# Adding a Auth Directive that only allows public access to some fields

**URL:** <https://discuss.dgraph.io/t/adding-a-auth-directive-that-only-allows-public-access-to-some-fields/17737>\
**Category:** GraphQL\
**Tags:** kind:question, dgraph\
**Created:** [September 7, 2022, 3:46pm UTC](https://discuss.dgraph.io/t/adding-a-auth-directive-that-only-allows-public-access-to-some-fields/17737 "2022-09-07T15:46:58Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Matt\_Wardle](https://yyz1.discourse-cdn.com/flex007/user_avatar/discuss.dgraph.io/matt_wardle/32/6563_2.png) [@Matt\_Wardle](https://discuss.dgraph.io/u/Matt_Wardle)\
**Post date:** [September 7, 2022, 3:46pm UTC](https://discuss.dgraph.io/t/adding-a-auth-directive-that-only-allows-public-access-to-some-fields/17737/1 "2022-09-07T15:46:58Z")

</div>

Is there any way to just allow public access to some fields from a type? So in the example type below only allow other users to access id and name without giving access to the email?

```auto
type User {
  id: ID!
  name: String
  email: String
}

```

---

<div class="post-metadata">

**Author:** ![MichelDiz](https://yyz1.discourse-cdn.com/flex007/user_avatar/discuss.dgraph.io/micheldiz/32/11873_2.png) [@MichelDiz](https://discuss.dgraph.io/u/MichelDiz)\
**Post date:** [September 7, 2022, 4:21pm UTC](https://discuss.dgraph.io/t/adding-a-auth-directive-that-only-allows-public-access-to-some-fields/17737/2 "2022-09-07T16:21:28Z")

</div>

That’s not possible as far as I know.

---

<div class="post-metadata">

**Author:** ![jdgamble555](https://yyz1.discourse-cdn.com/flex007/user_avatar/discuss.dgraph.io/jdgamble555/32/7503_2.png) [@jdgamble555](https://discuss.dgraph.io/u/jdgamble555)\
**Post date:** [September 7, 2022, 4:31pm UTC](https://discuss.dgraph.io/t/adding-a-auth-directive-that-only-allows-public-access-to-some-fields/17737/3 "2022-09-07T16:31:29Z")

</div>

It is not currently possible.

You basically have two work arounds:

1. Create two User types, one with public, one with private info
2. Lock the whole type from view, and create a custom dql query to query only what you want to be visible

> [@How to achieve field level auth at the moment?](http://discuss.hypermode.com/t/how-to-achieve-field-level-auth-at-the-moment/13069):
>
> I will explain my issue, but first let me tell you a quick overview. I am creating a POC for a new project which has little bit similar functionality to the DevJokes Example repo here - [graphql-sample-apps/dev-jokes at master · dgraph-io/graphql-sample-apps · GitHub](https://github.com/dgraph-io/graphql-sample-apps/tree/master/dev-jokes) My Frontend is going to be connected to the Slash GraphQL directly and there is no server in-between. to summarize, Users would be able to post stuff that needs to go through an Approval Process. this is present in the example lin…

J

---

<div class="post-metadata">

**Author:** ![Matt\_Wardle](https://yyz1.discourse-cdn.com/flex007/user_avatar/discuss.dgraph.io/matt_wardle/32/6563_2.png) [@Matt\_Wardle](https://discuss.dgraph.io/u/Matt_Wardle)\
**Post date:** [September 8, 2022, 8:39am UTC](https://discuss.dgraph.io/t/adding-a-auth-directive-that-only-allows-public-access-to-some-fields/17737/4 "2022-09-08T08:39:50Z")

</div>

Thanks for your response. With the two type option could the public node just reference the private one. Or would we have to duplicate the node?

---

<div class="post-metadata">

**Author:** ![jdgamble555](https://yyz1.discourse-cdn.com/flex007/user_avatar/discuss.dgraph.io/jdgamble555/32/7503_2.png) [@jdgamble555](https://discuss.dgraph.io/u/jdgamble555)\
**Post date:** [September 8, 2022, 10:54am UTC](https://discuss.dgraph.io/t/adding-a-auth-directive-that-only-allows-public-access-to-some-fields/17737/5 "2022-09-08T10:54:01Z")

</div>

The private could reference the public but not the other way around. The information would be different, as there would be no need to duplicate data.

J

---

<div class="post-metadata">

**Author:** ![amaster507](https://yyz1.discourse-cdn.com/flex007/user_avatar/discuss.dgraph.io/amaster507/32/4123_2.png) [@amaster507](https://discuss.dgraph.io/u/amaster507)\
**Post date:** [September 8, 2022, 2:58pm UTC](https://discuss.dgraph.io/t/adding-a-auth-directive-that-only-allows-public-access-to-some-fields/17737/6 "2022-09-08T14:58:05Z")

</div>

Another idea in theory is to use an interface where the interface is the public and the implementing is the private. This would mean that the data was on a singular node still. There might be some other gotchas when using this model but in theory it should work.

---

<div class="post-metadata">

**Author:** ![Poolshark](https://yyz1.discourse-cdn.com/flex007/user_avatar/discuss.dgraph.io/poolshark/32/10074_2.png) [@Poolshark](https://discuss.dgraph.io/u/Poolshark)\
**Post date:** [September 29, 2022, 4:46am UTC](https://discuss.dgraph.io/t/adding-a-auth-directive-that-only-allows-public-access-to-some-fields/17737/7 "2022-09-29T04:46:31Z")

</div>

@amaster507 this will not work as expected. If I understood right, then you suggest something like this:

```auto
interface Public {
  id: ID!
  name: String
}

type User implements Public 
  @auth(
    # query rules - eg. users can only see their own email
  ){
  id: ID!
  name: String

  email: String
}

```

In such a scenario you would not be able to run a **single user query** for type `User` since `@auth` rules for the implementation of interfaces are connected with `AND`. Thus, querying _(and applying the assumption that `@auth` is set so that a user can only query himself)_

```auto
query User {
  queryUser {
    id
    name
    email
  }
}

# Result
{
  data: {
    queryUser: [
      {
        id: "0x1"
        name: "My User"
        email: "myuser@user.com"
      }
    ]
  }
}

```

would only give one result - that of the querying user. Running the query via the interface would result in the expected results for all users

```auto
query Public {
  queryPublic {
    id
    name
  }
}

# Result
{
  data: {
    queryPublic: [
      {
        id: "0x1"
        name: "My User"
      },
      {
        id: "0x2"
        name: "User 2"
      },
      {
        id: "0x3"
        name: "User 3"
      }
    ]
  }
}

```

So, at least in my understanding, the only way of having a single user query with the expected field protection is either via a [`@custom DQL`](https://dgraph.io/docs/graphql/custom/dql/) query if you only care about query protection, or, if you need a more sophisticated approach _(eg. including mutations)_, via [custom lambda resolvers.](https://dgraph.io/docs/graphql/lambda/overview/)
