n\n### SDL-First\n\nInstead of using the extension fields, we use the `@public` directive.\n\n```tsx\nimport { makeExecutableSchema } from \"@graphql-tools/schema\";\nimport {\n  publicDirectiveSDL,\n  buildPublicSchema,\n} from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst source = /* GraphQL */ `\n  type Query {\n    hello: String @public\n    secret: String\n  }\n`;\n\nconst privateSchema = makeExecutableSchema({\n  typeDefs: [publicDirectiveSDL, source],\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\n## FAQ\n\n### Why `isPublic` and `@public` over `isPrivate` and `@private`?\n\nDeny-listing is more prone to errors than allow-listing. By adding a directive/extension field we explicitly set something to public. The other way around it is easier to forgot to add a `@private`/ `isPrivate` annotation, which would automatically result in the new fields being public. Being verbose about what fields are public is the safest way.\n\n### Why is the no more granular control that allows building multiple unique public schemas?\n\nI considered this at the beginning, but in practice we never had a use for this. Having multiple public schemas requires maintaining a lot of documentation. In our use-case we only have a public and a private schema. There is still role based access for the public schema. certain users are not allowed to select specific fields. Instead of hiding those fields for those users we instead deny operations that select fields the users are not allowed to select before even executing it with the [envelop `useOperationFieldPermissions` plugin](https://www.envelop.dev/plugins/use-operation-field-permissions).\n\nYou can overwrite the `isPublic` function which is used to determine whether a field or type is public based on directives and extensions. This allows to fully customize the behavior based on your needs.\n\n```ts\ntype SharedExtensionAndDirectiveInformation = {\n  extensions?: Maybe<{\n    [attributeName: string]: any;\n  }>;\n  astNode?: Maybe<\n    Readonly<{\n      directives?: ReadonlyArray<DirectiveNode>;\n    }>\n  >;\n};\n\nexport const defaultIsPublic = (\n  input: SharedExtensionAndDirectiveInformation\n): boolean =>\n  input.extensions?.[\"isPublic\"] === true ||\n  !!input.astNode?.directives?.find(\n    (directive) => directive.name.value === \"public\"\n  );\n```\n\n## License\n\nMIT\n","readmeFilename":"README.md","_id":"@n1ru4l/graphql-public-schema-filter@1.0.0-alpha-20220928122357-14cc304","_nodeVersion":"18.9.1","_npmVersion":"8.19.1","dist":{"integrity":"sha512-iaUsladHQ80rhbEzgfTuqs9Dy/B5/baRPQtzlxtMYytmtDs2PeE76M7ffzTnEFleAkQd4+8VvOFWFP2hwtU0xQ==","shasum":"43c775eb58756294613d1404cb156a851fd20819","tarball":"https://registry.npmjs.org/@n1ru4l/graphql-public-schema-filter/-/graphql-public-schema-filter-1.0.0-alpha-20220928122357-14cc304.tgz","fileCount":12,"unpackedSize":43552,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIEGzb94nphJbQviCvmYyKrkSXPSN/EfyX5tWVIziz4m2AiA2SYih51jsZo3YfvBmuq0GwQcwtXQOAPRvo4K93AhU7w=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjNDzlACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqkHg//dMe9+zVMJ/NkSIAGzvKaSQcMYNyB6rCqfr57ETJxCvG4b3Nr\r\nCIIttoo/FhVRJYjt3r8ooR34OFSTlL9dLqvbJiMxP225P+y0fdBGsHIOACVh\r\nJDOb43gTJobrk6roTcVK+gkalc6k9W5lY6Ki/Of/vhEap5CoT6QNVpWyb1qM\r\nQ8DQDLtb83WpCaYBzE7At6XQANa1Nw0rHE/I8eIrH861RtwIZiLJB/i+KAmr\r\nCHIOqJUTDmEvTfrLgSMqSGliFu5+3yq7bFoLU7lhRmBn3GAkU3gQG1LB2JeU\r\nBUW+AjELWMnSXIyeyDk9EfocnAMpT7oC569Hehg5XKdrlIlylzCWesSOx8qe\r\nQBVZ8wHzCD4d/xwBaPz/lq9pjM0EGJ0LY5jWrjeRRzQYVxuvVVYL3+mPWT/z\r\nar4rgTqfxA23N0cesfjzTHmZD6oRjj20D0YegxX/N4TH7u1hVidaGAzG1Wkf\r\nntIablseZ3EGAbqXO/+aHTw18Up1PJ5SM7Xg2TyIGI+RWBv4nB/VWEd6bspk\r\neUFQIyFS9D0FYpsWAOWXH4G1Mlcoh362CHY8ZtuQoNaETv4p77ZrARtYza7V\r\nPiAGZSsv2M+YY+JGT9IVTW6/L8bQ2QUWtvkwHVLu5FiDTyiVNN1cHhaY29OR\r\nLqyKzAyy2wZRjIGwVKgFbPzxjaSjBeFmrng=\r\n=y15w\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"n1ru4l","email":"laurinquast@googlemail.com"},"directories":{},"maintainers":[{"name":"n1ru4l","email":"laurinquast@googlemail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/graphql-public-schema-filter_1.0.0-alpha-20220928122357-14cc304_1664367844915_0.6608819718577028"},"_hasShrinkwrap":false},"1.0.0":{"name":"@n1ru4l/graphql-public-schema-filter","version":"1.0.0","description":"Filter your GraphQL schema into a public schema.","peerDependencies":{"graphql":"16.x.x"},"dependencies":{"@graphql-tools/utils":"^8.0.0"},"author":{"name":"Laurin Quast","email":"laurinquast@googlemail.com","url":"https://github.com/n1ru4l"},"license":"MIT","main":"index.js","module":"index.mjs","typings":"index.d.ts","typescript":{"definition":"index.d.ts"},"exports":{".":{"require":"./index.js","import":"./index.mjs"},"./*":{"require":"./*.js","import":"./*.mjs"},"./package.json":"./package.json"},"gitHead":"58cfbeb8dc377ba0de6de961a250450ddd657d4c","_id":"@n1ru4l/graphql-public-schema-filter@1.0.0","_nodeVersion":"18.9.1","_npmVersion":"8.19.1","dist":{"integrity":"sha512-94kEXagQ/eeXQNjIzXhb+KbKX6IK8zHzs2cCLTXqPr0bq9Mx8M0NDQ0Sj1yye3T3dh9H8b9M+1o+f6duCZGcGQ==","shasum":"b0f13d366b8227762307d35823cd2212ea35f97d","tarball":"https://registry.npmjs.org/@n1ru4l/graphql-public-schema-filter/-/graphql-public-schema-filter-1.0.0.tgz","fileCount":12,"unpackedSize":43523,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIB/3MckKveLl4ztbNAA4DDmvn78rXszCQoiokFa6SsQWAiBMQkXY67t+Kb9pYOmg73/muX784MopUWMxsVPkZeXYjQ=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjNE+YACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrlIxAAjDlywP+3nvXeIdISqGhPGrysx126fLn7lmPbtu9xwg6sycr6\r\nbmyvJdz09ngVOgJrymxPd9zVzPXMwdfUaUv/TZE9lEaEuygIsoq3fXNKANlb\r\nj5eehBLHVqjYDBNX63cey3If9pupoShrOkffE+XEq9tzuI8c1plqHbc4yivJ\r\nTNlTmgpu/QLtQ6dbcZanb5gVeyckHxshXMxyiiTC/ifY2UvGEJLppDMi76Ln\r\njGL7eR/zO7NSX7zUcghU11xcTepEoElXSlcJu2jPIYiVe8Yy3cYP20njlYBH\r\nv2z5iHZiFJwG7s556IU3hoil4+YOCfOVx6hMG48J0DrRe7P4/zCZYlPHe+cw\r\n7NlBNcmkNZ6H6q4azDmXCTGmS+zoVMVcHCPhTngumA/ffo/b0Cl1DwYyiJ98\r\niYcs95DyZD+p5p5AO0nZTSWX20K08fgI2aHPYlXtTXKSZ0GSc01y8SRYSANp\r\nqDPViwlO8oDRH3THAU2EVmlW7LNRjtwvG/mooutCYwgyKoivqoSMN9l8MfKb\r\nrBZQQku+pLBM30iHH7qxFYB6z+iR/M8kSBH87ugNHlQH3h5v5h/NM5lweh8P\r\ngftLC11oAqMqLCQcEY6h5kTH1w+smEtBmMWRUNgPD03VKoROdt0zMJJiDDak\r\nbYDw54YE08QLrKP0IprztGud5K9XGT1FRTQ=\r\n=f3HN\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"n1ru4l","email":"laurinquast@googlemail.com"},"directories":{},"maintainers":[{"name":"n1ru4l","email":"laurinquast@googlemail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/graphql-public-schema-filter_1.0.0_1664372632670_0.9300533238573747"},"_hasShrinkwrap":false},"1.1.0-alpha-20221124104716-188eb70":{"name":"@n1ru4l/graphql-public-schema-filter","version":"1.1.0-alpha-20221124104716-188eb70","description":"Filter your GraphQL schema into a public schema.","peerDependencies":{"graphql":"16.x.x"},"dependencies":{"@graphql-tools/utils":"^8.0.0"},"author":{"name":"Laurin Quast","email":"laurinquast@googlemail.com","url":"https://github.com/n1ru4l"},"license":"MIT","main":"index.js","module":"index.mjs","typings":"index.d.ts","typescript":{"definition":"index.d.ts"},"exports":{".":{"require":"./index.js","import":"./index.mjs"},"./*":{"require":"./*.js","import":"./*.mjs"},"./package.json":"./package.json"},"gitHead":"188eb7059c9957afde2fb8351586e2fc5b295c72","readme":"# @n1ru4l/graphql-public-schema-filter\n\nThis library allows filtering an existing GraphQL schema down into a subset of the original schema. It supports both the code first development flow of building GraphQL schemas (via GraphQL extension fields) and the SDL first development flow (via schema directives).\n\nThe implementation is smart and warns the user if the processed annotations would result in an invalid schema such as:\n\n- Object Type without fields\n- Field whose type is not part of the schema\n\nIf such a scenario is encountered the implementation will propagate and hide all fields/types that use types that are not marked as public or that would be invalid.\n\n## Why would you need this?\n\nAs I have been building GraphQL APIs I often had the need to have both a private and public API.\n\nThe private API is used for in-house products. Breaking changes can and will occur. It also includes types and fields specific to in-house application built around the API. The public API, however, is used by individuals not part of our organization. We cannot simply roll out breaking changes on the GraphQL API for those. Furthermore, they should only have access to a subset of the whole GraphQL graph. By generating a subgraph out of the internal graph we can hide stuff, without having to maintain and build two GraphQL schema.\n\n## Install instructions\n\nThis library requires `graphql` as a peer dependency and has a runtime dependency on `@graphql-tools/utils`.\n\n```bash\nyarn add -E @n1ru4l/graphql-public-schema-filter\n```\n\n## Usage Instructions\n\nThis library is designed to be inclusive for anyone within the GraphQL.js ecosystem. It supports both the SDL `makeExecutableSchema` and code-first via extension fields flow.\n\nThere is no delegation or validation overhead when executing against the newly generated schema. It is highly recommended to built the public schema during server-startup and not on the fly during incoming requests.\n\n### Code-First\n\nAnnotate types and fields that should be public with the `isPublic` extension.\n\n```ts\nimport { GraphQLObjectType, GraphQLString } from \"graphql\";\nimport { buildPublicSchema } from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst GraphQLQueryType = new GraphQLObjectType({\n  name: \"Query\",\n  fields: {\n    hello: {\n      type: GraphQLString,\n      resolve: () => \"hi\",\n      extensions: {\n        isPublic: true,\n      },\n    },\n    secret: {\n      type: GraphQLString,\n      resolve: () => \"sup\",\n    },\n  },\n});\n\nconst privateSchema = new GraphQLSchema({\n  query: GraphQLQueryType,\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\nYou can also find this example within `examples/src/schema.ts`.\n\n### SDL-First\n\nInstead of using the extension fields, we use the `@public` directive.\n\n```tsx\nimport { makeExecutableSchema } from \"@graphql-tools/schema\";\nimport {\n  publicDirectiveSDL,\n  buildPublicSchema,\n} from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst source = /* GraphQL */ `\n  type Query {\n    hello: String @public\n    secret: String\n  }\n`;\n\nconst privateSchema = makeExecutableSchema({\n  typeDefs: [publicDirectiveSDL, source],\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\n## FAQ\n\n### Why `isPublic` and `@public` over `isPrivate` and `@private`?\n\nDeny-listing is more prone to errors than allow-listing. By adding a directive/extension field we explicitly set something to public. The other way around it is easier to forgot to add a `@private`/ `isPrivate` annotation, which would automatically result in the new fields being public. Being verbose about what fields are public is the safest way.\n\n### Why is the no more granular control that allows building multiple unique public schemas?\n\nI considered this at the beginning, but in practice we never had a use for this. Having multiple public schemas requires maintaining a lot of documentation. In our use-case we only have a public and a private schema. There is still role based access for the public schema. certain users are not allowed to select specific fields. Instead of hiding those fields for those users we instead deny operations that select fields the users are not allowed to select before even executing it with the [envelop `useOperationFieldPermissions` plugin](https://www.envelop.dev/plugins/use-operation-field-permissions).\n\nYou can overwrite the `isPublic` function which is used to determine whether a field or type is public based on directives and extensions. This allows to fully customize the behavior based on your needs.\n\n```ts\ntype SharedExtensionAndDirectiveInformation = {\n  extensions?: Maybe<{\n    [attributeName: string]: any;\n  }>;\n  astNode?: Maybe<\n    Readonly<{\n      directives?: ReadonlyArray<DirectiveNode>;\n    }>\n  >;\n};\n\nexport const defaultIsPublic = (\n  input: SharedExtensionAndDirectiveInformation\n): boolean =>\n  input.extensions?.[\"isPublic\"] === true ||\n  !!input.astNode?.directives?.find(\n    (directive) => directive.name.value === \"public\"\n  );\n```\n\n## License\n\nMIT\n","readmeFilename":"README.md","_id":"@n1ru4l/graphql-public-schema-filter@1.1.0-alpha-20221124104716-188eb70","_nodeVersion":"18.12.1","_npmVersion":"8.19.2","dist":{"integrity":"sha512-2eUES9NAeYAzrzAhTgOwHxRK0onTCLSHQVGIZSzTMVTyMhGilEHgMKWMEFTVlbeFOI1AABzB4C1RGvsjHhc7og==","shasum":"5fd7cef869e1e6200d1abcce4294e6d679f5521e","tarball":"https://registry.npmjs.org/@n1ru4l/graphql-public-schema-filter/-/graphql-public-schema-filter-1.1.0-alpha-20221124104716-188eb70.tgz","fileCount":12,"unpackedSize":44309,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIG6DB1cwK3PJZf5ziLlultEnZsP17iU6L05qyphT5/mdAiEA9p7ET2pO0gFvEb20dCj2g0wjOQdzcfEN0eRWa3d3Yso="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjf0u+ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoI4w//ZCuwCAQCIqJ2vVR5dCsFIZgWk1GP9wSdKSRqiNdxvo/068GH\r\nOnTg9gb9br1ciXK9Dbql5DlG0D86vCqECVkJfiahgu0Utj5iTUeS6eLdkylP\r\nVIgXQGMz7BQJSyZwzQMoXvCJp38ogi/FTxsU8fU7Ukoy4Gxdvn/uQsUpblhG\r\ngfZrnpEYZw/xZ2we3++jt7h+hGObyD2nCkj+n40qx1qbT+wUmsAkzaVr6dir\r\neUo20l8WLLkTaUTrS+APvXbJfs/+Zb2+AIV9RhYs/9V5qNGRa01bVGJcyA6F\r\nOYPMFYIOh0t4uBKd+LgspD5k6kOiM8YInCx3QudKULRBbmEZyfEZFe+C34g2\r\naLB70UXHYDL9hDCFImKzqRIiPvhFBbQoItVNAHLXJysbWaECPbh+hr8NnrS8\r\npxGzBKBBhhSW5TlY/GUgO33cN7w0ZUePJyh5TKkRTodLj5OCs47jDsfPhyLv\r\nV1aQghT/+vhA49drTcyV2wYUBfTOriEKnGa7+OkUO96BUkYtQ3SUiWJJctMs\r\npJm86UmaPV/1UkRklp3fbmUDHkpwQBVzrQqYVOV8nk1yFDZLBOUwCVvmPnPm\r\nC9DOZ6lDjpn+OsMlw3sp2Op/vXAcqLsl/6KQGqm1LkJygLKl8TmHAYWjh9Ce\r\ntzdAMtWqVJYgurJjIEs+gNB1AJu6WDJClQs=\r\n=rWtg\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"n1ru4l","email":"laurinquast@googlemail.com"},"directories":{},"maintainers":[{"name":"n1ru4l","email":"laurinquast@googlemail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/graphql-public-schema-filter_1.1.0-alpha-20221124104716-188eb70_1669286846134_0.14436966837768206"},"_hasShrinkwrap":false},"1.1.0-alpha-20221125113817-e6a165a":{"name":"@n1ru4l/graphql-public-schema-filter","version":"1.1.0-alpha-20221125113817-e6a165a","description":"Filter your GraphQL schema into a public schema.","peerDependencies":{"graphql":"16.x.x"},"dependencies":{"@graphql-tools/utils":"^8.0.0"},"author":{"name":"Laurin Quast","email":"laurinquast@googlemail.com","url":"https://github.com/n1ru4l"},"license":"MIT","main":"index.js","module":"index.mjs","typings":"index.d.ts","typescript":{"definition":"index.d.ts"},"exports":{".":{"require":"./index.js","import":"./index.mjs"},"./*":{"require":"./*.js","import":"./*.mjs"},"./package.json":"./package.json"},"gitHead":"e6a165ad0b3518fdc0c1bc7fb9dcc8323e878958","readme":"# @n1ru4l/graphql-public-schema-filter\n\nThis library allows filtering an existing GraphQL schema down into a subset of the original schema. It supports both the code first development flow of building GraphQL schemas (via GraphQL extension fields) and the SDL first development flow (via schema directives).\n\nThe implementation is smart and warns the user if the processed annotations would result in an invalid schema such as:\n\n- Object Type without fields\n- Field whose type is not part of the schema\n\nIf such a scenario is encountered the implementation will propagate and hide all fields/types that use types that are not marked as public or that would be invalid.\n\n## Why would you need this?\n\nAs I have been building GraphQL APIs I often had the need to have both a private and public API.\n\nThe private API is used for in-house products. Breaking changes can and will occur. It also includes types and fields specific to in-house application built around the API. The public API, however, is used by individuals not part of our organization. We cannot simply roll out breaking changes on the GraphQL API for those. Furthermore, they should only have access to a subset of the whole GraphQL graph. By generating a subgraph out of the internal graph we can hide stuff, without having to maintain and build two GraphQL schema.\n\n## Install instructions\n\nThis library requires `graphql` as a peer dependency and has a runtime dependency on `@graphql-tools/utils`.\n\n```bash\nyarn add -E @n1ru4l/graphql-public-schema-filter\n```\n\n## Usage Instructions\n\nThis library is designed to be inclusive for anyone within the GraphQL.js ecosystem. It supports both the SDL `makeExecutableSchema` and code-first via extension fields flow.\n\nThere is no delegation or validation overhead when executing against the newly generated schema. It is highly recommended to built the public schema during server-startup and not on the fly during incoming requests.\n\n### Code-First\n\nAnnotate types and fields that should be public with the `isPublic` extension.\n\n```ts\nimport { GraphQLObjectType, GraphQLString } from \"graphql\";\nimport { buildPublicSchema } from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst GraphQLQueryType = new GraphQLObjectType({\n  name: \"Query\",\n  fields: {\n    hello: {\n      type: GraphQLString,\n      resolve: () => \"hi\",\n      extensions: {\n        isPublic: true,\n      },\n    },\n    secret: {\n      type: GraphQLString,\n      resolve: () => \"sup\",\n    },\n  },\n});\n\nconst privateSchema = new GraphQLSchema({\n  query: GraphQLQueryType,\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\nYou can also find this example within `examples/src/schema.ts`.\n\n### SDL-First\n\nInstead of using the extension fields, we use the `@public` directive.\n\n```tsx\nimport { makeExecutableSchema } from \"@graphql-tools/schema\";\nimport {\n  publicDirectiveSDL,\n  buildPublicSchema,\n} from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst source = /* GraphQL */ `\n  type Query {\n    hello: String @public\n    secret: String\n  }\n`;\n\nconst privateSchema = makeExecutableSchema({\n  typeDefs: [publicDirectiveSDL, source],\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\n## FAQ\n\n### Why `isPublic` and `@public` over `isPrivate` and `@private`?\n\nDeny-listing is more prone to errors than allow-listing. By adding a directive/extension field we explicitly set something to public. The other way around it is easier to forgot to add a `@private`/ `isPrivate` annotation, which would automatically result in the new fields being public. Being verbose about what fields are public is the safest way.\n\n### Why is the no more granular control that allows building multiple unique public schemas?\n\nI considered this at the beginning, but in practice we never had a use for this. Having multiple public schemas requires maintaining a lot of documentation. In our use-case we only have a public and a private schema. There is still role based access for the public schema. certain users are not allowed to select specific fields. Instead of hiding those fields for those users we instead deny operations that select fields the users are not allowed to select before even executing it with the [envelop `useOperationFieldPermissions` plugin](https://www.envelop.dev/plugins/use-operation-field-permissions).\n\nYou can overwrite the `isPublic` function which is used to determine whether a field or type is public based on directives and extensions. This allows to fully customize the behavior based on your needs.\n\n```ts\ntype SharedExtensionAndDirectiveInformation = {\n  extensions?: Maybe<{\n    [attributeName: string]: any;\n  }>;\n  astNode?: Maybe<\n    Readonly<{\n      directives?: ReadonlyArray<DirectiveNode>;\n    }>\n  >;\n};\n\nexport const defaultIsPublic = (\n  input: SharedExtensionAndDirectiveInformation\n): boolean =>\n  input.extensions?.[\"isPublic\"] === true ||\n  !!input.astNode?.directives?.find(\n    (directive) => directive.name.value === \"public\"\n  );\n```\n\n## License\n\nMIT\n","readmeFilename":"README.md","_id":"@n1ru4l/graphql-public-schema-filter@1.1.0-alpha-20221125113817-e6a165a","_nodeVersion":"18.12.1","_npmVersion":"8.19.2","dist":{"integrity":"sha512-6/HKsazJIyJWHvbicUwT24rnpx3Gqe8ueNoju0T/xOD/iW78vDoL+sdOuIuyBC6BzCH1eZHO9n1SbVjTWUzH1A==","shasum":"cdcbb33820822dc94a650fde0e356e62dc6f1fca","tarball":"https://registry.npmjs.org/@n1ru4l/graphql-public-schema-filter/-/graphql-public-schema-filter-1.1.0-alpha-20221125113817-e6a165a.tgz","fileCount":12,"unpackedSize":44309,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIE3jPYv3yQn2gygTgOyiEPLVZv8gtwgn08C7Bsxh3Et2AiAWzoTxmf3YyXJkWkN17pBooKH+JRpXZ/M3P9kVZQ5OsA=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjgKkyACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoZXA/+L7w6T8wRAThEp2k4vWKJY0u7tqYbSnhqWOIw4lrayHGqRUdL\r\nzM8oMnxcb0K1/SHyUmbwaiUXWNOAOTfQ4JLpChIifwwke0wWYifuHLkMhNBR\r\nyZaPLqzAGFJcGIxGHtVQpmp7gdwq5vruAa6Yudyj3ANicL4Q/7sr2AzZj9vf\r\nOlSKxj5icriDf9QX73tn6nesUNinLKFXfDLV54GYwptOMgxmmdmqyYuFeI/M\r\nlPwGMGKyNxvlIkzrkGRvzX/ukSgyyrgMk+cJX1x6JHBsyGAAIhF3R3j/YKtI\r\ndRpHrN0YAT+4JuXHcSryubPZDnJ0+X9LSE2Cyvv09Ak85Rvme9NnAKHpbfC0\r\nzVkXEcNJtXjU9NE93vwR5JU4LeaA/a7ipVzyJH8TonZtQdRMaOPoei5VXo5b\r\nAPyUufEViZ/jZc0vRRDQxrtpoEpqjMjmyjuhwDwj25dzNtcjU2qgS/ZYltBK\r\n18jnhNhKfGxP9vTsySnKoDxQa3ikTpNL8rl3einL94j3l4tPAtej3tzLInYb\r\nxZFOdNbXBsKvANI5VycDuW5Dap+xoIkr8bPGbCwm9bfhhz2zIDi1buubHwvX\r\nnGttKrAcD5miwq9io1H3tH4vWu/8Z1214MHDaTUM4Ybfch9KXF6Iu/Mol8Ow\r\nr7NyIdnQoz0hsqhWLVPutCXMlMTUQl/qBGo=\r\n=lWNx\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"n1ru4l","email":"laurinquast@googlemail.com"},"directories":{},"maintainers":[{"name":"n1ru4l","email":"laurinquast@googlemail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/graphql-public-schema-filter_1.1.0-alpha-20221125113817-e6a165a_1669376306095_0.6146261262607879"},"_hasShrinkwrap":false},"1.1.0-alpha-20221128184529-1e76543":{"name":"@n1ru4l/graphql-public-schema-filter","version":"1.1.0-alpha-20221128184529-1e76543","description":"Filter your GraphQL schema into a public schema.","peerDependencies":{"graphql":"16.x.x"},"dependencies":{"@graphql-tools/utils":"^8.0.0"},"author":{"name":"Laurin Quast","email":"laurinquast@googlemail.com","url":"https://github.com/n1ru4l"},"license":"MIT","main":"index.js","module":"index.mjs","typings":"index.d.ts","typescript":{"definition":"index.d.ts"},"exports":{".":{"require":"./index.js","import":"./index.mjs"},"./*":{"require":"./*.js","import":"./*.mjs"},"./package.json":"./package.json"},"gitHead":"1e76543a2273a184643b2a82c352870c8ab1b7a7","readme":"# @n1ru4l/graphql-public-schema-filter\n\nThis library allows filtering an existing GraphQL schema down into a subset of the original schema. It supports both the code first development flow of building GraphQL schemas (via GraphQL extension fields) and the SDL first development flow (via schema directives).\n\nThe implementation is smart and warns the user if the processed annotations would result in an invalid schema such as:\n\n- Object Type without fields\n- Field whose type is not part of the schema\n\nIf such a scenario is encountered the implementation will propagate and hide all fields/types that use types that are not marked as public or that would be invalid.\n\n## Why would you need this?\n\nAs I have been building GraphQL APIs I often had the need to have both a private and public API.