The GraphQL /api/graphql endpoint returns all locations regardless of the requesting user's permissions, while the REST API /api/v2/locations correctly filters locations based on user access rights.