503 karma · joined February 18, 2010
yatsyk@gmail.com
Here are the advantages of this approach compared to using guts lib: - I get validation with clear error messages. - It supports many languages out of the box. - I don’t need to maintain a custom library. - JSON Schema is well supported in LLMs (for example, with structured output or vibe coding).
As I understand it, Durov doesn’t agree with your statement — you can check point 5 of his 2014 manifesto [1]
[1] https://globalvoices.org/2014/03/13/pavel-durovs-seven-reaso...
But I think it’s hypocritical to talk about freedom of speech issues in Western Europe while ignoring similar or worse restrictions in China, Russia, or Dubai, where he lives.
It’s similar to Musk’s approach — when Twitter is shut down in Brazil, it’s a freedom of speech violation, but having a Tesla factory in China suddenly makes that problem disappear there.
Disclaimer: I'm the author
[1] https://treemap.yatsyk.com/ [2] https://treemap.yatsyk.com/folderstat
I've created npm module for cushion treemap rendering [1]. Treemaps is most compact way to visualize huge tree structures such as file sytem.
This tool allows to create transport schemas such as metro maps. You can import data from open street map data to save time or start from scratch. Maps stored in git repository so you can consider this editor like headless CMS for static site and in order to edit schema created by other user you need to fork it.
I like rails, but in js world may be not so good idea to reimplement or integrate everything related to ui, routing etc. Meteor.js was not very successful with this model. I think routing or UI on react-native/web/blessed/VR is too different to be part of one framework.
But I see the usefulness of framework with functionality related to data fetching and business logic.
I consider perfect stack for this things is Postgress->Hasura (or also Prisma)->mst-gql->mobx-state-tree. You create database schema and everything up to models on client is autogenerated and each part of this stack could be updated, customized or completely rewritten. This stack could be used on react-native or web or any other js platform.
You can check even trivial rails blog or todo example from some book and it will be limited in scope but more or less secure. I'm having hard time to find secure couchdb example.
> Security for all systems is non trivial. But not equally hard.
If you use firebase you should understand that you getting vendor lock-in and in some cases you can spend much more money, but for some types of projects this platform is ok for me.
Same with couchdb, I understand that if I get replication with client, I need to pay by reorganising data or may be spend more resources to make system secure. There is no free lunch.
In case of couch I've not seen any secure open-source example.
I'm not focused on DOS attacks, I'm just proposing different attack vectors.
Spam prevention is not trivial but mostly solved problem. You can find a lot of articles about this topic.
But creating secure couchdb looks like very non-trivial.
My idea that it’s very hard to create safe couchdb based system and most recommendations limited to setup nginx proxy and authenticate users which is not enough.
Mongo and postgress usually is not accessible for clients only for backend. Security handled by backend mostly and there is a plenty of resources how to implement secure server side applications which discusses attack vectors and how to make secure apps. Thankfully to this thread I’ve got few good ideas, that may help to design secure couchdb architecture (such as remove _find endpoint) but I’ve not seen any in-depth document about couchdb.
> I feel like your thinking about Couch as exposing your entire PostgreSQL DB to the internet
No, why do you think so?
[1] https://stackoverflow.com/questions/40752578/couchdb-views-c...
I’ve limited document size to 10mb and ratelimited updates to 10 per second. Client starts to update document with random data 10 requests per second. As far as I understand couch stores all versions at least some time. This means that this one client could fill space on my server 100mb/s. There is no such issues with postgress, and no one allow clients execute raw queries on database without any application server. Document only 10mb but database is huge.
> What kind of "expensive" query are you envisioning?
I have never used couch, so I don’t know what could be expensive. May be some lookup without index or something like this.
Sorry for my ignorance, is it true that if I limit couch only to replication it will not be any not indexed lookups?
Looks like implement secure system with couch is very hard but I can’t find any best practices, mostly only authentication and basic validation.
I'm not sure about current time but previously it was a problem that couchdb file grow until some limit on filesystem and couchdb just crashed.
Start of the envoy readme: it's not battle tested or supported in any way. Also it doesn't do any validation apart from limiting permissions for different users.
It's easier to reimplement couchdb than to create smart proxy that will estimate is this query expensive or not.
I'm not saying about rate-limiting proxy or load-balancing to different backends which could be implemented on nginx or something else.
One of the major selling point of couchdb is replication protocol for client-server data syncing. When you design product with posgress you don't allow to execute raw sql queries from clients without any application server. But looks like it is recommended way to update data in couchdb world if you want to have synchronisation. I can't understand how can this architecture be secure?