\n\nThe private API is used for in-house products. Breaking changes can and will occur. It also includes types and fields specific to in-house application built around the API. The public API, however, is used by individuals not part of our organization. We cannot simply roll out breaking changes on the GraphQL API for those. Furthermore, they should only have access to a subset of the whole GraphQL graph. By generating a subgraph out of the internal graph we can hide stuff, without having to maintain and build two GraphQL schema.\n\n## Install instructions\n\nThis library requires `graphql` as a peer dependency and has a runtime dependency on `@graphql-tools/utils`.\n\n```bash\nyarn add -E @n1ru4l/graphql-public-schema-filter\n```\n\n## Usage Instructions\n\nThis library is designed to be inclusive for anyone within the GraphQL.js ecosystem. It supports both the SDL `makeExecutableSchema` and code-first via extension fields flow.\n\nThere is no delegation or validation overhead when executing against the newly generated schema. It is highly recommended to built the public schema during server-startup and not on the fly during incoming requests.\n\n### Code-First\n\nAnnotate types and fields that should be public with the `isPublic` extension.\n\n```ts\nimport { GraphQLObjectType, GraphQLString } from \"graphql\";\nimport { buildPublicSchema } from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst GraphQLQueryType = new GraphQLObjectType({\n  name: \"Query\",\n  fields: {\n    hello: {\n      type: GraphQLString,\n      resolve: () => \"hi\",\n      extensions: {\n        isPublic: true,\n      },\n    },\n    secret: {\n      type: GraphQLString,\n      resolve: () => \"sup\",\n    },\n  },\n});\n\nconst privateSchema = new GraphQLSchema({\n  query: GraphQLQueryType,\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\nYou can also find this example within `examples/src/schema.ts`.\n\n### SDL-First\n\nInstead of using the extension fields, we use the `@public` directive.\n\n```tsx\nimport { makeExecutableSchema } from \"@graphql-tools/schema\";\nimport {\n  publicDirectiveSDL,\n  buildPublicSchema,\n} from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst source = /* GraphQL */ `\n  type Query {\n    hello: String @public\n    secret: String\n  }\n`;\n\nconst privateSchema = makeExecutableSchema({\n  typeDefs: [publicDirectiveSDL, source],\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\n## FAQ\n\n### Why `isPublic` and `@public` over `isPrivate` and `@private`?\n\nDeny-listing is more prone to errors than allow-listing. By adding a directive/extension field we explicitly set something to public. The other way around it is easier to forgot to add a `@private`/ `isPrivate` annotation, which would automatically result in the new fields being public. Being verbose about what fields are public is the safest way.\n\n### Why is the no more granular control that allows building multiple unique public schemas?\n\nI considered this at the beginning, but in practice we never had a use for this. Having multiple public schemas requires maintaining a lot of documentation. In our use-case we only have a public and a private schema. There is still role based access for the public schema. certain users are not allowed to select specific fields. Instead of hiding those fields for those users we instead deny operations that select fields the users are not allowed to select before even executing it with the [envelop `useOperationFieldPermissions` plugin](https://www.envelop.dev/plugins/use-operation-field-permissions).\n\nYou can overwrite the `isPublic` function which is used to determine whether a field or type is public based on directives and extensions. This allows to fully customize the behavior based on your needs.\n\n```ts\ntype SharedExtensionAndDirectiveInformation = {\n  extensions?: Maybe<{\n    [attributeName: string]: any;\n  }>;\n  astNode?: Maybe<\n    Readonly<{\n      directives?: ReadonlyArray<DirectiveNode>;\n    }>\n  >;\n};\n\nexport const defaultIsPublic = (\n  input: SharedExtensionAndDirectiveInformation\n): boolean =>\n  input.extensions?.[\"isPublic\"] === true ||\n  !!input.astNode?.directives?.find(\n    (directive) => directive.name.value === \"public\"\n  );\n```\n\n## License\n\nMIT\n","readmeFilename":"README.md","_id":"@n1ru4l/graphql-public-schema-filter@1.1.0-alpha-20221128184529-1e76543","_nodeVersion":"18.12.1","_npmVersion":"8.19.2","dist":{"integrity":"sha512-DCAH2Vp2F+42I0m8+SctdymNxslgr7iqxqfLq0nLO071sZAoCRJEyU73WmoFN/9x2Gn3dNvi+UexEQbZxMCkLA==","shasum":"520a5a9be27fe0aeca43abc2e7befbe10456b089","tarball":"https://registry.npmjs.org/@n1ru4l/graphql-public-schema-filter/-/graphql-public-schema-filter-1.1.0-alpha-20221128184529-1e76543.tgz","fileCount":12,"unpackedSize":44309,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDwaiViS3erUE4l357AAEObbD5Zfv9+uTkQlWT4u6YOgQIhAOFWEc+qoFQAoC90lG/1h8HmvcraELDf5irUFHWXl7GP"}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjhQHTACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpurBAAohoMSxRpic887HE4sVeL3ASUzwb+9QKfPlri2gg1FIbI/JF/\r\njKn/0ODgkV7ZQ3G5NIcRsl5BEM/0Vzkw5w5IzfwXsCZFo0xHNqw9Ev9Bum5E\r\n/lBrFKOoI7DNXZ0jaQ+jQat2/uZEL6TeyWIRSO9YSkklh/uYStn5qtlh1+2D\r\nUm+9Y1blEHfYB4I9ZAasSbBImCKokRPRlmh5DF/V58MV7cGBWFAMY+89hbTT\r\nNc0AYxvSvy04hpSRMEZIwNulv8u0OjWEK1pvBckS0LJHJzk8yGcYxUIkdl7C\r\nSn8Ii4SJGkFP7ExJM78vqD/NkcYVdpNOh6zy3xgP/2H5q2h1iXkka9vpnttX\r\n7Xov8giYT1nInaPmojeHXxywD+NT5EJvO0uSaOVUGzg414es8C11dBs4IwGZ\r\nL5Akp4H4b7k+uFXY5bW4iOTYn/BoC72XQBDpol7oyZUpZIKBbLieT1ry17Q8\r\nWtjT2NRxSURDiSJTyDtClTVKss+KWtnd/ZnfB00ubRjktwN4k27nbzfN1C6r\r\nwBlYF/09yp8rx63pqVXgNDNdWlOunTUImNPHo5SMPUffbWKbWoqZZVioqRCC\r\nBMVhrDawjZfqrIIvfYMSyvWLi8Ms8sOpcCMdeVRXiTCofZr63mEjv9/Zl4Ln\r\neXUtjOHIAnTjjuaLCA/aijG2QXmnqywIxuo=\r\n=8KI8\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"n1ru4l","email":"laurinquast@googlemail.com"},"directories":{},"maintainers":[{"name":"n1ru4l","email":"laurinquast@googlemail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/graphql-public-schema-filter_1.1.0-alpha-20221128184529-1e76543_1669661139590_0.5838456266994465"},"_hasShrinkwrap":false},"1.1.0-alpha-20221130233145-9e0e08d":{"name":"@n1ru4l/graphql-public-schema-filter","version":"1.1.0-alpha-20221130233145-9e0e08d","description":"Filter your GraphQL schema into a public schema.","peerDependencies":{"graphql":"16.x.x"},"dependencies":{"@graphql-tools/utils":"^8.0.0"},"author":{"name":"Laurin Quast","email":"laurinquast@googlemail.com","url":"https://github.com/n1ru4l"},"license":"MIT","main":"index.js","module":"index.mjs","typings":"index.d.ts","typescript":{"definition":"index.d.ts"},"exports":{".":{"require":"./index.js","import":"./index.mjs"},"./*":{"require":"./*.js","import":"./*.mjs"},"./package.json":"./package.json"},"gitHead":"9e0e08d6ef429c21a8a0ba10f1651d2b8d0e7795","readme":"# @n1ru4l/graphql-public-schema-filter\n\nThis library allows filtering an existing GraphQL schema down into a subset of the original schema. It supports both the code first development flow of building GraphQL schemas (via GraphQL extension fields) and the SDL first development flow (via schema directives).\n\nThe implementation is smart and warns the user if the processed annotations would result in an invalid schema such as:\n\n- Object Type without fields\n- Field whose type is not part of the schema\n\nIf such a scenario is encountered the implementation will propagate and hide all fields/types that use types that are not marked as public or that would be invalid.\n\n## Why would you need this?\n\nAs I have been building GraphQL APIs I often had the need to have both a private and public API.\n\nThe private API is used for in-house products. Breaking changes can and will occur. It also includes types and fields specific to in-house application built around the API. The public API, however, is used by individuals not part of our organization. We cannot simply roll out breaking changes on the GraphQL API for those. Furthermore, they should only have access to a subset of the whole GraphQL graph. By generating a subgraph out of the internal graph we can hide stuff, without having to maintain and build two GraphQL schema.\n\n## Install instructions\n\nThis library requires `graphql` as a peer dependency and has a runtime dependency on `@graphql-tools/utils`.\n\n```bash\nyarn add -E @n1ru4l/graphql-public-schema-filter\n```\n\n## Usage Instructions\n\nThis library is designed to be inclusive for anyone within the GraphQL.js ecosystem. It supports both the SDL `makeExecutableSchema` and code-first via extension fields flow.\n\nThere is no delegation or validation overhead when executing against the newly generated schema. It is highly recommended to built the public schema during server-startup and not on the fly during incoming requests.\n\n### Code-First\n\nAnnotate types and fields that should be public with the `isPublic` extension.\n\n```ts\nimport { GraphQLObjectType, GraphQLString } from \"graphql\";\nimport { buildPublicSchema } from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst GraphQLQueryType = new GraphQLObjectType({\n  name: \"Query\",\n  fields: {\n    hello: {\n      type: GraphQLString,\n      resolve: () => \"hi\",\n      extensions: {\n        isPublic: true,\n      },\n    },\n    secret: {\n      type: GraphQLString,\n      resolve: () => \"sup\",\n    },\n  },\n});\n\nconst privateSchema = new GraphQLSchema({\n  query: GraphQLQueryType,\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\nYou can also find this example within `examples/src/schema.ts`.\n\n### SDL-First\n\nInstead of using the extension fields, we use the `@public` directive.\n\n```tsx\nimport { makeExecutableSchema } from \"@graphql-tools/schema\";\nimport {\n  publicDirectiveSDL,\n  buildPublicSchema,\n} from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst source = /* GraphQL */ `\n  type Query {\n    hello: String @public\n    secret: String\n  }\n`;\n\nconst privateSchema = makeExecutableSchema({\n  typeDefs: [publicDirectiveSDL, source],\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\n## FAQ\n\n### Why `isPublic` and `@public` over `isPrivate` and `@private`?\n\nDeny-listing is more prone to errors than allow-listing. By adding a directive/extension field we explicitly set something to public. The other way around it is easier to forgot to add a `@private`/ `isPrivate` annotation, which would automatically result in the new fields being public. Being verbose about what fields are public is the safest way.\n\n### Why is the no more granular control that allows building multiple unique public schemas?\n\nI considered this at the beginning, but in practice we never had a use for this. Having multiple public schemas requires maintaining a lot of documentation. In our use-case we only have a public and a private schema. There is still role based access for the public schema. certain users are not allowed to select specific fields. Instead of hiding those fields for those users we instead deny operations that select fields the users are not allowed to select before even executing it with the [envelop `useOperationFieldPermissions` plugin](https://www.envelop.dev/plugins/use-operation-field-permissions).\n\nYou can overwrite the `isPublic` function which is used to determine whether a field or type is public based on directives and extensions. This allows to fully customize the behavior based on your needs.\n\n```ts\ntype SharedExtensionAndDirectiveInformation = {\n  extensions?: Maybe<{\n    [attributeName: string]: any;\n  }>;\n  astNode?: Maybe<\n    Readonly<{\n      directives?: ReadonlyArray<DirectiveNode>;\n    }>\n  >;\n};\n\nexport const defaultIsPublic = (\n  input: SharedExtensionAndDirectiveInformation\n): boolean =>\n  input.extensions?.[\"isPublic\"] === true ||\n  !!input.astNode?.directives?.find(\n    (directive) => directive.name.value === \"public\"\n  );\n```\n\n## License\n\nMIT\n","readmeFilename":"README.md","_id":"@n1ru4l/graphql-public-schema-filter@1.1.0-alpha-20221130233145-9e0e08d","_nodeVersion":"18.12.1","_npmVersion":"8.19.2","dist":{"integrity":"sha512-+lKcBoHNPvu5KDctrDNQ4NvoKg8bFKcj3xeN0U74wFhGmhiNFjJoy4S9w1w8oD9SFBw9t/BfY+aS78RqwXJwQg==","shasum":"7d75604f819e3cc25a5d5514eebc7f9566e7d5ca","tarball":"https://registry.npmjs.org/@n1ru4l/graphql-public-schema-filter/-/graphql-public-schema-filter-1.1.0-alpha-20221130233145-9e0e08d.tgz","fileCount":12,"unpackedSize":44309,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCNViLIBkh+b3Rwi3Tau71Ktm7hxzU1Xhc3NT7cOj88sgIhAMpygVhpGrWCRrFJHjlVHnDDfzz6Dm1OkEs3mTUbzTcd"}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjh+fpACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqKCQ/+J5T8QdW4pHTXPfATVwnpUT1jg43fk5kJp3tVyTtVhGJGmXEf\r\ny8JJAeMJx7+VXXrjCk91QSq2g56RgvX7L0wHS48GPiWO7Q4x+FFB1T7ed46X\r\nnE6UTLHfSfS9knmMXtY8JU3xGYcoLBqJEwXTaHQ1W8rnU0Durx5Ay16apIGa\r\nM0nRo5uLcrsZLGwk54BBrQqftpCxYRcr6i3Gs+r5puTFiq3KvcHLrfrTBQEP\r\nrRdlgNdS6n6z8zmPV/vbTZK49P8wB3gClcZbPEhrsfjzcPj5fioXQKioQLOp\r\nOZOqCuucmQMh3dxw3Y/jBBbn9TpUQd0EfPah+3wiQUAnFMVoKNg3kjs8GbbD\r\ndaCRfpvdALpvhL2HBs9mJGosH4i0+PigBI0U47sj9byh1ByYoZz0q9aXB2uA\r\nVTxbm9xCUhxcjOFgiydcDFtembSecZsCumKdzO7S4oLi+mhQdNHf891u4ay3\r\n7whom0XJQJChuLOsZ90tZEJE/rSVTd6NdPFZF1hTYzTgq+Fz2wEC5KcI0kn+\r\nvnuIw7mv1k0eYIE04LSjS5Eipw40Z46ldB0DmOVImkwk9NsRLQsU59nMRxRE\r\nXrwRYiI/6or6FQM4E++K0e6agUpmnQ/hyIjFyIocQNhPqpdaJsbrAhTL4I0n\r\n3zbx07zhWqCa8lP2LbUiWiOabilkUa8DBeo=\r\n=EoFd\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"n1ru4l","email":"laurinquast@googlemail.com"},"directories":{},"maintainers":[{"name":"n1ru4l","email":"laurinquast@googlemail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/graphql-public-schema-filter_1.1.0-alpha-20221130233145-9e0e08d_1669851113346_0.31535426518253384"},"_hasShrinkwrap":false},"1.1.0":{"name":"@n1ru4l/graphql-public-schema-filter","version":"1.1.0","description":"Filter your GraphQL schema into a public schema.","peerDependencies":{"graphql":"16.x.x"},"dependencies":{"@graphql-tools/utils":"^8.0.0"},"author":{"name":"Laurin Quast","email":"laurinquast@googlemail.com","url":"https://github.com/n1ru4l"},"license":"MIT","main":"index.js","module":"index.mjs","typings":"index.d.ts","typescript":{"definition":"index.d.ts"},"exports":{".":{"require":"./index.js","import":"./index.mjs"},"./*":{"require":"./*.js","import":"./*.mjs"},"./package.json":"./package.json"},"gitHead":"84e76a645003182a9d5643f0b46b6c1b34c0b3a8","_id":"@n1ru4l/graphql-public-schema-filter@1.1.0","_nodeVersion":"18.12.1","_npmVersion":"8.19.2","dist":{"integrity":"sha512-ZPOehjKujY/IxS1wkyVjGbiSnB+pmqe5cDiT7cCOtX6qQRJiADGHK9CP0N76oKSangeEey5OYPFl3BZ5UtV/jQ==","shasum":"be9300ef7a6dbe3160b6947b0a7565adc8d201bd","tarball":"https://registry.npmjs.org/@n1ru4l/graphql-public-schema-filter/-/graphql-public-schema-filter-1.1.0.tgz","fileCount":12,"unpackedSize":44583,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIEFWEFZAZl5gAygH7Gj7cDra7WOTkPYmtO4GE52K+4lkAiAfdTOjVlzMnmxR9GeNHGlD0iAz9RyxplvwnZ/L/6WDKw=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjiiNKACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrLlA/9H9Kv7WD/GA9qFA4dXuzgWJH6RfFeewxDUuaRCqcx7I8kOkTI\r\nkQgPueAakeE0zIksjgauTefylQhQvDUE0Hxdb9wEuPCdXjW8lp467pg3XSxq\r\nVtQb+o3n8+DGVER1iuyDGL0LinpriTrTh+spC6mepVTS51jXnI+VBH87xCjK\r\nSlH/YuuhECjsH7cHm5Cc+ljxhIyd/q+DHc0uXoQUlQnAGEUUgcwyyIxdulN7\r\nYV1rMDQyJ+U/7IMCGMtO8O3Eb20L13lzslr9LX/lJJcxiwe0f00KBRCdhsju\r\nv/WhNiowccF+29GFlYjmpVzeFdja5aseK/KaCn9kTNvyf4BUudKXwpivWWkc\r\nooFNZQBLDA6PkAwjscaqij7xDfdNpfpSGsI5adfcHQbZJH82IIzbwpX3O6ml\r\n9WuSdHiegU616nleL+5qYe8kKBRZcecMkr3rnK6ypcJ5D3iNnN7iTIwtmV6n\r\nRu+o38NrcB3TKJOFwU9bF3j6iGU9tMETV9TpUXCS7bWbtqz914TGqtXXg7wE\r\nBfP22wupDzw4kkYYsb4U9BmPHq3l1kRuh2/yfUq8SSArfSYCZFLXnUrUw2gs\r\nyBx+Fzjt8UI9wJmsizv+Wjrejw2JfD00xg0aG3DLEMEAsRtM4Yseg7v8uqgY\r\nNnSDrnsW9xEbdzxjk4XFUyqoOR1A+8Rgc7M=\r\n=cXhd\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"n1ru4l","email":"laurinquast@googlemail.com"},"directories":{},"maintainers":[{"name":"n1ru4l","email":"laurinquast@googlemail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/graphql-public-schema-filter_1.1.0_1669997386011_0.4326009521233247"},"_hasShrinkwrap":false},"2.0.0-alpha-20230506173925-b7dc957":{"name":"@n1ru4l/graphql-public-schema-filter","version":"2.0.0-alpha-20230506173925-b7dc957","description":"Filter your GraphQL schema into a public schema.","peerDependencies":{"graphql":"16.x.x"},"dependencies":{"@graphql-tools/utils":"^8.0.0"},"author":{"name":"Laurin Quast","email":"laurinquast@googlemail.com","url":"https://github.com/n1ru4l"},"license":"MIT","main":"cjs/index.js","module":"esm/index.js","typings":"typings/index.d.ts","typescript":{"definition":"typings/index.d.ts"},"exports":{".":{"require":{"types":"./typings/index.d.cts","default":"./cjs/index.js"},"import":{"types":"./typings/index.d.ts","default":"./esm/index.js"},"default":{"types":"./typings/index.d.ts","default":"./esm/index.js"}},"./*":{"require":"./cjs/*.js","import":"./esm/*.js","default":"./esm/*.js"}},"gitHead":"b7dc957e2a24586e0339eca966056999c7721477","readme":"# @n1ru4l/graphql-public-schema-filter\n\nThis library allows filtering an existing GraphQL schema down into a subset of the original schema. It supports both the code first development flow of building GraphQL schemas (via GraphQL extension fields) and the SDL first development flow (via schema directives).\n\nThe implementation is smart and warns the user if the processed annotations would result in an invalid schema such as:\n\n- Object Type without fields\n- Field whose type is not part of the schema\n\nIf such a scenario is encountered the implementation will propagate and hide all fields/types that use types that are not marked as public or that would be invalid.\n\n## Why would you need this?\n\nAs I have been building GraphQL APIs I often had the need to have both a private and public API.\n\nThe private API is used for in-house products. Breaking changes can and will occur. It also includes types and fields specific to in-house application built around the API. The public API, however, is used by individuals not part of our organization. We cannot simply roll out breaking changes on the GraphQL API for those. Furthermore, they should only have access to a subset of the whole GraphQL graph. By generating a subgraph out of the internal graph we can hide stuff, without having to maintain and build two GraphQL schema.\n\n## Install instructions\n\nThis library requires `graphql` as a peer dependency and has a runtime dependency on `@graphql-tools/utils`.\n\n```bash\nyarn add -E @n1ru4l/graphql-public-schema-filter\n```\n\n## Usage Instructions\n\nThis library is designed to be inclusive for anyone within the GraphQL.js ecosystem. It supports both the SDL `makeExecutableSchema` and code-first via extension fields flow.\n\nThere is no delegation or validation overhead when executing against the newly generated schema. It is highly recommended to built the public schema during server-startup and not on the fly during incoming requests.\n\n### Code-First\n\nAnnotate types and fields that should be public with the `isPublic` extension.\n\n```ts\nimport { GraphQLObjectType, GraphQLString } from \"graphql\";\nimport { buildPublicSchema } from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst GraphQLQueryType = new GraphQLObjectType({\n  name: \"Query\",\n  fields: {\n    hello: {\n      type: GraphQLString,\n      resolve: () => \"hi\",\n      extensions: {\n        isPublic: true,\n      },\n    },\n    secret: {\n      type: GraphQLString,\n      resolve: () => \"sup\",\n    },\n  },\n});\n\nconst privateSchema = new GraphQLSchema({\n  query: GraphQLQueryType,\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\nYou can also find this example within `examples/src/schema.ts`.\n\n### SDL-First\n\nInstead of using the extension fields, we use the `@public` directive.\n\n```tsx\nimport { makeExecutableSchema } from \"@graphql-tools/schema\";\nimport {\n  publicDirectiveSDL,\n  buildPublicSchema,\n} from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst source = /* GraphQL */ `\n  type Query {\n    hello: String @public\n    secret: String\n  }\n`;\n\nconst privateSchema = makeExecutableSchema({\n  typeDefs: [publicDirectiveSDL, source],\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\n## FAQ\n\n### Why `isPublic` and `@public` over `isPrivate` and `@private`?\n\nDeny-listing is more prone to errors than allow-listing. By adding a directive/extension field we explicitly set something to public. The other way around it is easier to forgot to add a `@private`/ `isPrivate` annotation, which would automatically result in the new fields being public. Being verbose about what fields are public is the safest way.\n\n### Why is the no more granular control that allows building multiple unique public schemas?\n\nI considered this at the beginning, but in practice we never had a use for this. Having multiple public schemas requires maintaining a lot of documentation. In our use-case we only have a public and a private schema. There is still role based access for the public schema. certain users are not allowed to select specific fields. Instead of hiding those fields for those users we instead deny operations that select fields the users are not allowed to select before even executing it with the [envelop `useOperationFieldPermissions` plugin](https://www.envelop.dev/plugins/use-operation-field-permissions).\n\nYou can overwrite the `isPublic` function which is used to determine whether a field or type is public based on directives and extensions. This allows to fully customize the behavior based on your needs.\n\n```ts\ntype SharedExtensionAndDirectiveInformation = {\n  extensions?: Maybe<{\n    [attributeName: string]: any;\n  }>;\n  astNode?: Maybe<\n    Readonly<{\n      directives?: ReadonlyArray<DirectiveNode>;\n    }>\n  >;\n};\n\nexport const defaultIsPublic = (\n  input: SharedExtensionAndDirectiveInformation\n): boolean =>\n  input.extensions?.[\"isPublic\"] === true ||\n  !!input.astNode?.directives?.find(\n    (directive) => directive.name.value === \"public\"\n  );\n```\n\n## License\n\nMIT\n","readmeFilename":"README.md","_id":"@n1ru4l/graphql-public-schema-filter@2.0.0-alpha-20230506173925-b7dc957","_nodeVersion":"18.16.0","_npmVersion":"9.5.1","dist":{"integrity":"sha512-xTqTE4CKjQNcW4LrMj4jIYrig9fGO9aZlYbh8VgKZpmM2b33yETQN9s6uCaKGT4XyCM+G9SFT3YTy8VXmzWaAw==","shasum":"9b0c1032d3a75810ce4ec9f939bac0145b02aff2","tarball":"https://registry.npmjs.org/@n1ru4l/graphql-public-schema-filter/-/graphql-public-schema-filter-2.0.0-alpha-20230506173925-b7dc957.tgz","fileCount":20,"unpackedSize":36713,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIE8QayiWUu1G7Xwg2Y0TMbG/yi5msKIRHnBanCUqtUkyAiBvI+2E5EkCfwg1WDfWGdkpxV4/0v1yshmTtlpVT9QIKw=="}]},"_npmUser":{"name":"n1ru4l","email":"laurinquast@googlemail.com"},"directories":{},"maintainers":[{"name":"n1ru4l","email":"laurinquast@googlemail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/graphql-public-schema-filter_2.0.0-alpha-20230506173925-b7dc957_1683394774624_0.1087640065935418"},"_hasShrinkwrap":false},"2.0.0-alpha-20230506174140-24e9153":{"name":"@n1ru4l/graphql-public-schema-filter","version":"2.0.0-alpha-20230506174140-24e9153","description":"Filter your GraphQL schema into a public schema.","peerDependencies":{"graphql":"16.x.x"},"dependencies":{"@graphql-tools/utils":"^8.0.0"},"author":{"name":"Laurin Quast","email":"laurinquast@googlemail.com","url":"https://github.com/n1ru4l"},"license":"MIT","main":"cjs/index.js","module":"esm/index.js","typings":"typings/index.d.ts","typescript":{"definition":"typings/index.d.ts"},"exports":{".":{"require":{"types":"./typings/index.d.cts","default":"./cjs/index.js"},"import":{"types":"./typings/index.d.ts","default":"./esm/index.js"},"default":{"types":"./typings/index.d.ts","default":"./esm/index.js"}},"./*":{"require":"./cjs/*.js","import":"./esm/*.js","default":"./esm/*.js"}},"gitHead":"24e915301067cf9fe01a54dd6a0cf1c5be5c3e41","readme":"# @n1ru4l/graphql-public-schema-filter\n\nThis library allows filtering an existing GraphQL schema down into a subset of the original schema. It supports both the code first development flow of building GraphQL schemas (via GraphQL extension fields) and the SDL first development flow (via schema directives).