3 ms·
Exact same thing that we are using for a realtime collaborative app. Generate token on server-side with access to certain keys. However, we had to redo our jso
by anshum4n 10y ago
Exact same thing that we are using for a realtime collaborative app. Generate token on server-side with access to certain keys.
However, we had to redo our json structure once we started thinking authorisation. It sucked and in retrospect should have thought about it earlier, but it seems to work.
Typically authorisation layers on top of existing data, but in this case, we had to redo data structure keeping auth in mind. Is that why you feel its brittle?
- girvo 10y ago> Typically authorisation layers on top of existing data, but in this case, we had to redo data structure keeping auth in mind. Is that why you feel its brittle? That's pretty much exactly it, I guess. It honestly just feels less "secure" than I'd like, even if it's not!