4 ms·
The video is a bit hard to follow, but looking at the code shown at 1:14, Datomic transactions seems to be made directly from the GUI. Isn't this a major secur
by casperc 11y ago
The video is a bit hard to follow, but looking at the code shown at 1:14, Datomic transactions seems to be made directly from the GUI.
Isn't this a major security problem given that anyone could just send arbitrary transactions using e.g. the Chrome console?
- swannodette 11y agoThat is server side code not client side code.
- jlongster 11y agoThe colocated queries on the frontend components are not datomic queries, Om Next has its own query language which is similar but the backend needs to translate it into datomic queries so you implement whatever security you need there.
- dignati 11y agoYou can add some sort of safety by only allowing transactions that use functions stored in the transactor.