\n\nThe implementation is smart and warns the user if the processed annotations would result in an invalid schema such as:\n\n- Object Type without fields\n- Field whose type is not part of the schema\n\nIf such a scenario is encountered the implementation will propagate and hide all fields/types that use types that are not marked as public or that would be invalid.\n\n## Why would you need this?\n\nAs I have been building GraphQL APIs I often had the need to have both a private and public API.\n\nThe private API is used for in-house products. Breaking changes can and will occur. It also includes types and fields specific to in-house application built around the API. The public API, however, is used by individuals not part of our organization. We cannot simply roll out breaking changes on the GraphQL API for those. Furthermore, they should only have access to a subset of the whole GraphQL graph. By generating a subgraph out of the internal graph we can hide stuff, without having to maintain and build two GraphQL schema.\n\n## Install instructions\n\nThis library requires `graphql` as a peer dependency and has a runtime dependency on `@graphql-tools/utils`.\n\n```bash\nyarn add -E @n1ru4l/graphql-public-schema-filter\n```\n\n## Usage Instructions\n\nThis library is designed to be inclusive for anyone within the GraphQL.js ecosystem. It supports both the SDL `makeExecutableSchema` and code-first via extension fields flow.\n\nThere is no delegation or validation overhead when executing against the newly generated schema. It is highly recommended to built the public schema during server-startup and not on the fly during incoming requests.\n\n### Code-First\n\nAnnotate types and fields that should be public with the `isPublic` extension.\n\n```ts\nimport { GraphQLObjectType, GraphQLString } from \"graphql\";\nimport { buildPublicSchema } from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst GraphQLQueryType = new GraphQLObjectType({\n  name: \"Query\",\n  fields: {\n    hello: {\n      type: GraphQLString,\n      resolve: () => \"hi\",\n      extensions: {\n        isPublic: true,\n      },\n    },\n    secret: {\n      type: GraphQLString,\n      resolve: () => \"sup\",\n    },\n  },\n});\n\nconst privateSchema = new GraphQLSchema({\n  query: GraphQLQueryType,\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\nYou can also find this example within `examples/src/schema.ts`.\n\n### SDL-First\n\nInstead of using the extension fields, we use the `@public` directive.\n\n```tsx\nimport { makeExecutableSchema } from \"@graphql-tools/schema\";\nimport {\n  publicDirectiveSDL,\n  buildPublicSchema,\n} from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst source = /* GraphQL */ `\n  type Query {\n    hello: String @public\n    secret: String\n  }\n`;\n\nconst privateSchema = makeExecutableSchema({\n  typeDefs: [publicDirectiveSDL, source],\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\n## FAQ\n\n### Why `isPublic` and `@public` over `isPrivate` and `@private`?\n\nDeny-listing is more prone to errors than allow-listing. By adding a directive/extension field we explicitly set something to public. The other way around it is easier to forgot to add a `@private`/ `isPrivate` annotation, which would automatically result in the new fields being public. Being verbose about what fields are public is the safest way.\n\n### Why is the no more granular control that allows building multiple unique public schemas?\n\nI considered this at the beginning, but in practice we never had a use for this. Having multiple public schemas requires maintaining a lot of documentation. In our use-case we only have a public and a private schema. There is still role based access for the public schema. certain users are not allowed to select specific fields. Instead of hiding those fields for those users we instead deny operations that select fields the users are not allowed to select before even executing it with the [envelop `useOperationFieldPermissions` plugin](https://www.envelop.dev/plugins/use-operation-field-permissions).\n\nYou can overwrite the `isPublic` function which is used to determine whether a field or type is public based on directives and extensions. This allows to fully customize the behavior based on your needs.\n\n```ts\ntype SharedExtensionAndDirectiveInformation = {\n  extensions?: Maybe<{\n    [attributeName: string]: any;\n  }>;\n  astNode?: Maybe<\n    Readonly<{\n      directives?: ReadonlyArray<DirectiveNode>;\n    }>\n  >;\n};\n\nexport const defaultIsPublic = (\n  input: SharedExtensionAndDirectiveInformation\n): boolean =>\n  input.extensions?.[\"isPublic\"] === true ||\n  !!input.astNode?.directives?.find(\n    (directive) => directive.name.value === \"public\"\n  );\n```\n\n## License\n\nMIT\n","readmeFilename":"README.md","_id":"@n1ru4l/graphql-public-schema-filter@2.0.0-alpha-20230506174140-24e9153","_nodeVersion":"18.16.0","_npmVersion":"9.5.1","dist":{"integrity":"sha512-eAPOWNzKRwgF4r60+TpyEPYx+kcmiTRQofJ3aWkXbXV/er+NR4FGu9rqGiSRguBa2IcA6qlnQVtJGmra9u9H+g==","shasum":"a7ca02c8cfd9f36e147906ffa00607ac528b8470","tarball":"https://registry.npmjs.org/@n1ru4l/graphql-public-schema-filter/-/graphql-public-schema-filter-2.0.0-alpha-20230506174140-24e9153.tgz","fileCount":20,"unpackedSize":36713,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDNQOqS+uIGsRJYJ6ogtPgWk1UaO3fW7xHoVPcZqj4hAQIhAN02hCcUL49nutkFW+aSCS32xaMnPPoIsPKrRts+rF52"}]},"_npmUser":{"name":"n1ru4l","email":"laurinquast@googlemail.com"},"directories":{},"maintainers":[{"name":"n1ru4l","email":"laurinquast@googlemail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/graphql-public-schema-filter_2.0.0-alpha-20230506174140-24e9153_1683394907597_0.9179943184078605"},"_hasShrinkwrap":false},"2.0.0-alpha-20230506174210-d334620":{"name":"@n1ru4l/graphql-public-schema-filter","version":"2.0.0-alpha-20230506174210-d334620","description":"Filter your GraphQL schema into a public schema.","peerDependencies":{"graphql":"16.x.x"},"dependencies":{"@graphql-tools/utils":"^8.0.0"},"author":{"name":"Laurin Quast","email":"laurinquast@googlemail.com","url":"https://github.com/n1ru4l"},"license":"MIT","main":"cjs/index.js","module":"esm/index.js","typings":"typings/index.d.ts","typescript":{"definition":"typings/index.d.ts"},"exports":{".":{"require":{"types":"./typings/index.d.cts","default":"./cjs/index.js"},"import":{"types":"./typings/index.d.ts","default":"./esm/index.js"},"default":{"types":"./typings/index.d.ts","default":"./esm/index.js"}},"./*":{"require":"./cjs/*.js","import":"./esm/*.js","default":"./esm/*.js"}},"gitHead":"d33462002e87b6bb3e3531d7f00642c8501279d5","readme":"# @n1ru4l/graphql-public-schema-filter\n\nThis library allows filtering an existing GraphQL schema down into a subset of the original schema. It supports both the code first development flow of building GraphQL schemas (via GraphQL extension fields) and the SDL first development flow (via schema directives).\n\nThe implementation is smart and warns the user if the processed annotations would result in an invalid schema such as:\n\n- Object Type without fields\n- Field whose type is not part of the schema\n\nIf such a scenario is encountered the implementation will propagate and hide all fields/types that use types that are not marked as public or that would be invalid.\n\n## Why would you need this?\n\nAs I have been building GraphQL APIs I often had the need to have both a private and public API.\n\nThe private API is used for in-house products. Breaking changes can and will occur. It also includes types and fields specific to in-house application built around the API. The public API, however, is used by individuals not part of our organization. We cannot simply roll out breaking changes on the GraphQL API for those. Furthermore, they should only have access to a subset of the whole GraphQL graph. By generating a subgraph out of the internal graph we can hide stuff, without having to maintain and build two GraphQL schema.\n\n## Install instructions\n\nThis library requires `graphql` as a peer dependency and has a runtime dependency on `@graphql-tools/utils`.\n\n```bash\nyarn add -E @n1ru4l/graphql-public-schema-filter\n```\n\n## Usage Instructions\n\nThis library is designed to be inclusive for anyone within the GraphQL.js ecosystem. It supports both the SDL `makeExecutableSchema` and code-first via extension fields flow.\n\nThere is no delegation or validation overhead when executing against the newly generated schema. It is highly recommended to built the public schema during server-startup and not on the fly during incoming requests.\n\n### Code-First\n\nAnnotate types and fields that should be public with the `isPublic` extension.\n\n```ts\nimport { GraphQLObjectType, GraphQLString } from \"graphql\";\nimport { buildPublicSchema } from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst GraphQLQueryType = new GraphQLObjectType({\n  name: \"Query\",\n  fields: {\n    hello: {\n      type: GraphQLString,\n      resolve: () => \"hi\",\n      extensions: {\n        isPublic: true,\n      },\n    },\n    secret: {\n      type: GraphQLString,\n      resolve: () => \"sup\",\n    },\n  },\n});\n\nconst privateSchema = new GraphQLSchema({\n  query: GraphQLQueryType,\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\nYou can also find this example within `examples/src/schema.ts`.\n\n### SDL-First\n\nInstead of using the extension fields, we use the `@public` directive.\n\n```tsx\nimport { makeExecutableSchema } from \"@graphql-tools/schema\";\nimport {\n  publicDirectiveSDL,\n  buildPublicSchema,\n} from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst source = /* GraphQL */ `\n  type Query {\n    hello: String @public\n    secret: String\n  }\n`;\n\nconst privateSchema = makeExecutableSchema({\n  typeDefs: [publicDirectiveSDL, source],\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\n## FAQ\n\n### Why `isPublic` and `@public` over `isPrivate` and `@private`?\n\nDeny-listing is more prone to errors than allow-listing. By adding a directive/extension field we explicitly set something to public. The other way around it is easier to forgot to add a `@private`/ `isPrivate` annotation, which would automatically result in the new fields being public. Being verbose about what fields are public is the safest way.\n\n### Why is the no more granular control that allows building multiple unique public schemas?\n\nI considered this at the beginning, but in practice we never had a use for this. Having multiple public schemas requires maintaining a lot of documentation. In our use-case we only have a public and a private schema. There is still role based access for the public schema. certain users are not allowed to select specific fields. Instead of hiding those fields for those users we instead deny operations that select fields the users are not allowed to select before even executing it with the [envelop `useOperationFieldPermissions` plugin](https://www.envelop.dev/plugins/use-operation-field-permissions).\n\nYou can overwrite the `isPublic` function which is used to determine whether a field or type is public based on directives and extensions. This allows to fully customize the behavior based on your needs.\n\n```ts\ntype SharedExtensionAndDirectiveInformation = {\n  extensions?: Maybe<{\n    [attributeName: string]: any;\n  }>;\n  astNode?: Maybe<\n    Readonly<{\n      directives?: ReadonlyArray<DirectiveNode>;\n    }>\n  >;\n};\n\nexport const defaultIsPublic = (\n  input: SharedExtensionAndDirectiveInformation\n): boolean =>\n  input.extensions?.[\"isPublic\"] === true ||\n  !!input.astNode?.directives?.find(\n    (directive) => directive.name.value === \"public\"\n  );\n```\n\n## License\n\nMIT\n","readmeFilename":"README.md","_id":"@n1ru4l/graphql-public-schema-filter@2.0.0-alpha-20230506174210-d334620","_nodeVersion":"18.16.0","_npmVersion":"9.5.1","dist":{"integrity":"sha512-Y9qOztlDVtPhklLg6K1mzYk33gLkrqeZPyUUQlo00SyDZthcfRvgUvASTg1WIHJxlK+nEPRzmmBwwKzi2QrIyg==","shasum":"9ed34cf8e0a04d0fd5a157859177ce40b0c2aa0e","tarball":"https://registry.npmjs.org/@n1ru4l/graphql-public-schema-filter/-/graphql-public-schema-filter-2.0.0-alpha-20230506174210-d334620.tgz","fileCount":20,"unpackedSize":36713,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCGoGuzqZOclT5aUCnrslHzCkXNWZTgyp5HSOkpZvKRTgIhAOtTYtTvwTGNxLJ9xJpB+OA+M+oHickEQTiPv1qpJ7Bo"}]},"_npmUser":{"name":"n1ru4l","email":"laurinquast@googlemail.com"},"directories":{},"maintainers":[{"name":"n1ru4l","email":"laurinquast@googlemail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/graphql-public-schema-filter_2.0.0-alpha-20230506174210-d334620_1683394939539_0.20301632594811392"},"_hasShrinkwrap":false},"2.0.0-alpha-20230506174240-a16e2a7":{"name":"@n1ru4l/graphql-public-schema-filter","version":"2.0.0-alpha-20230506174240-a16e2a7","description":"Filter your GraphQL schema into a public schema.","peerDependencies":{"graphql":"16.x.x"},"dependencies":{"@graphql-tools/utils":"^8.0.0"},"author":{"name":"Laurin Quast","email":"laurinquast@googlemail.com","url":"https://github.com/n1ru4l"},"license":"MIT","main":"cjs/index.js","module":"esm/index.js","typings":"typings/index.d.ts","typescript":{"definition":"typings/index.d.ts"},"exports":{".":{"require":{"types":"./typings/index.d.cts","default":"./cjs/index.js"},"import":{"types":"./typings/index.d.ts","default":"./esm/index.js"},"default":{"types":"./typings/index.d.ts","default":"./esm/index.js"}},"./*":{"require":"./cjs/*.js","import":"./esm/*.js","default":"./esm/*.js"}},"gitHead":"a16e2a7648c9e5bb1d6b69182bb2cb4b89b2ede6","readme":"# @n1ru4l/graphql-public-schema-filter\n\nThis library allows filtering an existing GraphQL schema down into a subset of the original schema. It supports both the code first development flow of building GraphQL schemas (via GraphQL extension fields) and the SDL first development flow (via schema directives).\n\nThe implementation is smart and warns the user if the processed annotations would result in an invalid schema such as:\n\n- Object Type without fields\n- Field whose type is not part of the schema\n\nIf such a scenario is encountered the implementation will propagate and hide all fields/types that use types that are not marked as public or that would be invalid.\n\n## Why would you need this?\n\nAs I have been building GraphQL APIs I often had the need to have both a private and public API.\n\nThe private API is used for in-house products. Breaking changes can and will occur. It also includes types and fields specific to in-house application built around the API. The public API, however, is used by individuals not part of our organization. We cannot simply roll out breaking changes on the GraphQL API for those. Furthermore, they should only have access to a subset of the whole GraphQL graph. By generating a subgraph out of the internal graph we can hide stuff, without having to maintain and build two GraphQL schema.\n\n## Install instructions\n\nThis library requires `graphql` as a peer dependency and has a runtime dependency on `@graphql-tools/utils`.\n\n```bash\nyarn add -E @n1ru4l/graphql-public-schema-filter\n```\n\n## Usage Instructions\n\nThis library is designed to be inclusive for anyone within the GraphQL.js ecosystem. It supports both the SDL `makeExecutableSchema` and code-first via extension fields flow.\n\nThere is no delegation or validation overhead when executing against the newly generated schema. It is highly recommended to built the public schema during server-startup and not on the fly during incoming requests.\n\n### Code-First\n\nAnnotate types and fields that should be public with the `isPublic` extension.\n\n```ts\nimport { GraphQLObjectType, GraphQLString } from \"graphql\";\nimport { buildPublicSchema } from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst GraphQLQueryType = new GraphQLObjectType({\n  name: \"Query\",\n  fields: {\n    hello: {\n      type: GraphQLString,\n      resolve: () => \"hi\",\n      extensions: {\n        isPublic: true,\n      },\n    },\n    secret: {\n      type: GraphQLString,\n      resolve: () => \"sup\",\n    },\n  },\n});\n\nconst privateSchema = new GraphQLSchema({\n  query: GraphQLQueryType,\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\nYou can also find this example within `examples/src/schema.ts`.\n\n### SDL-First\n\nInstead of using the extension fields, we use the `@public` directive.\n\n```tsx\nimport { makeExecutableSchema } from \"@graphql-tools/schema\";\nimport {\n  publicDirectiveSDL,\n  buildPublicSchema,\n} from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst source = /* GraphQL */ `\n  type Query {\n    hello: String @public\n    secret: String\n  }\n`;\n\nconst privateSchema = makeExecutableSchema({\n  typeDefs: [publicDirectiveSDL, source],\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\n## FAQ\n\n### Why `isPublic` and `@public` over `isPrivate` and `@private`?\n\nDeny-listing is more prone to errors than allow-listing. By adding a directive/extension field we explicitly set something to public. The other way around it is easier to forgot to add a `@private`/ `isPrivate` annotation, which would automatically result in the new fields being public. Being verbose about what fields are public is the safest way.\n\n### Why is the no more granular control that allows building multiple unique public schemas?\n\nI considered this at the beginning, but in practice we never had a use for this. Having multiple public schemas requires maintaining a lot of documentation. In our use-case we only have a public and a private schema. There is still role based access for the public schema. certain users are not allowed to select specific fields. Instead of hiding those fields for those users we instead deny operations that select fields the users are not allowed to select before even executing it with the [envelop `useOperationFieldPermissions` plugin](https://www.envelop.dev/plugins/use-operation-field-permissions).\n\nYou can overwrite the `isPublic` function which is used to determine whether a field or type is public based on directives and extensions. This allows to fully customize the behavior based on your needs.\n\n```ts\ntype SharedExtensionAndDirectiveInformation = {\n  extensions?: Maybe<{\n    [attributeName: string]: any;\n  }>;\n  astNode?: Maybe<\n    Readonly<{\n      directives?: ReadonlyArray<DirectiveNode>;\n    }>\n  >;\n};\n\nexport const defaultIsPublic = (\n  input: SharedExtensionAndDirectiveInformation\n): boolean =>\n  input.extensions?.[\"isPublic\"] === true ||\n  !!input.astNode?.directives?.find(\n    (directive) => directive.name.value === \"public\"\n  );\n```\n\n## License\n\nMIT\n","readmeFilename":"README.md","_id":"@n1ru4l/graphql-public-schema-filter@2.0.0-alpha-20230506174240-a16e2a7","_nodeVersion":"18.16.0","_npmVersion":"9.5.1","dist":{"integrity":"sha512-NVWiZw/hx6IjitMR8CqbsZR84hXUYezXw+tAvcfo7bEWqdXhaCah/wJszq6+oy5V598o58f/1JSB+x1U3IjQ9Q==","shasum":"1beb31f567fa1b774da04dea85ba2f0e03d10e65","tarball":"https://registry.npmjs.org/@n1ru4l/graphql-public-schema-filter/-/graphql-public-schema-filter-2.0.0-alpha-20230506174240-a16e2a7.tgz","fileCount":20,"unpackedSize":36713,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDg2MvcgF5NgNd4HhdCnancz4J90UpMDaVOv8UYE1xskAIgD6eSE3vQmzwjnNKsrqERzuxjVkWdyOrKeh/0qm6gmlQ="}]},"_npmUser":{"name":"n1ru4l","email":"laurinquast@googlemail.com"},"directories":{},"maintainers":[{"name":"n1ru4l","email":"laurinquast@googlemail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/graphql-public-schema-filter_2.0.0-alpha-20230506174240-a16e2a7_1683394969358_0.6525619787873316"},"_hasShrinkwrap":false},"2.0.0-alpha-20230506174311-82eb981":{"name":"@n1ru4l/graphql-public-schema-filter","version":"2.0.0-alpha-20230506174311-82eb981","description":"Filter your GraphQL schema into a public schema.","peerDependencies":{"graphql":"16.x.x"},"dependencies":{"@graphql-tools/utils":"^8.0.0"},"author":{"name":"Laurin Quast","email":"laurinquast@googlemail.com","url":"https://github.com/n1ru4l"},"license":"MIT","main":"cjs/index.js","module":"esm/index.js","typings":"typings/index.d.ts","typescript":{"definition":"typings/index.d.ts"},"exports":{".":{"require":{"types":"./typings/index.d.cts","default":"./cjs/index.js"},"import":{"types":"./typings/index.d.ts","default":"./esm/index.js"},"default":{"types":"./typings/index.d.ts","default":"./esm/index.js"}},"./*":{"require":"./cjs/*.js","import":"./esm/*.js","default":"./esm/*.js"}},"gitHead":"82eb98151da5fffdd73a897e68578969a4ee6352","readme":"# @n1ru4l/graphql-public-schema-filter\n\nThis library allows filtering an existing GraphQL schema down into a subset of the original schema. It supports both the code first development flow of building GraphQL schemas (via GraphQL extension fields) and the SDL first development flow (via schema directives).\n\nThe implementation is smart and warns the user if the processed annotations would result in an invalid schema such as:\n\n- Object Type without fields\n- Field whose type is not part of the schema\n\nIf such a scenario is encountered the implementation will propagate and hide all fields/types that use types that are not marked as public or that would be invalid.\n\n## Why would you need this?\n\nAs I have been building GraphQL APIs I often had the need to have both a private and public API.\n\nThe private API is used for in-house products. Breaking changes can and will occur. It also includes types and fields specific to in-house application built around the API. The public API, however, is used by individuals not part of our organization. We cannot simply roll out breaking changes on the GraphQL API for those. Furthermore, they should only have access to a subset of the whole GraphQL graph. By generating a subgraph out of the internal graph we can hide stuff, without having to maintain and build two GraphQL schema.\n\n## Install instructions\n\nThis library requires `graphql` as a peer dependency and has a runtime dependency on `@graphql-tools/utils`.\n\n```bash\nyarn add -E @n1ru4l/graphql-public-schema-filter\n```\n\n## Usage Instructions\n\nThis library is designed to be inclusive for anyone within the GraphQL.js ecosystem. It supports both the SDL `makeExecutableSchema` and code-first via extension fields flow.\n\nThere is no delegation or validation overhead when executing against the newly generated schema. It is highly recommended to built the public schema during server-startup and not on the fly during incoming requests.\n\n### Code-First\n\nAnnotate types and fields that should be public with the `isPublic` extension.