3 ms·
We used Firebase ACL to prevent from that. Our backend were already splited.
by baptistejamin 10y ago
We used Firebase ACL to prevent from that.
Our backend were already splited.
- Mister_Snuggles 10y agoOk, so Firebase already has a way to make sure clients can only look at/update data they're authorized to do so? What about business rules? Is there a way to enforce that, for example, when one product is ordered an additional item is automatically added to a shopping cart (e.g., if I buy a computer, my province requires a recycling fee be paid too)? Or does this get beyond what Firebase is meant for?
- thruflo22 10y agoA common pattern is to have a server process running that watches parts of the firebase tree and then runs business logic in response to changes. It's described as client - db - server rather than client - server - db. I believe there are also Firebase queue and task abstractions that make it fairly easy to map a write to a 'backend handler'.
- inlined 10y agoThe rules for the Firebase Database allow read & write access as well as validation. It may not handle every possible case of business logic, but it's a very powerful tool.