Graphql Security

Hi,

I want to know how to make sure that my app extension or normal app embed is secure and not misused by bad actors.

Let’s say I am creating a product or customer (mutation) using GraphQL on the front end. How do I make sure it will not be used?