\n\n```ts\nimport { GraphQLObjectType, GraphQLString } from \"graphql\";\nimport { buildPublicSchema } from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst GraphQLQueryType = new GraphQLObjectType({\n  name: \"Query\",\n  fields: {\n    hello: {\n      type: GraphQLString,\n      resolve: () => \"hi\",\n      extensions: {\n        isPublic: true,\n      },\n    },\n    secret: {\n      type: GraphQLString,\n      resolve: () => \"sup\",\n    },\n  },\n});\n\nconst privateSchema = new GraphQLSchema({\n  query: GraphQLQueryType,\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\nYou can also find this example within `examples/src/schema.ts`.\n\n### SDL-First\n\nInstead of using the extension fields, we use the `@public` directive.\n\n```tsx\nimport { makeExecutableSchema } from \"@graphql-tools/schema\";\nimport {\n  publicDirectiveSDL,\n  buildPublicSchema,\n} from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst source = /* GraphQL */ `\n  type Query {\n    hello: String @public\n    secret: String\n  }\n`;\n\nconst privateSchema = makeExecutableSchema({\n  typeDefs: [publicDirectiveSDL, source],\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\n## FAQ\n\n### Why `isPublic` and `@public` over `isPrivate` and `@private`?\n\nDeny-listing is more prone to errors than allow-listing. By adding a directive/extension field we explicitly set something to public. The other way around it is easier to forgot to add a `@private`/ `isPrivate` annotation, which would automatically result in the new fields being public. Being verbose about what fields are public is the safest way.\n\n### Why is the no more granular control that allows building multiple unique public schemas?\n\nI considered this at the beginning, but in practice we never had a use for this. Having multiple public schemas requires maintaining a lot of documentation. In our use-case we only have a public and a private schema. There is still role based access for the public schema. certain users are not allowed to select specific fields. Instead of hiding those fields for those users we instead deny operations that select fields the users are not allowed to select before even executing it with the [envelop `useOperationFieldPermissions` plugin](https://www.envelop.dev/plugins/use-operation-field-permissions).\n\nYou can overwrite the `isPublic` function which is used to determine whether a field or type is public based on directives and extensions. This allows to fully customize the behavior based on your needs.\n\n```ts\ntype SharedExtensionAndDirectiveInformation = {\n  extensions?: Maybe<{\n    [attributeName: string]: any;\n  }>;\n  astNode?: Maybe<\n    Readonly<{\n      directives?: ReadonlyArray<DirectiveNode>;\n    }>\n  >;\n};\n\nexport const defaultIsPublic = (\n  input: SharedExtensionAndDirectiveInformation\n): boolean =>\n  input.extensions?.[\"isPublic\"] === true ||\n  !!input.astNode?.directives?.find(\n    (directive) => directive.name.value === \"public\"\n  );\n```\n\n## License\n\nMIT\n","readmeFilename":"README.md","_id":"@n1ru4l/graphql-public-schema-filter@2.0.0-alpha-20230506174311-82eb981","_nodeVersion":"18.16.0","_npmVersion":"9.5.1","dist":{"integrity":"sha512-UWUSRE2bS39uRFTCjAEBXZ8hbavRkptb0XsgHi890/6FmQ6/7v1zcB/JRAMOqC3AIx7wCat143xyJC8raYgxAw==","shasum":"bf51e60843ca39811d168beed4043ac353e7f2da","tarball":"https://registry.npmjs.org/@n1ru4l/graphql-public-schema-filter/-/graphql-public-schema-filter-2.0.0-alpha-20230506174311-82eb981.tgz","fileCount":20,"unpackedSize":36713,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCcLQOqF9S1vkMySHXnmoQaC20LbfFJqyMvbxBPH4k2rQIgf7AXan9P7rWmiCbZcuKW7pH2IyjD3V+zJnj9Ysvaq44="}]},"_npmUser":{"name":"n1ru4l","email":"laurinquast@googlemail.com"},"directories":{},"maintainers":[{"name":"n1ru4l","email":"laurinquast@googlemail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/graphql-public-schema-filter_2.0.0-alpha-20230506174311-82eb981_1683394998674_0.3348490454978128"},"_hasShrinkwrap":false},"2.0.0-alpha-20230506174324-4490b4d":{"name":"@n1ru4l/graphql-public-schema-filter","version":"2.0.0-alpha-20230506174324-4490b4d","description":"Filter your GraphQL schema into a public schema.","peerDependencies":{"graphql":"16.x.x"},"dependencies":{"@graphql-tools/utils":"^8.0.0"},"author":{"name":"Laurin Quast","email":"laurinquast@googlemail.com","url":"https://github.com/n1ru4l"},"license":"MIT","main":"cjs/index.js","module":"esm/index.js","typings":"typings/index.d.ts","typescript":{"definition":"typings/index.d.ts"},"exports":{".":{"require":{"types":"./typings/index.d.cts","default":"./cjs/index.js"},"import":{"types":"./typings/index.d.ts","default":"./esm/index.js"},"default":{"types":"./typings/index.d.ts","default":"./esm/index.js"}},"./*":{"require":"./cjs/*.js","import":"./esm/*.js","default":"./esm/*.js"}},"gitHead":"4490b4dd84300a759f2e05c926a9b9556ac32de9","readme":"# @n1ru4l/graphql-public-schema-filter\n\nThis library allows filtering an existing GraphQL schema down into a subset of the original schema. It supports both the code first development flow of building GraphQL schemas (via GraphQL extension fields) and the SDL first development flow (via schema directives).\n\nThe implementation is smart and warns the user if the processed annotations would result in an invalid schema such as:\n\n- Object Type without fields\n- Field whose type is not part of the schema\n\nIf such a scenario is encountered the implementation will propagate and hide all fields/types that use types that are not marked as public or that would be invalid.\n\n## Why would you need this?\n\nAs I have been building GraphQL APIs I often had the need to have both a private and public API.\n\nThe private API is used for in-house products. Breaking changes can and will occur. It also includes types and fields specific to in-house application built around the API. The public API, however, is used by individuals not part of our organization. We cannot simply roll out breaking changes on the GraphQL API for those. Furthermore, they should only have access to a subset of the whole GraphQL graph. By generating a subgraph out of the internal graph we can hide stuff, without having to maintain and build two GraphQL schema.\n\n## Install instructions\n\nThis library requires `graphql` as a peer dependency and has a runtime dependency on `@graphql-tools/utils`.\n\n```bash\nyarn add -E @n1ru4l/graphql-public-schema-filter\n```\n\n## Usage Instructions\n\nThis library is designed to be inclusive for anyone within the GraphQL.js ecosystem. It supports both the SDL `makeExecutableSchema` and code-first via extension fields flow.\n\nThere is no delegation or validation overhead when executing against the newly generated schema. It is highly recommended to built the public schema during server-startup and not on the fly during incoming requests.\n\n### Code-First\n\nAnnotate types and fields that should be public with the `isPublic` extension.\n\n```ts\nimport { GraphQLObjectType, GraphQLString } from \"graphql\";\nimport { buildPublicSchema } from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst GraphQLQueryType = new GraphQLObjectType({\n  name: \"Query\",\n  fields: {\n    hello: {\n      type: GraphQLString,\n      resolve: () => \"hi\",\n      extensions: {\n        isPublic: true,\n      },\n    },\n    secret: {\n      type: GraphQLString,\n      resolve: () => \"sup\",\n    },\n  },\n});\n\nconst privateSchema = new GraphQLSchema({\n  query: GraphQLQueryType,\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\nYou can also find this example within `examples/src/schema.ts`.\n\n### SDL-First\n\nInstead of using the extension fields, we use the `@public` directive.\n\n```tsx\nimport { makeExecutableSchema } from \"@graphql-tools/schema\";\nimport {\n  publicDirectiveSDL,\n  buildPublicSchema,\n} from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst source = /* GraphQL */ `\n  type Query {\n    hello: String @public\n    secret: String\n  }\n`;\n\nconst privateSchema = makeExecutableSchema({\n  typeDefs: [publicDirectiveSDL, source],\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\n## FAQ\n\n### Why `isPublic` and `@public` over `isPrivate` and `@private`?\n\nDeny-listing is more prone to errors than allow-listing. By adding a directive/extension field we explicitly set something to public. The other way around it is easier to forgot to add a `@private`/ `isPrivate` annotation, which would automatically result in the new fields being public. Being verbose about what fields are public is the safest way.\n\n### Why is the no more granular control that allows building multiple unique public schemas?\n\nI considered this at the beginning, but in practice we never had a use for this. Having multiple public schemas requires maintaining a lot of documentation. In our use-case we only have a public and a private schema. There is still role based access for the public schema. certain users are not allowed to select specific fields. Instead of hiding those fields for those users we instead deny operations that select fields the users are not allowed to select before even executing it with the [envelop `useOperationFieldPermissions` plugin](https://www.envelop.dev/plugins/use-operation-field-permissions).\n\nYou can overwrite the `isPublic` function which is used to determine whether a field or type is public based on directives and extensions. This allows to fully customize the behavior based on your needs.\n\n```ts\ntype SharedExtensionAndDirectiveInformation = {\n  extensions?: Maybe<{\n    [attributeName: string]: any;\n  }>;\n  astNode?: Maybe<\n    Readonly<{\n      directives?: ReadonlyArray<DirectiveNode>;\n    }>\n  >;\n};\n\nexport const defaultIsPublic = (\n  input: SharedExtensionAndDirectiveInformation\n): boolean =>\n  input.extensions?.[\"isPublic\"] === true ||\n  !!input.astNode?.directives?.find(\n    (directive) => directive.name.value === \"public\"\n  );\n```\n\n## License\n\nMIT\n","readmeFilename":"README.md","_id":"@n1ru4l/graphql-public-schema-filter@2.0.0-alpha-20230506174324-4490b4d","_nodeVersion":"18.16.0","_npmVersion":"9.5.1","dist":{"integrity":"sha512-gtJjELTCJr/pWFgb8th1SdW/LdzUssmX6iMxW7kGKjL7eOv5KwJs2hVF/K8Zmwh+NswTbq33BJtCDihj8RVIcg==","shasum":"9cb36fd5476f9372df776c21c86d355dca2658b3","tarball":"https://registry.npmjs.org/@n1ru4l/graphql-public-schema-filter/-/graphql-public-schema-filter-2.0.0-alpha-20230506174324-4490b4d.tgz","fileCount":20,"unpackedSize":36713,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCpQ4VjBhY+/Fvzd4E5HYKgTN2CcN4uWGE3wMNC+wmiWgIhAMnVcnMDZ9FMSPdIANnI/mr/+h3jDiVWOhof4oMbHtGj"}]},"_npmUser":{"name":"n1ru4l","email":"laurinquast@googlemail.com"},"directories":{},"maintainers":[{"name":"n1ru4l","email":"laurinquast@googlemail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/graphql-public-schema-filter_2.0.0-alpha-20230506174324-4490b4d_1683395012488_0.9445424370640307"},"_hasShrinkwrap":false},"2.0.0-alpha-20230506175146-dfd01cb":{"name":"@n1ru4l/graphql-public-schema-filter","version":"2.0.0-alpha-20230506175146-dfd01cb","description":"Filter your GraphQL schema into a public schema.","peerDependencies":{"graphql":"16.x.x"},"dependencies":{"@graphql-tools/utils":"^8.0.0"},"author":{"name":"Laurin Quast","email":"laurinquast@googlemail.com","url":"https://github.com/n1ru4l"},"license":"MIT","main":"cjs/index.js","module":"esm/index.js","typings":"typings/index.d.ts","typescript":{"definition":"typings/index.d.ts"},"exports":{".":{"require":{"types":"./typings/index.d.cts","default":"./cjs/index.js"},"import":{"types":"./typings/index.d.ts","default":"./esm/index.js"},"default":{"types":"./typings/index.d.ts","default":"./esm/index.js"}},"./*":{"require":"./cjs/*.js","import":"./esm/*.js","default":"./esm/*.js"}},"gitHead":"dfd01cb8464c75bb42ab9cbfc93ec5f7c77becb1","readme":"# @n1ru4l/graphql-public-schema-filter\n\nThis library allows filtering an existing GraphQL schema down into a subset of the original schema. It supports both the code first development flow of building GraphQL schemas (via GraphQL extension fields) and the SDL first development flow (via schema directives).\n\nThe implementation is smart and warns the user if the processed annotations would result in an invalid schema such as:\n\n- Object Type without fields\n- Field whose type is not part of the schema\n\nIf such a scenario is encountered the implementation will propagate and hide all fields/types that use types that are not marked as public or that would be invalid.\n\n## Why would you need this?\n\nAs I have been building GraphQL APIs I often had the need to have both a private and public API.\n\nThe private API is used for in-house products. Breaking changes can and will occur. It also includes types and fields specific to in-house application built around the API. The public API, however, is used by individuals not part of our organization. We cannot simply roll out breaking changes on the GraphQL API for those. Furthermore, they should only have access to a subset of the whole GraphQL graph. By generating a subgraph out of the internal graph we can hide stuff, without having to maintain and build two GraphQL schema.\n\n## Install instructions\n\nThis library requires `graphql` as a peer dependency and has a runtime dependency on `@graphql-tools/utils`.\n\n```bash\nyarn add -E @n1ru4l/graphql-public-schema-filter\n```\n\n## Usage Instructions\n\nThis library is designed to be inclusive for anyone within the GraphQL.js ecosystem. It supports both the SDL `makeExecutableSchema` and code-first via extension fields flow.\n\nThere is no delegation or validation overhead when executing against the newly generated schema. It is highly recommended to built the public schema during server-startup and not on the fly during incoming requests.\n\n### Code-First\n\nAnnotate types and fields that should be public with the `isPublic` extension.\n\n```ts\nimport { GraphQLObjectType, GraphQLString } from \"graphql\";\nimport { buildPublicSchema } from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst GraphQLQueryType = new GraphQLObjectType({\n  name: \"Query\",\n  fields: {\n    hello: {\n      type: GraphQLString,\n      resolve: () => \"hi\",\n      extensions: {\n        isPublic: true,\n      },\n    },\n    secret: {\n      type: GraphQLString,\n      resolve: () => \"sup\",\n    },\n  },\n});\n\nconst privateSchema = new GraphQLSchema({\n  query: GraphQLQueryType,\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\nYou can also find this example within `examples/src/schema.ts`.\n\n### SDL-First\n\nInstead of using the extension fields, we use the `@public` directive.\n\n```tsx\nimport { makeExecutableSchema } from \"@graphql-tools/schema\";\nimport {\n  publicDirectiveSDL,\n  buildPublicSchema,\n} from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst source = /* GraphQL */ `\n  type Query {\n    hello: String @public\n    secret: String\n  }\n`;\n\nconst privateSchema = makeExecutableSchema({\n  typeDefs: [publicDirectiveSDL, source],\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\n## FAQ\n\n### Why `isPublic` and `@public` over `isPrivate` and `@private`?\n\nDeny-listing is more prone to errors than allow-listing. By adding a directive/extension field we explicitly set something to public. The other way around it is easier to forgot to add a `@private`/ `isPrivate` annotation, which would automatically result in the new fields being public. Being verbose about what fields are public is the safest way.\n\n### Why is the no more granular control that allows building multiple unique public schemas?\n\nI considered this at the beginning, but in practice we never had a use for this. Having multiple public schemas requires maintaining a lot of documentation. In our use-case we only have a public and a private schema. There is still role based access for the public schema. certain users are not allowed to select specific fields. Instead of hiding those fields for those users we instead deny operations that select fields the users are not allowed to select before even executing it with the [envelop `useOperationFieldPermissions` plugin](https://www.envelop.dev/plugins/use-operation-field-permissions).\n\nYou can overwrite the `isPublic` function which is used to determine whether a field or type is public based on directives and extensions. This allows to fully customize the behavior based on your needs.\n\n```ts\ntype SharedExtensionAndDirectiveInformation = {\n  extensions?: Maybe<{\n    [attributeName: string]: any;\n  }>;\n  astNode?: Maybe<\n    Readonly<{\n      directives?: ReadonlyArray<DirectiveNode>;\n    }>\n  >;\n};\n\nexport const defaultIsPublic = (\n  input: SharedExtensionAndDirectiveInformation\n): boolean =>\n  input.extensions?.[\"isPublic\"] === true ||\n  !!input.astNode?.directives?.find(\n    (directive) => directive.name.value === \"public\"\n  );\n```\n\n## License\n\nMIT\n","readmeFilename":"README.md","_id":"@n1ru4l/graphql-public-schema-filter@2.0.0-alpha-20230506175146-dfd01cb","_nodeVersion":"18.16.0","_npmVersion":"9.5.1","dist":{"integrity":"sha512-tHyOATriL3LpLXZt8/pp+fZJIvIoPJ/5BaeilUdPeZBraWCGtVR7h7BZsIRVB/h4XjMZwt1CG7gwtVmiPfngCw==","shasum":"d942a446dac5c60e2f4aa1fa018c82ee7e05d91a","tarball":"https://registry.npmjs.org/@n1ru4l/graphql-public-schema-filter/-/graphql-public-schema-filter-2.0.0-alpha-20230506175146-dfd01cb.tgz","fileCount":20,"unpackedSize":36713,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQClEzIOJ3z5vNOnFga9vdZPiQUdn1ynfNaVXTBg7ghncAIgZM+GgyIquBVjrp6mIVUTMCyUl+VEHOD/gQTZx+eN2s8="}]},"_npmUser":{"name":"n1ru4l","email":"laurinquast@googlemail.com"},"directories":{},"maintainers":[{"name":"n1ru4l","email":"laurinquast@googlemail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/graphql-public-schema-filter_2.0.0-alpha-20230506175146-dfd01cb_1683395513758_0.6161729059398946"},"_hasShrinkwrap":false},"2.0.0-alpha-20230506175216-393a8b2":{"name":"@n1ru4l/graphql-public-schema-filter","version":"2.0.0-alpha-20230506175216-393a8b2","description":"Filter your GraphQL schema into a public schema.","peerDependencies":{"graphql":"16.x.x"},"dependencies":{"@graphql-tools/utils":"^8.0.0"},"author":{"name":"Laurin Quast","email":"laurinquast@googlemail.com","url":"https://github.com/n1ru4l"},"license":"MIT","main":"cjs/index.js","module":"esm/index.js","typings":"typings/index.d.ts","typescript":{"definition":"typings/index.d.ts"},"exports":{".":{"require":{"types":"./typings/index.d.cts","default":"./cjs/index.js"},"import":{"types":"./typings/index.d.ts","default":"./esm/index.js"},"default":{"types":"./typings/index.d.ts","default":"./esm/index.js"}},"./*":{"require":"./cjs/*.js","import":"./esm/*.js","default":"./esm/*.js"}},"gitHead":"393a8b29e9b10188cd3994c4033946b92b851227","readme":"# @n1ru4l/graphql-public-schema-filter\n\nThis library allows filtering an existing GraphQL schema down into a subset of the original schema. It supports both the code first development flow of building GraphQL schemas (via GraphQL extension fields) and the SDL first development flow (via schema directives).\n\nThe implementation is smart and warns the user if the processed annotations would result in an invalid schema such as:\n\n- Object Type without fields\n- Field whose type is not part of the schema\n\nIf such a scenario is encountered the implementation will propagate and hide all fields/types that use types that are not marked as public or that would be invalid.\n\n## Why would you need this?\n\nAs I have been building GraphQL APIs I often had the need to have both a private and public API.\n\nThe private API is used for in-house products. Breaking changes can and will occur. It also includes types and fields specific to in-house application built around the API. The public API, however, is used by individuals not part of our organization. We cannot simply roll out breaking changes on the GraphQL API for those. Furthermore, they should only have access to a subset of the whole GraphQL graph. By generating a subgraph out of the internal graph we can hide stuff, without having to maintain and build two GraphQL schema.\n\n## Install instructions\n\nThis library requires `graphql` as a peer dependency and has a runtime dependency on `@graphql-tools/utils`.\n\n```bash\nyarn add -E @n1ru4l/graphql-public-schema-filter\n```\n\n## Usage Instructions\n\nThis library is designed to be inclusive for anyone within the GraphQL.js ecosystem. It supports both the SDL `makeExecutableSchema` and code-first via extension fields flow.\n\nThere is no delegation or validation overhead when executing against the newly generated schema. It is highly recommended to built the public schema during server-startup and not on the fly during incoming requests.\n\n### Code-First\n\nAnnotate types and fields that should be public with the `isPublic` extension.\n\n```ts\nimport { GraphQLObjectType, GraphQLString } from \"graphql\";\nimport { buildPublicSchema } from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst GraphQLQueryType = new GraphQLObjectType({\n  name: \"Query\",\n  fields: {\n    hello: {\n      type: GraphQLString,\n      resolve: () => \"hi\",\n      extensions: {\n        isPublic: true,\n      },\n    },\n    secret: {\n      type: GraphQLString,\n      resolve: () => \"sup\",\n    },\n  },\n});\n\nconst privateSchema = new GraphQLSchema({\n  query: GraphQLQueryType,\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\nYou can also find this example within `examples/src/schema.ts`.\n\n### SDL-First\n\nInstead of using the extension fields, we use the `@public` directive.\n\n```tsx\nimport { makeExecutableSchema } from \"@graphql-tools/schema\";\nimport {\n  publicDirectiveSDL,\n  buildPublicSchema,\n} from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst source = /* GraphQL */ `\n  type Query {\n    hello: String @public\n    secret: String\n  }\n`;\n\nconst privateSchema = makeExecutableSchema({\n  typeDefs: [publicDirectiveSDL, source],\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\n## FAQ\n\n### Why `isPublic` and `@public` over `isPrivate` and `@private`?\n\nDeny-listing is more prone to errors than allow-listing. By adding a directive/extension field we explicitly set something to public. The other way around it is easier to forgot to add a `@private`/ `isPrivate` annotation, which would automatically result in the new fields being public. Being verbose about what fields are public is the safest way.\n\n### Why is the no more granular control that allows building multiple unique public schemas?\n\nI considered this at the beginning, but in practice we never had a use for this. Having multiple public schemas requires maintaining a lot of documentation. In our use-case we only have a public and a private schema. There is still role based access for the public schema. certain users are not allowed to select specific fields. Instead of hiding those fields for those users we instead deny operations that select fields the users are not allowed to select before even executing it with the [envelop `useOperationFieldPermissions` plugin](https://www.envelop.dev/plugins/use-operation-field-permissions).\n\nYou can overwrite the `isPublic` function which is used to determine whether a field or type is public based on directives and extensions. This allows to fully customize the behavior based on your needs.\n\n```ts\ntype SharedExtensionAndDirectiveInformation = {\n  extensions?: Maybe<{\n    [attributeName: string]: any;\n  }>;\n  astNode?: Maybe<\n    Readonly<{\n      directives?: ReadonlyArray<DirectiveNode>;\n    }>\n  >;\n};\n\nexport const defaultIsPublic = (\n  input: SharedExtensionAndDirectiveInformation\n): boolean =>\n  input.extensions?.