My preferred "easy/simple" model of app design is Firebase (backend and JS lib for pure web clients), who have security figured out.
My preferred "easy/simple" model of app design is Firebase (backend and JS lib for pure web clients), who have security figured out.
Unlike Firebase, Meteor actually allows you to send "first top 20 guest posts from November" as an example. The filtering can happen on the server, before sending the data and the data model usually fits into a sets of documents in set of collections. In Firebase, everything is part of a big subtree that is not filterable (the last time I checked).
Firebase is a good choice for keeping your real-time data. But knowing its limitations is as important as knowing its strengths.
We also have limitToFirst(), limitToLast(), startAt(), endAt(), and equalTo() methods to further filter your data.
This allows you to build queries like this:
ref.orderByChild("weight").limitToLast(2).on("child_added", function(snapshot) {
console.log(snapshot.key());
});
Please check out our querying docs[1], and let us know if you have any questions![0] https://www.firebase.com/blog/2014-11-04-firebase-realtime-q...
You remove the autopublish package and you can no longer query records from the client.
If there's one thing we should have learned from Rails' various security failures, it's that things must be secure by default.
Likewise, no matter what languages, majority are insecure by defaults.
One of the things I like about rails (and ember-cli) is that it is "secure-by-default". If I am going to make a choice that potentially has security vulnerabilities, I have to deliberately make that choice - I basically have to create a whitelist of things I want to allow.
It leaves a "I should triple check everything again before going live since I cannot trust the tool to do its job" thread running permanently in the back of the mind. It's such a slowdown. Don't get me wrong, it's important to read the documentation and double check settings, but insanity by default does not build trust.
That said in the case of meteor beyond the autopublish package that should be off by default, I think everything is spot on. I mostly use PostgreSQL, so I cannot use it as much as I'd like to, but hopefully that will change.
meteor remove autopublish
meteor remove insecure
The Mongo-accessible frontent is genius. This makes your prototyping much faster, and you can totally skip the "model" layer of your frontend. It matches your backend automatically. No further configuration needed. No REST endpoints, no callbacks. And yes, it's secure.
Meteor's security model is very well-designed. The list of things left for the developer to do, security-wise, is very short.
It's still important to learn your tools and understand how security works.
http://security-resources.meteor.com/