Then again, REST/RPC are query languages in their own right.
How would one go about securing this thing anyways?
(I agree with the basic sentiment, but find it somewhat unrealistic)
How would one go about securing this thing anyways?
(I agree with the basic sentiment, but find it somewhat unrealistic)
If along you expose not the the real tables but views I honestly don't see what could go wrong.
Then again, no doubt there are some cases where this is the best solution. But it's worth being cautious before adopting an approach like this.