[\"isPublic\"] === true ||\n  !!input.astNode?.directives?.find(\n    (directive) => directive.name.value === \"public\"\n  );\n```\n\n## License\n\nMIT\n","readmeFilename":"README.md","_id":"@n1ru4l/graphql-public-schema-filter@2.0.0-alpha-20230506175216-393a8b2","_nodeVersion":"18.16.0","_npmVersion":"9.5.1","dist":{"integrity":"sha512-1tcraoIpndLvGSHGYnaeH+4QtDNWIEsf9813Z+GnoIm06HWEI6Hsimo1/P3r89FjXYXp7hSN4+Y8jC8AZrHD6Q==","shasum":"f91989f8fff52835a2dea0176faa3275224500a9","tarball":"https://registry.npmjs.org/@n1ru4l/graphql-public-schema-filter/-/graphql-public-schema-filter-2.0.0-alpha-20230506175216-393a8b2.tgz","fileCount":20,"unpackedSize":36713,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDfjiSMM4/kXhAtPjj/vWh5+2Rqg2d8Q34S3MhjwEZ8HAIhAPwcUihUeCMhFjDMlH4YtQVOUcaf+yySHBcfQxkAMJ3S"}]},"_npmUser":{"name":"n1ru4l","email":"laurinquast@googlemail.com"},"directories":{},"maintainers":[{"name":"n1ru4l","email":"laurinquast@googlemail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/graphql-public-schema-filter_2.0.0-alpha-20230506175216-393a8b2_1683395544315_0.11383826584301393"},"_hasShrinkwrap":false},"2.0.0-alpha-20230506175305-c10106b":{"name":"@n1ru4l/graphql-public-schema-filter","version":"2.0.0-alpha-20230506175305-c10106b","description":"Filter your GraphQL schema into a public schema.","peerDependencies":{"graphql":"16.x.x"},"dependencies":{"@graphql-tools/utils":"^8.0.0"},"author":{"name":"Laurin Quast","email":"laurinquast@googlemail.com","url":"https://github.com/n1ru4l"},"license":"MIT","main":"cjs/index.js","module":"esm/index.js","typings":"typings/index.d.ts","typescript":{"definition":"typings/index.d.ts"},"exports":{".":{"require":{"types":"./typings/index.d.cts","default":"./cjs/index.js"},"import":{"types":"./typings/index.d.ts","default":"./esm/index.js"},"default":{"types":"./typings/index.d.ts","default":"./esm/index.js"}},"./*":{"require":"./cjs/*.js","import":"./esm/*.js","default":"./esm/*.js"}},"gitHead":"c10106b3fb147bdc3a97d77ab141dc07f64f1fcf","readme":"# @n1ru4l/graphql-public-schema-filter\n\nThis library allows filtering an existing GraphQL schema down into a subset of the original schema. It supports both the code first development flow of building GraphQL schemas (via GraphQL extension fields) and the SDL first development flow (via schema directives).\n\nThe implementation is smart and warns the user if the processed annotations would result in an invalid schema such as:\n\n- Object Type without fields\n- Field whose type is not part of the schema\n\nIf such a scenario is encountered the implementation will propagate and hide all fields/types that use types that are not marked as public or that would be invalid.\n\n## Why would you need this?\n\nAs I have been building GraphQL APIs I often had the need to have both a private and public API.\n\nThe private API is used for in-house products. Breaking changes can and will occur. It also includes types and fields specific to in-house application built around the API. The public API, however, is used by individuals not part of our organization. We cannot simply roll out breaking changes on the GraphQL API for those. Furthermore, they should only have access to a subset of the whole GraphQL graph. By generating a subgraph out of the internal graph we can hide stuff, without having to maintain and build two GraphQL schema.\n\n## Install instructions\n\nThis library requires `graphql` as a peer dependency and has a runtime dependency on `@graphql-tools/utils`.\n\n```bash\nyarn add -E @n1ru4l/graphql-public-schema-filter\n```\n\n## Usage Instructions\n\nThis library is designed to be inclusive for anyone within the GraphQL.js ecosystem. It supports both the SDL `makeExecutableSchema` and code-first via extension fields flow.\n\nThere is no delegation or validation overhead when executing against the newly generated schema. It is highly recommended to built the public schema during server-startup and not on the fly during incoming requests.\n\n### Code-First\n\nAnnotate types and fields that should be public with the `isPublic` extension.\n\n```ts\nimport { GraphQLObjectType, GraphQLString } from \"graphql\";\nimport { buildPublicSchema } from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst GraphQLQueryType = new GraphQLObjectType({\n  name: \"Query\",\n  fields: {\n    hello: {\n      type: GraphQLString,\n      resolve: () => \"hi\",\n      extensions: {\n        isPublic: true,\n      },\n    },\n    secret: {\n      type: GraphQLString,\n      resolve: () => \"sup\",\n    },\n  },\n});\n\nconst privateSchema = new GraphQLSchema({\n  query: GraphQLQueryType,\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\nYou can also find this example within `examples/src/schema.ts`.\n\n### SDL-First\n\nInstead of using the extension fields, we use the `@public` directive.\n\n```tsx\nimport { makeExecutableSchema } from \"@graphql-tools/schema\";\nimport {\n  publicDirectiveSDL,\n  buildPublicSchema,\n} from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst source = /* GraphQL */ `\n  type Query {\n    hello: String @public\n    secret: String\n  }\n`;\n\nconst privateSchema = makeExecutableSchema({\n  typeDefs: [publicDirectiveSDL, source],\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\n## FAQ\n\n### Why `isPublic` and `@public` over `isPrivate` and `@private`?\n\nDeny-listing is more prone to errors than allow-listing. By adding a directive/extension field we explicitly set something to public. The other way around it is easier to forgot to add a `@private`/ `isPrivate` annotation, which would automatically result in the new fields being public. Being verbose about what fields are public is the safest way.\n\n### Why is the no more granular control that allows building multiple unique public schemas?\n\nI considered this at the beginning, but in practice we never had a use for this. Having multiple public schemas requires maintaining a lot of documentation. In our use-case we only have a public and a private schema. There is still role based access for the public schema. certain users are not allowed to select specific fields. Instead of hiding those fields for those users we instead deny operations that select fields the users are not allowed to select before even executing it with the [envelop `useOperationFieldPermissions` plugin](https://www.envelop.dev/plugins/use-operation-field-permissions).\n\nYou can overwrite the `isPublic` function which is used to determine whether a field or type is public based on directives and extensions. This allows to fully customize the behavior based on your needs.\n\n```ts\ntype SharedExtensionAndDirectiveInformation = {\n  extensions?: Maybe<{\n    [attributeName: string]: any;\n  }>;\n  astNode?: Maybe<\n    Readonly<{\n      directives?: ReadonlyArray<DirectiveNode>;\n    }>\n  >;\n};\n\nexport const defaultIsPublic = (\n  input: SharedExtensionAndDirectiveInformation\n): boolean =>\n  input.extensions?.[\"isPublic\"] === true ||\n  !!input.astNode?.directives?.find(\n    (directive) => directive.name.value === \"public\"\n  );\n```\n\n## License\n\nMIT\n","readmeFilename":"README.md","_id":"@n1ru4l/graphql-public-schema-filter@2.0.0-alpha-20230506175305-c10106b","_nodeVersion":"18.16.0","_npmVersion":"9.5.1","dist":{"integrity":"sha512-st9Gqi6A58eKO17EyZp9rMnb4RMgNxyVp58fDFNSwDmxG2R78N7gpo4y4q2p38dMI2URMKXzuy7XHn8bN19CGg==","shasum":"0b3fc15d2bd4766a920e83caa9193f28bc786343","tarball":"https://registry.npmjs.org/@n1ru4l/graphql-public-schema-filter/-/graphql-public-schema-filter-2.0.0-alpha-20230506175305-c10106b.tgz","fileCount":20,"unpackedSize":36713,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDcHnikeHoI/qM+S7/NbMcCNRgRBJEJ/EOWrBv0vNpZYwIgGx+WYpEe82vtDncxIXQvh9S3D0hz+fEJnbqHqFQC1ug="}]},"_npmUser":{"name":"n1ru4l","email":"laurinquast@googlemail.com"},"directories":{},"maintainers":[{"name":"n1ru4l","email":"laurinquast@googlemail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/graphql-public-schema-filter_2.0.0-alpha-20230506175305-c10106b_1683395592633_0.7692894681201856"},"_hasShrinkwrap":false},"2.0.0-alpha-20230506175416-afa59e7":{"name":"@n1ru4l/graphql-public-schema-filter","version":"2.0.0-alpha-20230506175416-afa59e7","description":"Filter your GraphQL schema into a public schema.","peerDependencies":{"graphql":"16.x.x"},"dependencies":{"@graphql-tools/utils":"^8.0.0"},"author":{"name":"Laurin Quast","email":"laurinquast@googlemail.com","url":"https://github.com/n1ru4l"},"license":"MIT","main":"cjs/index.js","module":"esm/index.js","typings":"typings/index.d.ts","typescript":{"definition":"typings/index.d.ts"},"exports":{".":{"require":{"types":"./typings/index.d.cts","default":"./cjs/index.js"},"import":{"types":"./typings/index.d.ts","default":"./esm/index.js"},"default":{"types":"./typings/index.d.ts","default":"./esm/index.js"}},"./*":{"require":"./cjs/*.js","import":"./esm/*.js","default":"./esm/*.js"}},"gitHead":"afa59e73554eb2456be30afbb3743698b1a903bd","readme":"# @n1ru4l/graphql-public-schema-filter\n\nThis library allows filtering an existing GraphQL schema down into a subset of the original schema. It supports both the code first development flow of building GraphQL schemas (via GraphQL extension fields) and the SDL first development flow (via schema directives).\n\nThe implementation is smart and warns the user if the processed annotations would result in an invalid schema such as:\n\n- Object Type without fields\n- Field whose type is not part of the schema\n\nIf such a scenario is encountered the implementation will propagate and hide all fields/types that use types that are not marked as public or that would be invalid.\n\n## Why would you need this?\n\nAs I have been building GraphQL APIs I often had the need to have both a private and public API.\n\nThe private API is used for in-house products. Breaking changes can and will occur. It also includes types and fields specific to in-house application built around the API. The public API, however, is used by individuals not part of our organization. We cannot simply roll out breaking changes on the GraphQL API for those. Furthermore, they should only have access to a subset of the whole GraphQL graph. By generating a subgraph out of the internal graph we can hide stuff, without having to maintain and build two GraphQL schema.\n\n## Install instructions\n\nThis library requires `graphql` as a peer dependency and has a runtime dependency on `@graphql-tools/utils`.\n\n```bash\nyarn add -E @n1ru4l/graphql-public-schema-filter\n```\n\n## Usage Instructions\n\nThis library is designed to be inclusive for anyone within the GraphQL.js ecosystem. It supports both the SDL `makeExecutableSchema` and code-first via extension fields flow.\n\nThere is no delegation or validation overhead when executing against the newly generated schema. It is highly recommended to built the public schema during server-startup and not on the fly during incoming requests.\n\n### Code-First\n\nAnnotate types and fields that should be public with the `isPublic` extension.\n\n```ts\nimport { GraphQLObjectType, GraphQLString } from \"graphql\";\nimport { buildPublicSchema } from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst GraphQLQueryType = new GraphQLObjectType({\n  name: \"Query\",\n  fields: {\n    hello: {\n      type: GraphQLString,\n      resolve: () => \"hi\",\n      extensions: {\n        isPublic: true,\n      },\n    },\n    secret: {\n      type: GraphQLString,\n      resolve: () => \"sup\",\n    },\n  },\n});\n\nconst privateSchema = new GraphQLSchema({\n  query: GraphQLQueryType,\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\nYou can also find this example within `examples/src/schema.ts`.\n\n### SDL-First\n\nInstead of using the extension fields, we use the `@public` directive.\n\n```tsx\nimport { makeExecutableSchema } from \"@graphql-tools/schema\";\nimport {\n  publicDirectiveSDL,\n  buildPublicSchema,\n} from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst source = /* GraphQL */ `\n  type Query {\n    hello: String @public\n    secret: String\n  }\n`;\n\nconst privateSchema = makeExecutableSchema({\n  typeDefs: [publicDirectiveSDL, source],\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\n## FAQ\n\n### Why `isPublic` and `@public` over `isPrivate` and `@private`?\n\nDeny-listing is more prone to errors than allow-listing. By adding a directive/extension field we explicitly set something to public. The other way around it is easier to forgot to add a `@private`/ `isPrivate` annotation, which would automatically result in the new fields being public. Being verbose about what fields are public is the safest way.\n\n### Why is the no more granular control that allows building multiple unique public schemas?\n\nI considered this at the beginning, but in practice we never had a use for this. Having multiple public schemas requires maintaining a lot of documentation. In our use-case we only have a public and a private schema. There is still role based access for the public schema. certain users are not allowed to select specific fields. Instead of hiding those fields for those users we instead deny operations that select fields the users are not allowed to select before even executing it with the [envelop `useOperationFieldPermissions` plugin](https://www.envelop.dev/plugins/use-operation-field-permissions).\n\nYou can overwrite the `isPublic` function which is used to determine whether a field or type is public based on directives and extensions. This allows to fully customize the behavior based on your needs.\n\n```ts\ntype SharedExtensionAndDirectiveInformation = {\n  extensions?: Maybe<{\n    [attributeName: string]: any;\n  }>;\n  astNode?: Maybe<\n    Readonly<{\n      directives?: ReadonlyArray<DirectiveNode>;\n    }>\n  >;\n};\n\nexport const defaultIsPublic = (\n  input: SharedExtensionAndDirectiveInformation\n): boolean =>\n  input.extensions?.[\"isPublic\"] === true ||\n  !!input.astNode?.directives?.find(\n    (directive) => directive.name.value === \"public\"\n  );\n```\n\n## License\n\nMIT\n","readmeFilename":"README.md","_id":"@n1ru4l/graphql-public-schema-filter@2.0.0-alpha-20230506175416-afa59e7","_nodeVersion":"18.16.0","_npmVersion":"9.5.1","dist":{"integrity":"sha512-EVU8vqgcxqb8cpg0Jpyp7gteY0s6+F4aBmigcbs8oybdM2QI8hkO+LdOS0GTXRnNTCLhl/o+zFXYEX9jAdMU2w==","shasum":"989c88888b5d437862dc90086c9eba38531eabb3","tarball":"https://registry.npmjs.org/@n1ru4l/graphql-public-schema-filter/-/graphql-public-schema-filter-2.0.0-alpha-20230506175416-afa59e7.tgz","fileCount":20,"unpackedSize":36713,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIGnQTeB3wLmUZRnpTVMvjiPQpL3QFC8HJ5zG0vKwmul4AiEAoB9ke/YOttmK8t8klVA53Z24aEeGOzFo5xf7ODSbDAU="}]},"_npmUser":{"name":"n1ru4l","email":"laurinquast@googlemail.com"},"directories":{},"maintainers":[{"name":"n1ru4l","email":"laurinquast@googlemail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/graphql-public-schema-filter_2.0.0-alpha-20230506175416-afa59e7_1683395663875_0.38208302171819164"},"_hasShrinkwrap":false},"2.0.0-alpha-20230506175452-62581f8":{"name":"@n1ru4l/graphql-public-schema-filter","version":"2.0.0-alpha-20230506175452-62581f8","description":"Filter your GraphQL schema into a public schema.","peerDependencies":{"graphql":"16.x.x"},"dependencies":{"@graphql-tools/utils":"^8.0.0"},"author":{"name":"Laurin Quast","email":"laurinquast@googlemail.com","url":"https://github.com/n1ru4l"},"license":"MIT","main":"cjs/index.js","module":"esm/index.js","typings":"typings/index.d.ts","typescript":{"definition":"typings/index.d.ts"},"exports":{".":{"require":{"types":"./typings/index.d.cts","default":"./cjs/index.js"},"import":{"types":"./typings/index.d.ts","default":"./esm/index.js"},"default":{"types":"./typings/index.d.ts","default":"./esm/index.js"}},"./*":{"require":"./cjs/*.js","import":"./esm/*.js","default":"./esm/*.js"}},"gitHead":"62581f8117c40a6d510105ba63db349c9dcec843","readme":"# @n1ru4l/graphql-public-schema-filter\n\nThis library allows filtering an existing GraphQL schema down into a subset of the original schema. It supports both the code first development flow of building GraphQL schemas (via GraphQL extension fields) and the SDL first development flow (via schema directives).\n\nThe implementation is smart and warns the user if the processed annotations would result in an invalid schema such as:\n\n- Object Type without fields\n- Field whose type is not part of the schema\n\nIf such a scenario is encountered the implementation will propagate and hide all fields/types that use types that are not marked as public or that would be invalid.\n\n## Why would you need this?\n\nAs I have been building GraphQL APIs I often had the need to have both a private and public API.\n\nThe private API is used for in-house products. Breaking changes can and will occur. It also includes types and fields specific to in-house application built around the API. The public API, however, is used by individuals not part of our organization. We cannot simply roll out breaking changes on the GraphQL API for those. Furthermore, they should only have access to a subset of the whole GraphQL graph. By generating a subgraph out of the internal graph we can hide stuff, without having to maintain and build two GraphQL schema.\n\n## Install instructions\n\nThis library requires `graphql` as a peer dependency and has a runtime dependency on `@graphql-tools/utils`.\n\n```bash\nyarn add -E @n1ru4l/graphql-public-schema-filter\n```\n\n## Usage Instructions\n\nThis library is designed to be inclusive for anyone within the GraphQL.js ecosystem. It supports both the SDL `makeExecutableSchema` and code-first via extension fields flow.\n\nThere is no delegation or validation overhead when executing against the newly generated schema. It is highly recommended to built the public schema during server-startup and not on the fly during incoming requests.\n\n### Code-First\n\nAnnotate types and fields that should be public with the `isPublic` extension.\n\n```ts\nimport { GraphQLObjectType, GraphQLString } from \"graphql\";\nimport { buildPublicSchema } from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst GraphQLQueryType = new GraphQLObjectType({\n  name: \"Query\",\n  fields: {\n    hello: {\n      type: GraphQLString,\n      resolve: () => \"hi\",\n      extensions: {\n        isPublic: true,\n      },\n    },\n    secret: {\n      type: GraphQLString,\n      resolve: () => \"sup\",\n    },\n  },\n});\n\nconst privateSchema = new GraphQLSchema({\n  query: GraphQLQueryType,\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\nYou can also find this example within `examples/src/schema.ts`.\n\n### SDL-First\n\nInstead of using the extension fields, we use the `@public` directive.\n\n```tsx\nimport { makeExecutableSchema } from \"@graphql-tools/schema\";\nimport {\n  publicDirectiveSDL,\n  buildPublicSchema,\n} from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst source = /* GraphQL */ `\n  type Query {\n    hello: String @public\n    secret: String\n  }\n`;\n\nconst privateSchema = makeExecutableSchema({\n  typeDefs: [publicDirectiveSDL, source],\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\n## FAQ\n\n### Why `isPublic` and `@public` over `isPrivate` and `@private`?\n\nDeny-listing is more prone to errors than allow-listing. By adding a directive/extension field we explicitly set something to public. The other way around it is easier to forgot to add a `@private`/ `isPrivate` annotation, which would automatically result in the new fields being public. Being verbose about what fields are public is the safest way.\n\n### Why is the no more granular control that allows building multiple unique public schemas?\n\nI considered this at the beginning, but in practice we never had a use for this. Having multiple public schemas requires maintaining a lot of documentation. In our use-case we only have a public and a private schema. There is still role based access for the public schema. certain users are not allowed to select specific fields. Instead of hiding those fields for those users we instead deny operations that select fields the users are not allowed to select before even executing it with the [envelop `useOperationFieldPermissions` plugin](https://www.envelop.dev/plugins/use-operation-field-permissions).\n\nYou can overwrite the `isPublic` function which is used to determine whether a field or type is public based on directives and extensions. This allows to fully customize the behavior based on your needs.\n\n```ts\ntype SharedExtensionAndDirectiveInformation = {\n  extensions?: Maybe<{\n    [attributeName: string]: any;\n  }>;\n  astNode?: Maybe<\n    Readonly<{\n      directives?: ReadonlyArray<DirectiveNode>;\n    }>\n  >;\n};\n\nexport const defaultIsPublic = (\n  input: SharedExtensionAndDirectiveInformation\n): boolean =>\n  input.extensions?.[\"isPublic\"] === true ||\n  !!input.astNode?.directives?.find(\n    (directive) => directive.name.value === \"public\"\n  );\n```\n\n## License\n\nMIT\n","readmeFilename":"README.md","_id":"@n1ru4l/graphql-public-schema-filter@2.0.0-alpha-20230506175452-62581f8","_nodeVersion":"18.16.0","_npmVersion":"9.5.1","dist":{"integrity":"sha512-G/JA4S1D2MfPYHNk51sDb7zFMzEZEqznr6nMe+x9QKrwAYjNx/9VgKISbCNh8a66s+HpcWq5boxQ10HjhmIjnQ==","shasum":"7e103a920805d1e9ccd89f44be1ee48caf255f20","tarball":"https://registry.npmjs.org/@n1ru4l/graphql-public-schema-filter/-/graphql-public-schema-filter-2.0.0-alpha-20230506175452-62581f8.tgz","fileCount":20,"unpackedSize":36713,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIGKBiTp+oKRtrj2KH8Jut29Ilu81vwnAvbnYU3WFcIQ7AiBYqdPS3jAVx4uMyu6ExIQ0rHlDm8FS0mdxZaDCna+p7w=="}]},"_npmUser":{"name":"n1ru4l","email":"laurinquast@googlemail.com"},"directories":{},"maintainers":[{"name":"n1ru4l","email":"laurinquast@googlemail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/graphql-public-schema-filter_2.0.0-alpha-20230506175452-62581f8_1683395701363_0.6726270917682275"},"_hasShrinkwrap":false},"2.0.0-alpha-20230506180028-00d68a8":{"name":"@n1ru4l/graphql-public-schema-filter","version":"2.0.0-alpha-20230506180028-00d68a8","description":"Filter your GraphQL schema into a public schema.","peerDependencies":{"graphql":"16.x.x"},"dependencies":{"@graphql-tools/utils":"^8.0.0"},"author":{"name":"Laurin Quast","email":"laurinquast@googlemail.com","url":"https://github.com/n1ru4l"},"license":"MIT","main":"cjs/index.js","module":"esm/index.js","typings":"typings/index.d.ts","typescript":{"definition":"typings/index.d.ts"},"exports":{".":{"require":{"types":"./typings/index.d.cts","default":"./cjs/index.js"},"import":{"types":"./typings/index.d.ts","default":"./esm/index.js"},"default":{"types":"./typings/index.d.ts","default":"./esm/index.js"}},"./*":{"require":"./cjs/*.js","import":"./esm/*.js","default":"./esm/*.js"}},"gitHead":"00d68a81c14eae76a42661874be7f1a40d9a9a4b","readme":"# @n1ru4l/graphql-public-schema-filter\n\nThis library allows filtering an existing GraphQL schema down into a subset of the original schema. It supports both the code first development flow of building GraphQL schemas (via GraphQL extension fields) and the SDL first development flow (via schema directives).\n\nThe implementation is smart and warns the user if the processed annotations would result in an invalid schema such as:\n\n- Object Type without fields\n- Field whose type is not part of the schema\n\nIf such a scenario is encountered the implementation will propagate and hide all fields/types that use types that are not marked as public or that would be invalid.