First, the author doesn't really address security and authorization, in fact they gloss over it. The typical solution with CouchDB/PouchDB seems to be per-user databases. That sounds horrendous to a SQL guy (me), but it turns out that CouchDB can happily handle hundreds of thousands of databases.
In my current application I have found couchperuser very useful. It's an Erlang Couchdb plugin that creates a database with appropriate permissions every time you create an entry in the _users database. (Access to the _users database is restricted to an admin account so is done via a parallel web service.)
If users are accessing CouchDB directly, of course you gotta worry about what horrors they're stuffing into your lovely pristine database. Control over that is provided via Javascript validation functions that are run on every document save. Those are saved into the per-user database at account creation time.
The biggest downside to this architecture that I've found is that there is two sources of truth on the client - the Redux store and the PouchDB database.