\n\n## Why would you need this?\n\nAs I have been building GraphQL APIs I often had the need to have both a private and public API.\n\nThe private API is used for in-house products. Breaking changes can and will occur. It also includes types and fields specific to in-house application built around the API. The public API, however, is used by individuals not part of our organization. We cannot simply roll out breaking changes on the GraphQL API for those. Furthermore, they should only have access to a subset of the whole GraphQL graph. By generating a subgraph out of the internal graph we can hide stuff, without having to maintain and build two GraphQL schema.\n\n## Install instructions\n\nThis library requires `graphql` as a peer dependency and has a runtime dependency on `@graphql-tools/utils`.\n\n```bash\nyarn add -E @n1ru4l/graphql-public-schema-filter\n```\n\n## Usage Instructions\n\nThis library is designed to be inclusive for anyone within the GraphQL.js ecosystem. It supports both the SDL `makeExecutableSchema` and code-first via extension fields flow.\n\nThere is no delegation or validation overhead when executing against the newly generated schema. It is highly recommended to built the public schema during server-startup and not on the fly during incoming requests.\n\n### Code-First\n\nAnnotate types and fields that should be public with the `isPublic` extension.\n\n```ts\nimport { GraphQLObjectType, GraphQLString } from \"graphql\";\nimport { buildPublicSchema } from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst GraphQLQueryType = new GraphQLObjectType({\n  name: \"Query\",\n  fields: {\n    hello: {\n      type: GraphQLString,\n      resolve: () => \"hi\",\n      extensions: {\n        isPublic: true,\n      },\n    },\n    secret: {\n      type: GraphQLString,\n      resolve: () => \"sup\",\n    },\n  },\n});\n\nconst privateSchema = new GraphQLSchema({\n  query: GraphQLQueryType,\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\nYou can also find this example within `examples/src/schema.ts`.\n\n### SDL-First\n\nInstead of using the extension fields, we use the `@public` directive.\n\n```tsx\nimport { makeExecutableSchema } from \"@graphql-tools/schema\";\nimport {\n  publicDirectiveSDL,\n  buildPublicSchema,\n} from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst source = /* GraphQL */ `\n  type Query {\n    hello: String @public\n    secret: String\n  }\n`;\n\nconst privateSchema = makeExecutableSchema({\n  typeDefs: [publicDirectiveSDL, source],\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\n## FAQ\n\n### Why `isPublic` and `@public` over `isPrivate` and `@private`?\n\nDeny-listing is more prone to errors than allow-listing. By adding a directive/extension field we explicitly set something to public. The other way around it is easier to forgot to add a `@private`/ `isPrivate` annotation, which would automatically result in the new fields being public. Being verbose about what fields are public is the safest way.\n\n### Why is the no more granular control that allows building multiple unique public schemas?\n\nI considered this at the beginning, but in practice we never had a use for this. Having multiple public schemas requires maintaining a lot of documentation. In our use-case we only have a public and a private schema. There is still role based access for the public schema. certain users are not allowed to select specific fields. Instead of hiding those fields for those users we instead deny operations that select fields the users are not allowed to select before even executing it with the [envelop `useOperationFieldPermissions` plugin](https://www.envelop.dev/plugins/use-operation-field-permissions).\n\nYou can overwrite the `isPublic` function which is used to determine whether a field or type is public based on directives and extensions. This allows to fully customize the behavior based on your needs.\n\n```ts\ntype SharedExtensionAndDirectiveInformation = {\n  extensions?: Maybe<{\n    [attributeName: string]: any;\n  }>;\n  astNode?: Maybe<\n    Readonly<{\n      directives?: ReadonlyArray<DirectiveNode>;\n    }>\n  >;\n};\n\nexport const defaultIsPublic = (\n  input: SharedExtensionAndDirectiveInformation\n): boolean =>\n  input.extensions?.[\"isPublic\"] === true ||\n  !!input.astNode?.directives?.find(\n    (directive) => directive.name.value === \"public\"\n  );\n```\n\n## License\n\nMIT\n","readmeFilename":"README.md","_id":"@n1ru4l/graphql-public-schema-filter@2.0.0-alpha-20230506180028-00d68a8","_nodeVersion":"18.16.0","_npmVersion":"9.5.1","dist":{"integrity":"sha512-wmQZUo+haAW7q+F5ZfFQq836xE23gf7x245cdZykHbqn/4tZdQmPRXKZaC25E7MVQOISh43bj+RP0kCtsilMJw==","shasum":"720b20a19cb7b8371f56e9ac8ea1f43557276484","tarball":"https://registry.npmjs.org/@n1ru4l/graphql-public-schema-filter/-/graphql-public-schema-filter-2.0.0-alpha-20230506180028-00d68a8.tgz","fileCount":20,"unpackedSize":36713,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIG6Ry2TAXy0TdGAz2q/VHyRB5smAHYzf+CYyQY71yhq6AiBU/dxTjaSo35QIwWyjK6ATR32fh006Q4Fw8N+N1lXn2Q=="}]},"_npmUser":{"name":"n1ru4l","email":"laurinquast@googlemail.com"},"directories":{},"maintainers":[{"name":"n1ru4l","email":"laurinquast@googlemail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/graphql-public-schema-filter_2.0.0-alpha-20230506180028-00d68a8_1683396038047_0.8013835271759646"},"_hasShrinkwrap":false},"2.0.0-alpha-20230506180237-65559c9":{"name":"@n1ru4l/graphql-public-schema-filter","version":"2.0.0-alpha-20230506180237-65559c9","description":"Filter your GraphQL schema into a public schema.","peerDependencies":{"graphql":"16.x.x"},"dependencies":{"@graphql-tools/utils":"^8.0.0"},"author":{"name":"Laurin Quast","email":"laurinquast@googlemail.com","url":"https://github.com/n1ru4l"},"license":"MIT","main":"cjs/index.js","module":"esm/index.js","typings":"typings/index.d.ts","typescript":{"definition":"typings/index.d.ts"},"exports":{".":{"require":{"types":"./typings/index.d.cts","default":"./cjs/index.js"},"import":{"types":"./typings/index.d.ts","default":"./esm/index.js"},"default":{"types":"./typings/index.d.ts","default":"./esm/index.js"}},"./*":{"require":"./cjs/*.js","import":"./esm/*.js","default":"./esm/*.js"}},"gitHead":"65559c99566e172a1d6e82b665920ea4f22a7613","readme":"# @n1ru4l/graphql-public-schema-filter\n\nThis library allows filtering an existing GraphQL schema down into a subset of the original schema. It supports both the code first development flow of building GraphQL schemas (via GraphQL extension fields) and the SDL first development flow (via schema directives).\n\nThe implementation is smart and warns the user if the processed annotations would result in an invalid schema such as:\n\n- Object Type without fields\n- Field whose type is not part of the schema\n\nIf such a scenario is encountered the implementation will propagate and hide all fields/types that use types that are not marked as public or that would be invalid.\n\n## Why would you need this?\n\nAs I have been building GraphQL APIs I often had the need to have both a private and public API.\n\nThe private API is used for in-house products. Breaking changes can and will occur. It also includes types and fields specific to in-house application built around the API. The public API, however, is used by individuals not part of our organization. We cannot simply roll out breaking changes on the GraphQL API for those. Furthermore, they should only have access to a subset of the whole GraphQL graph. By generating a subgraph out of the internal graph we can hide stuff, without having to maintain and build two GraphQL schema.\n\n## Install instructions\n\nThis library requires `graphql` as a peer dependency and has a runtime dependency on `@graphql-tools/utils`.\n\n```bash\nyarn add -E @n1ru4l/graphql-public-schema-filter\n```\n\n## Usage Instructions\n\nThis library is designed to be inclusive for anyone within the GraphQL.js ecosystem. It supports both the SDL `makeExecutableSchema` and code-first via extension fields flow.\n\nThere is no delegation or validation overhead when executing against the newly generated schema. It is highly recommended to built the public schema during server-startup and not on the fly during incoming requests.\n\n### Code-First\n\nAnnotate types and fields that should be public with the `isPublic` extension.\n\n```ts\nimport { GraphQLObjectType, GraphQLString } from \"graphql\";\nimport { buildPublicSchema } from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst GraphQLQueryType = new GraphQLObjectType({\n  name: \"Query\",\n  fields: {\n    hello: {\n      type: GraphQLString,\n      resolve: () => \"hi\",\n      extensions: {\n        isPublic: true,\n      },\n    },\n    secret: {\n      type: GraphQLString,\n      resolve: () => \"sup\",\n    },\n  },\n});\n\nconst privateSchema = new GraphQLSchema({\n  query: GraphQLQueryType,\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\nYou can also find this example within `examples/src/schema.ts`.\n\n### SDL-First\n\nInstead of using the extension fields, we use the `@public` directive.\n\n```tsx\nimport { makeExecutableSchema } from \"@graphql-tools/schema\";\nimport {\n  publicDirectiveSDL,\n  buildPublicSchema,\n} from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst source = /* GraphQL */ `\n  type Query {\n    hello: String @public\n    secret: String\n  }\n`;\n\nconst privateSchema = makeExecutableSchema({\n  typeDefs: [publicDirectiveSDL, source],\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\n## FAQ\n\n### Why `isPublic` and `@public` over `isPrivate` and `@private`?\n\nDeny-listing is more prone to errors than allow-listing. By adding a directive/extension field we explicitly set something to public. The other way around it is easier to forgot to add a `@private`/ `isPrivate` annotation, which would automatically result in the new fields being public. Being verbose about what fields are public is the safest way.\n\n### Why is the no more granular control that allows building multiple unique public schemas?\n\nI considered this at the beginning, but in practice we never had a use for this. Having multiple public schemas requires maintaining a lot of documentation. In our use-case we only have a public and a private schema. There is still role based access for the public schema. certain users are not allowed to select specific fields. Instead of hiding those fields for those users we instead deny operations that select fields the users are not allowed to select before even executing it with the [envelop `useOperationFieldPermissions` plugin](https://www.envelop.dev/plugins/use-operation-field-permissions).\n\nYou can overwrite the `isPublic` function which is used to determine whether a field or type is public based on directives and extensions. This allows to fully customize the behavior based on your needs.\n\n```ts\ntype SharedExtensionAndDirectiveInformation = {\n  extensions?: Maybe<{\n    [attributeName: string]: any;\n  }>;\n  astNode?: Maybe<\n    Readonly<{\n      directives?: ReadonlyArray<DirectiveNode>;\n    }>\n  >;\n};\n\nexport const defaultIsPublic = (\n  input: SharedExtensionAndDirectiveInformation\n): boolean =>\n  input.extensions?.[\"isPublic\"] === true ||\n  !!input.astNode?.directives?.find(\n    (directive) => directive.name.value === \"public\"\n  );\n```\n\n## License\n\nMIT\n","readmeFilename":"README.md","_id":"@n1ru4l/graphql-public-schema-filter@2.0.0-alpha-20230506180237-65559c9","_nodeVersion":"18.16.0","_npmVersion":"9.5.1","dist":{"integrity":"sha512-2Mpr2FRw8xXHaZ3SmNSQ/EjMs2FHHosba6F7THnEg9ZuDRCgRcYHRBoy7KSaguzStuZHwx81unY/OrclzoWyvg==","shasum":"b9623bdedbb3cd73563cde41d00f361ed162e993","tarball":"https://registry.npmjs.org/@n1ru4l/graphql-public-schema-filter/-/graphql-public-schema-filter-2.0.0-alpha-20230506180237-65559c9.tgz","fileCount":20,"unpackedSize":36713,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDH+P/OcGRerlMy7y0u8zSz+pnwk5vEgkh230dy9Y1sQQIgBv3dRduKHE6EP+D9mQzdJqRb4FvyS/mg1fuBet3+ITs="}]},"_npmUser":{"name":"n1ru4l","email":"laurinquast@googlemail.com"},"directories":{},"maintainers":[{"name":"n1ru4l","email":"laurinquast@googlemail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/graphql-public-schema-filter_2.0.0-alpha-20230506180237-65559c9_1683396164466_0.1648883852229941"},"_hasShrinkwrap":false},"2.0.0-alpha-20230506180327-894dd36":{"name":"@n1ru4l/graphql-public-schema-filter","version":"2.0.0-alpha-20230506180327-894dd36","description":"Filter your GraphQL schema into a public schema.","peerDependencies":{"graphql":"16.x.x"},"dependencies":{"@graphql-tools/utils":"^8.0.0"},"author":{"name":"Laurin Quast","email":"laurinquast@googlemail.com","url":"https://github.com/n1ru4l"},"license":"MIT","main":"cjs/index.js","module":"esm/index.js","typings":"typings/index.d.ts","typescript":{"definition":"typings/index.d.ts"},"exports":{".":{"require":{"types":"./typings/index.d.cts","default":"./cjs/index.js"},"import":{"types":"./typings/index.d.ts","default":"./esm/index.js"},"default":{"types":"./typings/index.d.ts","default":"./esm/index.js"}},"./*":{"require":"./cjs/*.js","import":"./esm/*.js","default":"./esm/*.js"}},"gitHead":"894dd361b34c6c88c8942e28cc1b8eb8bb2e6db5","readme":"# @n1ru4l/graphql-public-schema-filter\n\nThis library allows filtering an existing GraphQL schema down into a subset of the original schema. It supports both the code first development flow of building GraphQL schemas (via GraphQL extension fields) and the SDL first development flow (via schema directives).\n\nThe implementation is smart and warns the user if the processed annotations would result in an invalid schema such as:\n\n- Object Type without fields\n- Field whose type is not part of the schema\n\nIf such a scenario is encountered the implementation will propagate and hide all fields/types that use types that are not marked as public or that would be invalid.\n\n## Why would you need this?\n\nAs I have been building GraphQL APIs I often had the need to have both a private and public API.\n\nThe private API is used for in-house products. Breaking changes can and will occur. It also includes types and fields specific to in-house application built around the API. The public API, however, is used by individuals not part of our organization. We cannot simply roll out breaking changes on the GraphQL API for those. Furthermore, they should only have access to a subset of the whole GraphQL graph. By generating a subgraph out of the internal graph we can hide stuff, without having to maintain and build two GraphQL schema.\n\n## Install instructions\n\nThis library requires `graphql` as a peer dependency and has a runtime dependency on `@graphql-tools/utils`.\n\n```bash\nyarn add -E @n1ru4l/graphql-public-schema-filter\n```\n\n## Usage Instructions\n\nThis library is designed to be inclusive for anyone within the GraphQL.js ecosystem. It supports both the SDL `makeExecutableSchema` and code-first via extension fields flow.\n\nThere is no delegation or validation overhead when executing against the newly generated schema. It is highly recommended to built the public schema during server-startup and not on the fly during incoming requests.\n\n### Code-First\n\nAnnotate types and fields that should be public with the `isPublic` extension.\n\n```ts\nimport { GraphQLObjectType, GraphQLString } from \"graphql\";\nimport { buildPublicSchema } from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst GraphQLQueryType = new GraphQLObjectType({\n  name: \"Query\",\n  fields: {\n    hello: {\n      type: GraphQLString,\n      resolve: () => \"hi\",\n      extensions: {\n        isPublic: true,\n      },\n    },\n    secret: {\n      type: GraphQLString,\n      resolve: () => \"sup\",\n    },\n  },\n});\n\nconst privateSchema = new GraphQLSchema({\n  query: GraphQLQueryType,\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\nYou can also find this example within `examples/src/schema.ts`.\n\n### SDL-First\n\nInstead of using the extension fields, we use the `@public` directive.\n\n```tsx\nimport { makeExecutableSchema } from \"@graphql-tools/schema\";\nimport {\n  publicDirectiveSDL,\n  buildPublicSchema,\n} from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst source = /* GraphQL */ `\n  type Query {\n    hello: String @public\n    secret: String\n  }\n`;\n\nconst privateSchema = makeExecutableSchema({\n  typeDefs: [publicDirectiveSDL, source],\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\n## FAQ\n\n### Why `isPublic` and `@public` over `isPrivate` and `@private`?\n\nDeny-listing is more prone to errors than allow-listing. By adding a directive/extension field we explicitly set something to public. The other way around it is easier to forgot to add a `@private`/ `isPrivate` annotation, which would automatically result in the new fields being public. Being verbose about what fields are public is the safest way.\n\n### Why is the no more granular control that allows building multiple unique public schemas?\n\nI considered this at the beginning, but in practice we never had a use for this. Having multiple public schemas requires maintaining a lot of documentation. In our use-case we only have a public and a private schema. There is still role based access for the public schema. certain users are not allowed to select specific fields. Instead of hiding those fields for those users we instead deny operations that select fields the users are not allowed to select before even executing it with the [envelop `useOperationFieldPermissions` plugin](https://www.envelop.dev/plugins/use-operation-field-permissions).\n\nYou can overwrite the `isPublic` function which is used to determine whether a field or type is public based on directives and extensions. This allows to fully customize the behavior based on your needs.\n\n```ts\ntype SharedExtensionAndDirectiveInformation = {\n  extensions?: Maybe<{\n    [attributeName: string]: any;\n  }>;\n  astNode?: Maybe<\n    Readonly<{\n      directives?: ReadonlyArray<DirectiveNode>;\n    }>\n  >;\n};\n\nexport const defaultIsPublic = (\n  input: SharedExtensionAndDirectiveInformation\n): boolean =>\n  input.extensions?.[\"isPublic\"] === true ||\n  !!input.astNode?.directives?.find(\n    (directive) => directive.name.value === \"public\"\n  );\n```\n\n## License\n\nMIT\n","readmeFilename":"README.md","_id":"@n1ru4l/graphql-public-schema-filter@2.0.0-alpha-20230506180327-894dd36","_nodeVersion":"18.16.0","_npmVersion":"9.5.1","dist":{"integrity":"sha512-ByTW35iaAFpuLJKEyfWFyVcaWcXIArf1iHaRlo17jt9AMfywxjARnjupJ6aZQaK3eR0xXtgtpn3L10pWNAW5SQ==","shasum":"85a1cec0825c34f2a543295086c6211af21b0e33","tarball":"https://registry.npmjs.org/@n1ru4l/graphql-public-schema-filter/-/graphql-public-schema-filter-2.0.0-alpha-20230506180327-894dd36.tgz","fileCount":20,"unpackedSize":36713,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIGqw+/YAYuxvVDwzSm3OOeG9fA4c2NgRq/TD+Bi3TvaJAiEAtf8Qk/EYoRWiFQO4QaIw1aTyphZxfclUUdVOMbD5wkk="}]},"_npmUser":{"name":"n1ru4l","email":"laurinquast@googlemail.com"},"directories":{},"maintainers":[{"name":"n1ru4l","email":"laurinquast@googlemail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/graphql-public-schema-filter_2.0.0-alpha-20230506180327-894dd36_1683396216426_0.7617247832479324"},"_hasShrinkwrap":false},"2.0.0-alpha-20230506180347-b1d02b3":{"name":"@n1ru4l/graphql-public-schema-filter","version":"2.0.0-alpha-20230506180347-b1d02b3","description":"Filter your GraphQL schema into a public schema.","peerDependencies":{"graphql":"16.x.x"},"dependencies":{"@graphql-tools/utils":"^8.0.0"},"author":{"name":"Laurin Quast","email":"laurinquast@googlemail.com","url":"https://github.com/n1ru4l"},"license":"MIT","main":"cjs/index.js","module":"esm/index.js","typings":"typings/index.d.ts","typescript":{"definition":"typings/index.d.ts"},"exports":{".":{"require":{"types":"./typings/index.d.cts","default":"./cjs/index.js"},"import":{"types":"./typings/index.d.ts","default":"./esm/index.js"},"default":{"types":"./typings/index.d.ts","default":"./esm/index.js"}},"./*":{"require":"./cjs/*.js","import":"./esm/*.js","default":"./esm/*.js"}},"gitHead":"b1d02b39f66eae7fa2af8d12524bb22517f3ec35","readme":"# @n1ru4l/graphql-public-schema-filter\n\nThis library allows filtering an existing GraphQL schema down into a subset of the original schema. It supports both the code first development flow of building GraphQL schemas (via GraphQL extension fields) and the SDL first development flow (via schema directives).\n\nThe implementation is smart and warns the user if the processed annotations would result in an invalid schema such as:\n\n- Object Type without fields\n- Field whose type is not part of the schema\n\nIf such a scenario is encountered the implementation will propagate and hide all fields/types that use types that are not marked as public or that would be invalid.\n\n## Why would you need this?\n\nAs I have been building GraphQL APIs I often had the need to have both a private and public API.\n\nThe private API is used for in-house products. Breaking changes can and will occur. It also includes types and fields specific to in-house application built around the API. The public API, however, is used by individuals not part of our organization. We cannot simply roll out breaking changes on the GraphQL API for those. Furthermore, they should only have access to a subset of the whole GraphQL graph. By generating a subgraph out of the internal graph we can hide stuff, without having to maintain and build two GraphQL schema.\n\n## Install instructions\n\nThis library requires `graphql` as a peer dependency and has a runtime dependency on `@graphql-tools/utils`.\n\n```bash\nyarn add -E @n1ru4l/graphql-public-schema-filter\n```\n\n## Usage Instructions\n\nThis library is designed to be inclusive for anyone within the GraphQL.js ecosystem. It supports both the SDL `makeExecutableSchema` and code-first via extension fields flow.\n\nThere is no delegation or validation overhead when executing against the newly generated schema. It is highly recommended to built the public schema during server-startup and not on the fly during incoming requests.\n\n### Code-First\n\nAnnotate types and fields that should be public with the `isPublic` extension.\n\n```ts\nimport { GraphQLObjectType, GraphQLString } from \"graphql\";\nimport { buildPublicSchema } from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst GraphQLQueryType = new GraphQLObjectType({\n  name: \"Query\",\n  fields: {\n    hello: {\n      type: GraphQLString,\n      resolve: () => \"hi\",\n      extensions: {\n        isPublic: true,\n      },\n    },\n    secret: {\n      type: GraphQLString,\n      resolve: () => \"sup\",\n    },\n  },\n});\n\nconst privateSchema = new GraphQLSchema({\n  query: GraphQLQueryType,\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\nYou can also find this example within `examples/src/schema.ts`.\n\n### SDL-First\n\nInstead of using the extension fields, we use the `@public` directive.\n\n```tsx\nimport { makeExecutableSchema } from \"@graphql-tools/schema\";\nimport {\n  publicDirectiveSDL,\n  buildPublicSchema,\n} from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst source = /* GraphQL */ `\n  type Query {\n    hello: String @public\n    secret: String\n  }\n`;\n\nconst privateSchema = makeExecutableSchema({\n  typeDefs: [publicDirectiveSDL, source],\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\n## FAQ\n\n### Why `isPublic` and `@public` over `isPrivate` and `@private`?\n\nDeny-listing is more prone to errors than allow-listing. By adding a directive/extension field we explicitly set something to public. The other way around it is easier to forgot to add a `@private`/ `isPrivate` annotation, which would automatically result in the new fields being public. Being verbose about what fields are public is the safest way.\n\n### Why is the no more granular control that allows building multiple unique public schemas?\n\nI considered this at the beginning, but in practice we never had a use for this. Having multiple public schemas requires maintaining a lot of documentation. In our use-case we only have a public and a private schema. There is still role based access for the public schema. certain users are not allowed to select specific fields. Instead of hiding those fields for those users we instead deny operations that select fields the users are not allowed to select before even executing it with the [envelop `useOperationFieldPermissions` plugin](https://www.envelop.dev/plugins/use-operation-field-permissions).\n\nYou can overwrite the `isPublic` function which is used to determine whether a field or type is public based on directives and extensions. This allows to fully customize the behavior based on your needs.\n\n```ts\ntype SharedExtensionAndDirectiveInformation = {\n  extensions?: Maybe<{\n    [attributeName: string]: any;\n  }>;\n  astNode?: Maybe<\n    Readonly<{\n      directives?: ReadonlyArray<DirectiveNode>;\n    }>\n  >;\n};\n\nexport const defaultIsPublic = (\n  input: SharedExtensionAndDirectiveInformation\n): boolean =>\n  input.extensions?.[\"isPublic\"] === true ||\n  !!input.astNode?.directives?.find(\n    (directive) => directive.name.value === \"public\"\n  );\n```\n\n## License\n\nMIT\n","readmeFilename":"README.md","_id":"@n1ru4l/graphql-public-schema-filter@2.0.0-alpha-20230506180347-b1d02b3","_nodeVersion":"18.16.0","_npmVersion":"9.5.1","dist":{"integrity":"sha512-Lz+LN/7GpcC0MTiKorTplu+dv22vbKnHotoPU+Dy4HvLkqoIu2G6dx/J1oKgWNzR6wGfVufhfyI5b0PIE3lQBg==","shasum":"94cd1c6d00961076e53fd211a6f987b17c5a26ad","tarball":"https://registry.npmjs.org/@n1ru4l/graphql-public-schema-filter/-/graphql-public-schema-filter-2.0.0-alpha-20230506180347-b1d02b3.tgz","fileCount":20,"unpackedSize":36713,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDqZbo2VJp4ML9oaRf33JzOj7ywljTry2xJ69spnmg4QgIgKQep7YwwjLH3M5xVNP5JVA0jnKUACDok6iQAGq8JKuc="}]},"_npmUser":{"name":"n1ru4l","email":"laurinquast@googlemail.com"},"directories":{},"maintainers":[{"name":"n1ru4l","email":"laurinquast@googlemail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/graphql-public-schema-filter_2.0.0-alpha-20230506180347-b1d02b3_1683396235456_0.21839090117363025"},"_hasShrinkwrap":false},"2.0.0-alpha-20230506180549-b22502c":{"name":"@n1ru4l/graphql-public-schema-filter","version":"2.0.0-alpha-20230506180549-b22502c","description":"Filter your GraphQL schema into a public schema.","peerDependencies":{"graphql":"16.x.x"},"dependencies":{"@graphql-tools/utils":"^8.0.0"},"author":{"name":"Laurin Quast","email":"laurinquast@googlemail.com","url":"https://github.com/n1ru4l"},"license":"MIT","main":"cjs/index.js","module":"esm/index.js","typings":"typings/index.d.ts","typescript":{"definition":"typings/index.d.ts"},"exports":{".":{"require":{"types":"./typings/index.d.cts","default":"./cjs/index.js"},"import":{"types":"./typings/index.d.ts","default":"./esm/index.js"},"default":{"types":"./typings/index.d.ts","default":"./esm/index.js"}},"./*":{"require":"./cjs/*.js","import":"./esm/*.js","default":"./esm/*.js"}},"gitHead":"b22502c7a26e0144936f81354d0a3a72e64f9418","readme":"# @n1ru4l/graphql-public-schema-filter\n\nThis library allows filtering an existing GraphQL schema down into a subset of the original schema. It supports both the code first development flow of building GraphQL schemas (via GraphQL extension fields) and the SDL first development flow (via schema directives).\n\nThe implementation is smart and warns the user if the processed annotations would result in an invalid schema such as:\n\n- Object Type without fields\n- Field whose type is not part of the schema\n\nIf such a scenario is encountered the implementation will propagate and hide all fields/types that use types that are not marked as public or that would be invalid.\n\n## Why would you need this?\n\nAs I have been building GraphQL APIs I often had the need to have both a private and public API.\n\nThe private API is used for in-house products. Breaking changes can and will occur. It also includes types and fields specific to in-house application built around the API. The public API, however, is used by individuals not part of our organization. We cannot simply roll out breaking changes on the GraphQL API for those. Furthermore, they should only have access to a subset of the whole GraphQL graph. By generating a subgraph out of the internal graph we can hide stuff, without having to maintain and build two GraphQL schema.\n\n## Install instructions\n\nThis library requires `graphql` as a peer dependency and has a runtime dependency on `@graphql-tools/utils`.\n\n```bash\nyarn add -E @n1ru4l/graphql-public-schema-filter\n```\n\n## Usage Instructions\n\nThis library is designed to be inclusive for anyone within the GraphQL.js ecosystem. It supports both the SDL `makeExecutableSchema` and code-first via extension fields flow.\n\nThere is no delegation or validation overhead when executing against the newly generated schema. It is highly recommended to built the public schema during server-startup and not on the fly during incoming requests.\n\n### Code-First\n\nAnnotate types and fields that should be public with the `isPublic` extension.\n\n```ts\nimport { GraphQLObjectType, GraphQLString } from \"graphql\";\nimport { buildPublicSchema } from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst GraphQLQueryType = new GraphQLObjectType({\n  name: \"Query\",\n  fields: {\n    hello: {\n      type: GraphQLString,\n      resolve: () => \"hi\",\n      extensions: {\n        isPublic: true,\n      },\n    },\n    secret: {\n      type: GraphQLString,\n      resolve: () => \"sup\",\n    },\n  },\n});\n\nconst privateSchema = new GraphQLSchema({\n  query: GraphQLQueryType,\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\nYou can also find this example within `examples/src/schema.ts`.\n\n### SDL-First\n\nInstead of using the extension fields, we use the `@public` directive.\n\n```tsx\nimport { makeExecutableSchema } from \"@graphql-tools/schema\";\nimport {\n  publicDirectiveSDL,\n  buildPublicSchema,\n} from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst source = /* GraphQL */ `\n  type Query {\n    hello: String @public\n    secret: String\n  }\n`;\n\nconst privateSchema = makeExecutableSchema({\n  typeDefs: [publicDirectiveSDL, source],\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\n## FAQ\n\n### Why `isPublic` and `@public` over `isPrivate` and `@private`?\n\nDeny-listing is more prone to errors than allow-listing. By adding a directive/extension field we explicitly set something to public. The other way around it is easier to forgot to add a `@private`/ `isPrivate` annotation, which would automatically result in the new fields being public. Being verbose about what fields are public is the safest way.\n\n### Why is the no more granular control that allows building multiple unique public schemas?\n\nI considered this at the beginning, but in practice we never had a use for this. Having multiple public schemas requires maintaining a lot of documentation. In our use-case we only have a public and a private schema. There is still role based access for the public schema. certain users are not allowed to select specific fields. Instead of hiding those fields for those users we instead deny operations that select fields the users are not allowed to select before even executing it with the [envelop `useOperationFieldPermissions` plugin](https://www.envelop.dev/plugins/use-operation-field-permissions).\n\nYou can overwrite the `isPublic` function which is used to determine whether a field or type is public based on directives and extensions. This allows to fully customize the behavior based on your needs.\n\n```ts\ntype SharedExtensionAndDirectiveInformation = {\n  extensions?: Maybe<{\n    [attributeName: string]: any;\n  }>;\n  astNode?: Maybe<\n    Readonly<{\n      directives?: ReadonlyArray<DirectiveNode>;\n    }>\n  >;\n};\n\nexport const defaultIsPublic = (\n  input: SharedExtensionAndDirectiveInformation\n): boolean =>\n  input.extensions?.[\"isPublic\"] === true ||\n  !!input.astNode?.directives?.find(\n    (directive) => directive.name.value === \"public\"\n  );\n```\n\n## License\n\nMIT\n","readmeFilename":"README.md","_id":"@n1ru4l/graphql-public-schema-filter@2.0.0-alpha-20230506180549-b22502c","_nodeVersion":"18.16.0","_npmVersion":"9.5.1","dist":{"integrity":"sha512-mztfVtCNez2iA1lYgE25O77yyqNE8A21nVGvlp9focgQrJ7epolRdm0thId8pPZS31MH1LSusCmq/pgLm89z6w==","shasum":"63020376bd33777794401468b0b47c53812b5fa4","tarball":"https://registry.npmjs.org/@n1ru4l/graphql-public-schema-filter/-/graphql-public-schema-filter-2.0.0-alpha-20230506180549-b22502c.tgz","fileCount":20,"unpackedSize":36713,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDB8sAr+nmMyWCuGF1Qd5ObG40SNcQxlUatKbAM9T2ljAIgEPpEtT2jtYedlXd1UcRpK3XDVVtyadlzQ2NSFcaVxUA="}]},"_npmUser":{"name":"n1ru4l","email":"laurinquast@googlemail.com"},"directories":{},"maintainers":[{"name":"n1ru4l","email":"laurinquast@googlemail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/graphql-public-schema-filter_2.0.0-alpha-20230506180549-b22502c_1683396356321_0.061854853470144855"},"_hasShrinkwrap":false},"2.0.0-alpha-20230506180651-5cbc926":{"name":"@n1ru4l/graphql-public-schema-filter","version":"2.0.0-alpha-20230506180651-5cbc926","description":"Filter your GraphQL schema into a public schema.","peerDependencies":{"graphql":"16.x.x"},"dependencies":{"@graphql-tools/utils":"^9.0.0"},"author":{"name":"Laurin Quast","email":"laurinquast@googlemail.com","url":"https://github.com/n1ru4l"},"license":"MIT","main":"cjs/index.js","module":"esm/index.js","typings":"typings/index.d.ts","typescript":{"definition":"typings/index.d.ts"},"exports":{".":{"require":{"types":"./typings/index.d.cts","default":"./cjs/index.js"},"import":{"types":"./typings/index.d.ts","default":"./esm/index.js"},"default":{"types":"./typings/index.d.ts","default":"./esm/index.js"}},"./*":{"require":"./cjs/*.js","import":"./esm/*.js","default":"./esm/*.js"}},"gitHead":"5cbc92675c72b0bb2832f4633287c0fcfcb222c7","readme":"# @n1ru4l/graphql-public-schema-filter\n\nThis library allows filtering an existing GraphQL schema down into a subset of the original schema. It supports both the code first development flow of building GraphQL schemas (via GraphQL extension fields) and the SDL first development flow (via schema directives).\n\nThe implementation is smart and warns the user if the processed annotations would result in an invalid schema such as:\n\n- Object Type without fields\n- Field whose type is not part of the schema\n\nIf such a scenario is encountered the implementation will propagate and hide all fields/types that use types that are not marked as public or that would be invalid.\n\n## Why would you need this?\n\nAs I have been building GraphQL APIs I often had the need to have both a private and public API.\n\nThe private API is used for in-house products. Breaking changes can and will occur. It also includes types and fields specific to in-house application built around the API. The public API, however, is used by individuals not part of our organization. We cannot simply roll out breaking changes on the GraphQL API for those. Furthermore, they should only have access to a subset of the whole GraphQL graph. By generating a subgraph out of the internal graph we can hide stuff, without having to maintain and build two GraphQL schema.\n\n## Install instructions\n\nThis library requires `graphql` as a peer dependency and has a runtime dependency on `@graphql-tools/utils`.\n\n```bash\nyarn add -E @n1ru4l/graphql-public-schema-filter\n```\n\n## Usage Instructions\n\nThis library is designed to be inclusive for anyone within the GraphQL.js ecosystem. It supports both the SDL `makeExecutableSchema` and code-first via extension fields flow.\n\nThere is no delegation or validation overhead when executing against the newly generated schema. It is highly recommended to built the public schema during server-startup and not on the fly during incoming requests.\n\n### Code-First\n\nAnnotate types and fields that should be public with the `isPublic` extension.\n\n```ts\nimport { GraphQLObjectType, GraphQLString } from \"graphql\";\nimport { buildPublicSchema } from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst GraphQLQueryType = new GraphQLObjectType({\n  name: \"Query\",\n  fields: {\n    hello: {\n      type: GraphQLString,\n      resolve: () => \"hi\",\n      extensions: {\n        isPublic: true,\n      },\n    },\n    secret: {\n      type: GraphQLString,\n      resolve: () => \"sup\",\n    },\n  },\n});\n\nconst privateSchema = new GraphQLSchema({\n  query: GraphQLQueryType,\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\nYou can also find this example within `examples/src/schema.ts`.\n\n### SDL-First\n\nInstead of using the extension fields, we use the `@public` directive.\n\n```tsx\nimport { makeExecutableSchema } from \"@graphql-tools/schema\";\nimport {\n  publicDirectiveSDL,\n  buildPublicSchema,\n} from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst source = /* GraphQL */ `\n  type Query {\n    hello: String @public\n    secret: String\n  }\n`;\n\nconst privateSchema = makeExecutableSchema({\n  typeDefs: [publicDirectiveSDL, source],\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\n## FAQ\n\n### Why `isPublic` and `@public` over `isPrivate` and `@private`?\n\nDeny-listing is more prone to errors than allow-listing. By adding a directive/extension field we explicitly set something to public. The other way around it is easier to forgot to add a `@private`/ `isPrivate` annotation, which would automatically result in the new fields being public. Being verbose about what fields are public is the safest way.\n\n### Why is the no more granular control that allows building multiple unique public schemas?\n\nI considered this at the beginning, but in practice we never had a use for this. Having multiple public schemas requires maintaining a lot of documentation. In our use-case we only have a public and a private schema. There is still role based access for the public schema. certain users are not allowed to select specific fields. Instead of hiding those fields for those users we instead deny operations that select fields the users are not allowed to select before even executing it with the [envelop `useOperationFieldPermissions` plugin](https://www.envelop.dev/plugins/use-operation-field-permissions).\n\nYou can overwrite the `isPublic` function which is used to determine whether a field or type is public based on directives and extensions. This allows to fully customize the behavior based on your needs.\n\n```ts\ntype SharedExtensionAndDirectiveInformation = {\n  extensions?: Maybe<{\n    [attributeName: string]: any;\n  }>;\n  astNode?: Maybe<\n    Readonly<{\n      directives?: ReadonlyArray<DirectiveNode>;\n    }>\n  >;\n};\n\nexport const defaultIsPublic = (\n  input: SharedExtensionAndDirectiveInformation\n): boolean =>\n  input.extensions?.[\"isPublic\"] === true ||\n  !!input.astNode?.directives?.find(\n    (directive) => directive.name.value === \"public\"\n  );\n```\n\n## License\n\nMIT\n","readmeFilename":"README.md","_id":"@n1ru4l/graphql-public-schema-filter@2.0.0-alpha-20230506180651-5cbc926","_nodeVersion":"18.16.0","_npmVersion":"9.5.1","dist":{"integrity":"sha512-0d0zw5I5IudzqP9IZxh/t1ymsIuXnlU1dgXAJLivZYCjBaLVSWeZi9h9do/q0G6ZTVjchVsg/qlFKSCa0Vtp2w==","shasum":"3342b4441e852db3fe310ce023ab684d82df1419","tarball":"https://registry.npmjs.org/@n1ru4l/graphql-public-schema-filter/-/graphql-public-schema-filter-2.0.0-alpha-20230506180651-5cbc926.tgz","fileCount":20,"unpackedSize":36713,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDvi2BhXXzRw21n6dsEFwew83JdEbfAqq4+A3KFI71nfQIgMhfx9Bo+rw7b9al+iWubYfDqhGWHfDLt7mHXkXfCyiU="}]},"_npmUser":{"name":"n1ru4l","email":"laurinquast@googlemail.com"},"directories":{},"maintainers":[{"name":"n1ru4l","email":"laurinquast@googlemail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/graphql-public-schema-filter_2.0.0-alpha-20230506180651-5cbc926_1683396420589_0.37683400325104244"},"_hasShrinkwrap":false},"2.0.0-alpha-20230506185615-089af78":{"name":"@n1ru4l/graphql-public-schema-filter","version":"2.0.0-alpha-20230506185615-089af78","description":"Filter your GraphQL schema into a public schema.","peerDependencies":{"graphql":"16.x.x"},"dependencies":{"@graphql-tools/utils":"^9.0.0"},"author":{"name":"Laurin Quast","email":"laurinquast@googlemail.com","url":"https://github.com/n1ru4l"},"license":"MIT","main":"cjs/index.js","module":"esm/index.js","typings":"typings/index.d.ts","typescript":{"definition":"typings/index.d.ts"},"exports":{".":{"require":{"types":"./typings/index.d.cts","default":"./cjs/index.js"},"import":{"types":"./typings/index.d.ts","default":"./esm/index.js"},"default":{"types":"./typings/index.d.ts","default":"./esm/index.js"}},"./*":{"require":"./cjs/*.js","import":"./esm/*.js","default":"./esm/*.js"}},"gitHead":"089af7896b7e99c6e32aad933b75568df46b9a76","readme":"# @n1ru4l/graphql-public-schema-filter\n\nThis library allows filtering an existing GraphQL schema down into a subset of the original schema. It supports both the code first development flow of building GraphQL schemas (via GraphQL extension fields) and the SDL first development flow (via schema directives).\n\nThe implementation is smart and warns the user if the processed annotations would result in an invalid schema such as:\n\n- Object Type without fields\n- Field whose type is not part of the schema\n\nIf such a scenario is encountered the implementation will propagate and hide all fields/types that use types that are not marked as public or that would be invalid.\n\n## Why would you need this?\n\nAs I have been building GraphQL APIs I often had the need to have both a private and public API.\n\nThe private API is used for in-house products. Breaking changes can and will occur. It also includes types and fields specific to in-house application built around the API. The public API, however, is used by individuals not part of our organization. We cannot simply roll out breaking changes on the GraphQL API for those. Furthermore, they should only have access to a subset of the whole GraphQL graph. By generating a subgraph out of the internal graph we can hide stuff, without having to maintain and build two GraphQL schema.\n\n## Install instructions\n\nThis library requires `graphql` as a peer dependency and has a runtime dependency on `@graphql-tools/utils`.\n\n```bash\nyarn add -E @n1ru4l/graphql-public-schema-filter\n```\n\n## Usage Instructions\n\nThis library is designed to be inclusive for anyone within the GraphQL.js ecosystem. It supports both the SDL `makeExecutableSchema` and code-first via extension fields flow.\n\nThere is no delegation or validation overhead when executing against the newly generated schema. It is highly recommended to built the public schema during server-startup and not on the fly during incoming requests.\n\n### Code-First\n\nAnnotate types and fields that should be public with the `isPublic` extension.\n\n```ts\nimport { GraphQLObjectType, GraphQLString } from \"graphql\";\nimport { buildPublicSchema } from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst GraphQLQueryType = new GraphQLObjectType({\n  name: \"Query\",\n  fields: {\n    hello: {\n      type: GraphQLString,\n      resolve: () => \"hi\",\n      extensions: {\n        isPublic: true,\n      },\n    },\n    secret: {\n      type: GraphQLString,\n      resolve: () => \"sup\",\n    },\n  },\n});\n\nconst privateSchema = new GraphQLSchema({\n  query: GraphQLQueryType,\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\nYou can also find this example within `examples/src/schema.ts`.\n\n### SDL-First\n\nInstead of using the extension fields, we use the `@public` directive.\n\n```tsx\nimport { makeExecutableSchema } from \"@graphql-tools/schema\";\nimport {\n  publicDirectiveSDL,\n  buildPublicSchema,\n} from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst source = /* GraphQL */ `\n  type Query {\n    hello: String @public\n    secret: String\n  }\n`;\n\nconst privateSchema = makeExecutableSchema({\n  typeDefs: [publicDirectiveSDL, source],\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\n## FAQ\n\n### Why `isPublic` and `@public` over `isPrivate` and `@private`?\n\nDeny-listing is more prone to errors than allow-listing. By adding a directive/extension field we explicitly set something to public. The other way around it is easier to forgot to add a `@private`/ `isPrivate` annotation, which would automatically result in the new fields being public. Being verbose about what fields are public is the safest way.\n\n### Why is the no more granular control that allows building multiple unique public schemas?\n\nI considered this at the beginning, but in practice we never had a use for this. Having multiple public schemas requires maintaining a lot of documentation. In our use-case we only have a public and a private schema. There is still role based access for the public schema. certain users are not allowed to select specific fields. Instead of hiding those fields for those users we instead deny operations that select fields the users are not allowed to select before even executing it with the [envelop `useOperationFieldPermissions` plugin](https://www.envelop.dev/plugins/use-operation-field-permissions).\n\nYou can overwrite the `isPublic` function which is used to determine whether a field or type is public based on directives and extensions. This allows to fully customize the behavior based on your needs.\n\n```ts\ntype SharedExtensionAndDirectiveInformation = {\n  extensions?: Maybe<{\n    [attributeName: string]: any;\n  }>;\n  astNode?: Maybe<\n    Readonly<{\n      directives?: ReadonlyArray<DirectiveNode>;\n    }>\n  >;\n};\n\nexport const defaultIsPublic = (\n  input: SharedExtensionAndDirectiveInformation\n): boolean =>\n  input.extensions?.[\"isPublic\"] === true ||\n  !!input.astNode?.directives?.find(\n    (directive) => directive.name.value === \"public\"\n  );\n```\n\n## License\n\nMIT\n","readmeFilename":"README.md","_id":"@n1ru4l/graphql-public-schema-filter@2.0.0-alpha-20230506185615-089af78","_nodeVersion":"18.16.0","_npmVersion":"9.5.1","dist":{"integrity":"sha512-B7aGYwaFIfFbL9YPH+o+wPP10C6/dvp6g1U/5dHbi7d0DAGIAcV0O7T8CErXBs4er1J6VbXmDS0Y7AvNZbElvw==","shasum":"0954833944bd45016fe44c45d2486f40a76ed1a3","tarball":"https://registry.npmjs.org/@n1ru4l/graphql-public-schema-filter/-/graphql-public-schema-filter-2.0.0-alpha-20230506185615-089af78.tgz","fileCount":20,"unpackedSize":36713,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIAX0eeckWo2+tHJcK3p60nBvVO/8rDQBiIo0Zqa1QAfNAiBj7dIvv7qQ9GOpj3uGhYhr1kpwYisUK0EbkKL4wHcecg=="}]},"_npmUser":{"name":"n1ru4l","email":"laurinquast@googlemail.com"},"directories":{},"maintainers":[{"name":"n1ru4l","email":"laurinquast@googlemail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/graphql-public-schema-filter_2.0.0-alpha-20230506185615-089af78_1683399382564_0.7027911891166914"},"_hasShrinkwrap":false},"2.0.0-alpha-20230506190009-afad072":{"name":"@n1ru4l/graphql-public-schema-filter","version":"2.0.0-alpha-20230506190009-afad072","description":"Filter your GraphQL schema into a public schema.","peerDependencies":{"graphql":"16.x.x"},"dependencies":{"@graphql-tools/utils":"^9.0.0"},"author":{"name":"Laurin Quast","email":"laurinquast@googlemail.com","url":"https://github.com/n1ru4l"},"license":"MIT","main":"cjs/index.js","module":"esm/index.js","typings":"typings/index.d.ts","typescript":{"definition":"typings/index.d.ts"},"exports":{".":{"require":{"types":"./typings/index.d.cts","default":"./cjs/index.js"},"import":{"types":"./typings/index.d.ts","default":"./esm/index.js"},"default":{"types":"./typings/index.d.ts","default":"./esm/index.js"}},"./*":{"require":"./cjs/*.js","import":"./esm/*.js","default":"./esm/*.js"}},"gitHead":"afad072a249d3261022b3b4549b6f9ab455f8abb","readme":"# @n1ru4l/graphql-public-schema-filter\n\nThis library allows filtering an existing GraphQL schema down into a subset of the original schema. It supports both the code first development flow of building GraphQL schemas (via GraphQL extension fields) and the SDL first development flow (via schema directives).\n\nThe implementation is smart and warns the user if the processed annotations would result in an invalid schema such as:\n\n- Object Type without fields\n- Field whose type is not part of the schema\n\nIf such a scenario is encountered the implementation will propagate and hide all fields/types that use types that are not marked as public or that would be invalid.\n\n## Why would you need this?\n\nAs I have been building GraphQL APIs I often had the need to have both a private and public API.\n\nThe private API is used for in-house products. Breaking changes can and will occur. It also includes types and fields specific to in-house application built around the API. The public API, however, is used by individuals not part of our organization. We cannot simply roll out breaking changes on the GraphQL API for those. Furthermore, they should only have access to a subset of the whole GraphQL graph. By generating a subgraph out of the internal graph we can hide stuff, without having to maintain and build two GraphQL schema.\n\n## Install instructions\n\nThis library requires `graphql` as a peer dependency and has a runtime dependency on `@graphql-tools/utils`.\n\n```bash\nyarn add -E @n1ru4l/graphql-public-schema-filter\n```\n\n## Usage Instructions\n\nThis library is designed to be inclusive for anyone within the GraphQL.js ecosystem. It supports both the SDL `makeExecutableSchema` and code-first via extension fields flow.\n\nThere is no delegation or validation overhead when executing against the newly generated schema. It is highly recommended to built the public schema during server-startup and not on the fly during incoming requests.\n\n### Code-First\n\nAnnotate types and fields that should be public with the `isPublic` extension.\n\n```ts\nimport { GraphQLObjectType, GraphQLString } from \"graphql\";\nimport { buildPublicSchema } from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst GraphQLQueryType = new GraphQLObjectType({\n  name: \"Query\",\n  fields: {\n    hello: {\n      type: GraphQLString,\n      resolve: () => \"hi\",\n      extensions: {\n        isPublic: true,\n      },\n    },\n    secret: {\n      type: GraphQLString,\n      resolve: () => \"sup\",\n    },\n  },\n});\n\nconst privateSchema = new GraphQLSchema({\n  query: GraphQLQueryType,\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\nYou can also find this example within `examples/src/schema.ts`.\n\n### SDL-First\n\nInstead of using the extension fields, we use the `@public` directive.\n\n```tsx\nimport { makeExecutableSchema } from \"@graphql-tools/schema\";\nimport {\n  publicDirectiveSDL,\n  buildPublicSchema,\n} from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst source = /* GraphQL */ `\n  type Query {\n    hello: String @public\n    secret: String\n  }\n`;\n\nconst privateSchema = makeExecutableSchema({\n  typeDefs: [publicDirectiveSDL, source],\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\n## FAQ\n\n### Why `isPublic` and `@public` over `isPrivate` and `@private`?\n\nDeny-listing is more prone to errors than allow-listing. By adding a directive/extension field we explicitly set something to public. The other way around it is easier to forgot to add a `@private`/ `isPrivate` annotation, which would automatically result in the new fields being public. Being verbose about what fields are public is the safest way.\n\n### Why is the no more granular control that allows building multiple unique public schemas?\n\nI considered this at the beginning, but in practice we never had a use for this. Having multiple public schemas requires maintaining a lot of documentation. In our use-case we only have a public and a private schema. There is still role based access for the public schema. certain users are not allowed to select specific fields. Instead of hiding those fields for those users we instead deny operations that select fields the users are not allowed to select before even executing it with the [envelop `useOperationFieldPermissions` plugin](https://www.envelop.dev/plugins/use-operation-field-permissions).\n\nYou can overwrite the `isPublic` function which is used to determine whether a field or type is public based on directives and extensions. This allows to fully customize the behavior based on your needs.\n\n```ts\ntype SharedExtensionAndDirectiveInformation = {\n  extensions?: Maybe<{\n    [attributeName: string]: any;\n  }>;\n  astNode?: Maybe<\n    Readonly<{\n      directives?: ReadonlyArray<DirectiveNode>;\n    }>\n  >;\n};\n\nexport const defaultIsPublic = (\n  input: SharedExtensionAndDirectiveInformation\n): boolean =>\n  input.extensions?.[\"isPublic\"] === true ||\n  !!input.astNode?.directives?.find(\n    (directive) => directive.name.value === \"public\"\n  );\n```\n\n## License\n\nMIT\n","readmeFilename":"README.md","_id":"@n1ru4l/graphql-public-schema-filter@2.0.0-alpha-20230506190009-afad072","_nodeVersion":"18.16.0","_npmVersion":"9.5.1","dist":{"integrity":"sha512-IWE6E7Z+4EbGiMg9RMYq4chU/vSSog485wriLMjmx7zoPQWMZLk3HsmsJjl2B8h964pQJK/jbxxCKhZkP3IoJA==","shasum":"c24e5b5eb7ca0848f2fc88fa502aadc669f5d8f2","tarball":"https://registry.npmjs.org/@n1ru4l/graphql-public-schema-filter/-/graphql-public-schema-filter-2.0.0-alpha-20230506190009-afad072.tgz","fileCount":20,"unpackedSize":36713,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIF2+pRU2HLIwbJW9RwnqBG43TvyHOoNfc1CAqUbvZsUhAiEAugGMZbR/LUFYLx2jYn4D5bMyiQnj2sHwdX/vSOsK5Ew="}]},"_npmUser":{"name":"n1ru4l","email":"laurinquast@googlemail.com"},"directories":{},"maintainers":[{"name":"n1ru4l","email":"laurinquast@googlemail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/graphql-public-schema-filter_2.0.0-alpha-20230506190009-afad072_1683399617058_0.362706146495416"},"_hasShrinkwrap":false},"2.0.0-alpha-20230506190034-9763797":{"name":"@n1ru4l/graphql-public-schema-filter","version":"2.0.0-alpha-20230506190034-9763797","description":"Filter your GraphQL schema into a public schema.","peerDependencies":{"graphql":"16.x.x"},"dependencies":{"@graphql-tools/utils":"^9.0.0"},"author":{"name":"Laurin Quast","email":"laurinquast@googlemail.com","url":"https://github.com/n1ru4l"},"license":"MIT","main":"cjs/index.js","module":"esm/index.js","typings":"typings/index.d.ts","typescript":{"definition":"typings/index.d.ts"},"exports":{".":{"require":{"types":"./typings/index.d.cts","default":"./cjs/index.js"},"import":{"types":"./typings/index.d.ts","default":"./esm/index.js"},"default":{"types":"./typings/index.d.ts","default":"./esm/index.js"}},"./*":{"require":"./cjs/*.js","import":"./esm/*.js","default":"./esm/*.js"}},"gitHead":"976379760ab0165edd59b5962bef28bb32de2720","readme":"# @n1ru4l/graphql-public-schema-filter\n\nThis library allows filtering an existing GraphQL schema down into a subset of the original schema. It supports both the code first development flow of building GraphQL schemas (via GraphQL extension fields) and the SDL first development flow (via schema directives).\n\nThe implementation is smart and warns the user if the processed annotations would result in an invalid schema such as:\n\n- Object Type without fields\n- Field whose type is not part of the schema\n\nIf such a scenario is encountered the implementation will propagate and hide all fields/types that use types that are not marked as public or that would be invalid.\n\n## Why would you need this?\n\nAs I have been building GraphQL APIs I often had the need to have both a private and public API.\n\nThe private API is used for in-house products. Breaking changes can and will occur. It also includes types and fields specific to in-house application built around the API. The public API, however, is used by individuals not part of our organization. We cannot simply roll out breaking changes on the GraphQL API for those. Furthermore, they should only have access to a subset of the whole GraphQL graph. By generating a subgraph out of the internal graph we can hide stuff, without having to maintain and build two GraphQL schema.\n\n## Install instructions\n\nThis library requires `graphql` as a peer dependency and has a runtime dependency on `@graphql-tools/utils`.\n\n```bash\nyarn add -E @n1ru4l/graphql-public-schema-filter\n```\n\n## Usage Instructions\n\nThis library is designed to be inclusive for anyone within the GraphQL.js ecosystem. It supports both the SDL `makeExecutableSchema` and code-first via extension fields flow.\n\nThere is no delegation or validation overhead when executing against the newly generated schema. It is highly recommended to built the public schema during server-startup and not on the fly during incoming requests.\n\n### Code-First\n\nAnnotate types and fields that should be public with the `isPublic` extension.\n\n```ts\nimport { GraphQLObjectType, GraphQLString } from \"graphql\";\nimport { buildPublicSchema } from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst GraphQLQueryType = new GraphQLObjectType({\n  name: \"Query\",\n  fields: {\n    hello: {\n      type: GraphQLString,\n      resolve: () => \"hi\",\n      extensions: {\n        isPublic: true,\n      },\n    },\n    secret: {\n      type: GraphQLString,\n      resolve: () => \"sup\",\n    },\n  },\n});\n\nconst privateSchema = new GraphQLSchema({\n  query: GraphQLQueryType,\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\nYou can also find this example within `examples/src/schema.ts`.\n\n### SDL-First\n\nInstead of using the extension fields, we use the `@public` directive.\n\n```tsx\nimport { makeExecutableSchema } from \"@graphql-tools/schema\";\nimport {\n  publicDirectiveSDL,\n  buildPublicSchema,\n} from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst source = /* GraphQL */ `\n  type Query {\n    hello: String @public\n    secret: String\n  }\n`;\n\nconst privateSchema = makeExecutableSchema({\n  typeDefs: [publicDirectiveSDL, source],\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\n## FAQ\n\n### Why `isPublic` and `@public` over `isPrivate` and `@private`?\n\nDeny-listing is more prone to errors than allow-listing. By adding a directive/extension field we explicitly set something to public. The other way around it is easier to forgot to add a `@private`/ `isPrivate` annotation, which would automatically result in the new fields being public. Being verbose about what fields are public is the safest way.\n\n### Why is the no more granular control that allows building multiple unique public schemas?\n\nI considered this at the beginning, but in practice we never had a use for this. Having multiple public schemas requires maintaining a lot of documentation. In our use-case we only have a public and a private schema. There is still role based access for the public schema. certain users are not allowed to select specific fields. Instead of hiding those fields for those users we instead deny operations that select fields the users are not allowed to select before even executing it with the [envelop `useOperationFieldPermissions` plugin](https://www.envelop.dev/plugins/use-operation-field-permissions).\n\nYou can overwrite the `isPublic` function which is used to determine whether a field or type is public based on directives and extensions. This allows to fully customize the behavior based on your needs.\n\n```ts\ntype SharedExtensionAndDirectiveInformation = {\n  extensions?: Maybe<{\n    [attributeName: string]: any;\n  }>;\n  astNode?: Maybe<\n    Readonly<{\n      directives?: ReadonlyArray<DirectiveNode>;\n    }>\n  >;\n};\n\nexport const defaultIsPublic = (\n  input: SharedExtensionAndDirectiveInformation\n): boolean =>\n  input.extensions?.[\"isPublic\"] === true ||\n  !!input.astNode?.directives?.find(\n    (directive) => directive.name.value === \"public\"\n  );\n```\n\n## License\n\nMIT\n","readmeFilename":"README.md","_id":"@n1ru4l/graphql-public-schema-filter@2.0.0-alpha-20230506190034-9763797","_nodeVersion":"18.16.0","_npmVersion":"9.5.1","dist":{"integrity":"sha512-PRT3S0u9JlwjtI/Qhf6hNq5kUq9RDKeelP9iwzMrXb0derz3hxUoAsr7JIzWX3YanXraKbSv4dBSi3MxKeKrlg==","shasum":"cc115559ed3b2de674850a4f9b86a22fd887d08b","tarball":"https://registry.npmjs.org/@n1ru4l/graphql-public-schema-filter/-/graphql-public-schema-filter-2.0.0-alpha-20230506190034-9763797.tgz","fileCount":20,"unpackedSize":36713,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCWS2hMirz5kUEBkWFb7diFqcP9BlBizm5C81YY3AbkugIgHsxwaDSITadY6lai7XyrImdCKovpwL+Fwom2UUjH14E="}]},"_npmUser":{"name":"n1ru4l","email":"laurinquast@googlemail.com"},"directories":{},"maintainers":[{"name":"n1ru4l","email":"laurinquast@googlemail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/graphql-public-schema-filter_2.0.0-alpha-20230506190034-9763797_1683399643018_0.7760110686577"},"_hasShrinkwrap":false},"2.0.0":{"name":"@n1ru4l/graphql-public-schema-filter","version":"2.0.0","description":"Filter your GraphQL schema into a public schema.","peerDependencies":{"graphql":"16.x.x"},"dependencies":{"@graphql-tools/utils":"^9.0.0"},"author":{"name":"Laurin Quast","email":"laurinquast@googlemail.com","url":"https://github.com/n1ru4l"},"license":"MIT","main":"cjs/index.js","module":"esm/index.js","typings":"typings/index.d.ts","typescript":{"definition":"typings/index.d.ts"},"exports":{".":{"require":{"types":"./typings/index.d.cts","default":"./cjs/index.js"},"import":{"types":"./typings/index.d.ts","default":"./esm/index.js"},"default":{"types":"./typings/index.d.ts","default":"./esm/index.js"}},"./*":{"require":"./cjs/*.js","import":"./esm/*.js","default":"./esm/*.js"}},"gitHead":"e76b6e10858588b5e5724f27be6945ee11b462cc","_id":"@n1ru4l/graphql-public-schema-filter@2.0.0","_nodeVersion":"18.16.0","_npmVersion":"9.5.1","dist":{"integrity":"sha512-n2uDQOUo8kA8EFiORcwDpezFjHsK4WLDjd1vxjU9zpOg+pn5wIzcA6unzvYqiGlv350SKn6Vv/0Ws9tQ+vUhJw==","shasum":"865cf44c6030a6a7e154e2bd83ace97819c10086","tarball":"https://registry.npmjs.org/@n1ru4l/graphql-public-schema-filter/-/graphql-public-schema-filter-2.0.0.tgz","fileCount":20,"unpackedSize":36684,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDuNwG9cHLBU75X2Gs1yis4BI8WDBbohtfXnBBdbh916QIgcGEqgU3zU5ktHKKn3p1BuEFUMM1FqvNlOxAqLf2M8mc="}]},"_npmUser":{"name":"n1ru4l","email":"laurinquast@googlemail.com"},"directories":{},"maintainers":[{"name":"n1ru4l","email":"laurinquast@googlemail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/graphql-public-schema-filter_2.0.0_1683400454230_0.019949170381232673"},"_hasShrinkwrap":false}},"time":{"created":"2021-07-27T13:50:38.505Z","0.1.0":"2021-07-27T13:50:38.708Z","modified":"2023-05-06T19:14:14.538Z","0.2.0":"2021-07-28T05:16:45.803Z","0.3.0":"2021-07-28T06:12:04.986Z","0.3.1":"2021-07-29T09:56:55.134Z","0.4.0":"2021-08-04T08:02:31.850Z","0.4.1-alpha-20220809154712-2549aa9":"2022-08-09T15:47:20.674Z","1.0.0-alpha-20220928122146-5a2f3e3":"2022-09-28T12:21:53.506Z","1.0.0-alpha-20220928122259-f3697d2":"2022-09-28T12:23:06.398Z","1.0.0-alpha-20220928122321-192fe3f":"2022-09-28T12:23:28.404Z","1.0.0-alpha-20220928122357-14cc304":"2022-09-28T12:24:05.063Z","1.0.0":"2022-09-28T13:43:52.786Z","1.1.0-alpha-20221124104716-188eb70":"2022-11-24T10:47:26.285Z","1.1.0-alpha-20221125113817-e6a165a":"2022-11-25T11:38:26.313Z","1.1.0-alpha-20221128184529-1e76543":"2022-11-28T18:45:39.785Z","1.1.0-alpha-20221130233145-9e0e08d":"2022-11-30T23:31:53.509Z","1.1.0":"2022-12-02T16:09:46.195Z","2.0.0-alpha-20230506173925-b7dc957":"2023-05-06T17:39:34.791Z","2.0.0-alpha-20230506174140-24e9153":"2023-05-06T17:41:47.759Z","2.0.0-alpha-20230506174210-d334620":"2023-05-06T17:42:19.715Z","2.0.0-alpha-20230506174240-a16e2a7":"2023-05-06T17:42:49.605Z","2.0.0-alpha-20230506174311-82eb981":"2023-05-06T17:43:18.870Z","2.0.0-alpha-20230506174324-4490b4d":"2023-05-06T17:43:32.624Z","2.0.0-alpha-20230506175146-dfd01cb":"2023-05-06T17:51:54.032Z","2.0.0-alpha-20230506175216-393a8b2":"2023-05-06T17:52:24.482Z","2.0.0-alpha-20230506175305-c10106b":"2023-05-06T17:53:12.849Z","2.0.0-alpha-20230506175416-afa59e7":"2023-05-06T17:54:24.058Z","2.0.0-alpha-20230506175452-62581f8":"2023-05-06T17:55:01.548Z","2.0.0-alpha-20230506180028-00d68a8":"2023-05-06T18:00:38.181Z","2.0.0-alpha-20230506180237-65559c9":"2023-05-06T18:02:44.691Z","2.0.0-alpha-20230506180327-894dd36":"2023-05-06T18:03:36.580Z","2.0.0-alpha-20230506180347-b1d02b3":"2023-05-06T18:03:55.655Z","2.0.0-alpha-20230506180549-b22502c":"2023-05-06T18:05:56.494Z","2.0.0-alpha-20230506180651-5cbc926":"2023-05-06T18:07:00.772Z","2.0.0-alpha-20230506185615-089af78":"2023-05-06T18:56:22.707Z","2.0.0-alpha-20230506190009-afad072":"2023-05-06T19:00:17.215Z","2.0.0-alpha-20230506190034-9763797":"2023-05-06T19:00:43.184Z","2.0.0":"2023-05-06T19:14:14.414Z"},"maintainers":[{"name":"n1ru4l","email":"laurinquast@googlemail.com"}],"description":"Filter your GraphQL schema into a public schema.","author":{"name":"Laurin Quast","email":"laurinquast@googlemail.com","url":"https://github.com/n1ru4l"},"license":"MIT","readme":"# @n1ru4l/graphql-public-schema-filter\n\nThis library allows filtering an existing GraphQL schema down into a subset of the original schema. It supports both the code first development flow of building GraphQL schemas (via GraphQL extension fields) and the SDL first development flow (via schema directives).\n\nThe implementation is smart and warns the user if the processed annotations would result in an invalid schema such as:\n\n- Object Type without fields\n- Field whose type is not part of the schema\n\nIf such a scenario is encountered the implementation will propagate and hide all fields/types that use types that are not marked as public or that would be invalid.\n\n## Why would you need this?\n\nAs I have been building GraphQL APIs I often had the need to have both a private and public API.\n\nThe private API is used for in-house products. Breaking changes can and will occur. It also includes types and fields specific to in-house application built around the API. The public API, however, is used by individuals not part of our organization. We cannot simply roll out breaking changes on the GraphQL API for those. Furthermore, they should only have access to a subset of the whole GraphQL graph. By generating a subgraph out of the internal graph we can hide stuff, without having to maintain and build two GraphQL schema.\n\n## Install instructions\n\nThis library requires `graphql` as a peer dependency and has a runtime dependency on `@graphql-tools/utils`.\n\n```bash\nyarn add -E @n1ru4l/graphql-public-schema-filter\n```\n\n## Usage Instructions\n\nThis library is designed to be inclusive for anyone within the GraphQL.js ecosystem. It supports both the SDL `makeExecutableSchema` and code-first via extension fields flow.\n\nThere is no delegation or validation overhead when executing against the newly generated schema. It is highly recommended to built the public schema during server-startup and not on the fly during incoming requests.\n\n### Code-First\n\nAnnotate types and fields that should be public with the `isPublic` extension.\n\n```ts\nimport { GraphQLObjectType, GraphQLString } from \"graphql\";\nimport { buildPublicSchema } from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst GraphQLQueryType = new GraphQLObjectType({\n  name: \"Query\",\n  fields: {\n    hello: {\n      type: GraphQLString,\n      resolve: () => \"hi\",\n      extensions: {\n        isPublic: true,\n      },\n    },\n    secret: {\n      type: GraphQLString,\n      resolve: () => \"sup\",\n    },\n  },\n});\n\nconst privateSchema = new GraphQLSchema({\n  query: GraphQLQueryType,\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\nYou can also find this example within `examples/src/schema.ts`.\n\n### SDL-First\n\nInstead of using the extension fields, we use the `@public` directive.\n\n```tsx\nimport { makeExecutableSchema } from \"@graphql-tools/schema\";\nimport {\n  publicDirectiveSDL,\n  buildPublicSchema,\n} from \"@n1ru4l/graphql-public-schema-filter\";\n\nconst source = /* GraphQL */ `\n  type Query {\n    hello: String @public\n    secret: String\n  }\n`;\n\nconst privateSchema = makeExecutableSchema({\n  typeDefs: [publicDirectiveSDL, source],\n});\nconst publicSchema = buildPublicSchema({ schema: privateSchema });\n// serve privateSchema or publicSchema based on the request :)\n```\n\n## FAQ\n\n### Why `isPublic` and `@public` over `isPrivate` and `@private`?\n\nDeny-listing is more prone to errors than allow-listing. By adding a directive/extension field we explicitly set something to public. The other way around it is easier to forgot to add a `@private`/ `isPrivate` annotation, which would automatically result in the new fields being public. Being verbose about what fields are public is the safest way.\n\n### Why is the no more granular control that allows building multiple unique public schemas?\n\nI considered this at the beginning, but in practice we never had a use for this. Having multiple public schemas requires maintaining a lot of documentation. In our use-case we only have a public and a private schema. There is still role based access for the public schema. certain users are not allowed to select specific fields. Instead of hiding those fields for those users we instead deny operations that select fields the users are not allowed to select before even executing it with the [envelop `useOperationFieldPermissions` plugin](https://www.envelop.dev/plugins/use-operation-field-permissions).\n\nYou can overwrite the `isPublic` function which is used to determine whether a field or type is public based on directives and extensions. This allows to fully customize the behavior based on your needs.\n\n```ts\ntype SharedExtensionAndDirectiveInformation = {\n  extensions?: Maybe<{\n    [attributeName: string]: any;\n  }>;\n  astNode?: Maybe<\n    Readonly<{\n      directives?: ReadonlyArray<DirectiveNode>;\n    }>\n  >;\n};\n\nexport const defaultIsPublic = (\n  input: SharedExtensionAndDirectiveInformation\n): boolean =>\n  input.extensions?.[\"isPublic\"] === true ||\n  !!input.astNode?.directives?.find(\n    (directive) => directive.name.value === \"public\"\n  );\n```\n\n## License\n\nMIT\n","readmeFilename":"README.md"}