4 ms·
The hype is the real issue. Even today, the CTO appears to claim that 90% of apps aren't relational enough to need Mongo. I did a startup in 2011/2012 where we
by STRML 9y ago
The hype is the real issue. Even today, the CTO appears to claim that 90% of apps aren't relational enough to need Mongo.
I did a startup in 2011/2012 where we bought into the hype and used MongoDB & Node + Mongoose. It was horrific.
Your app is relational, full stop. You would know if it wasn't. Do you have users? Do those users need to log in? Well, you now have access tokens related to users. Do those users need to create anything at all? You've now related those owned objects back to the user. We're talking the very basics of any application, and Mongo's support for it is basically nil.
We went down the road of embedding relations inside the model (e.g. an "user" has multiple "tickets" to "events"), and then we'd just filter through the "events" table to find the related one. But what if the admin running the event wants a list of all the tickets for his event? We're talking webapp 101 stuff, but we had to write some really gnarly application logic and duplicate a bunch of data to make it fast.
It was a complete waste of time.
At the crux of this is a fallacy that easier is always better. It's not. There is a reason SQL databases are a little complicated to use - they have evolved over many decades to fit the needs of real applications. MongoDB is only barely removed from writing raw JSON arrays to disk, which is probably the simplest "database" imaginable.
When you so callously discard the common wisdom on how to store data, you rediscover why it exists, the slow, hard way.
10gen made a business - and a fortune - out of misleading new developers.
- 43224gg252 9y ago>Do you have users? Do those users need to log in? Well, you now have access tokens related to users. Aren't those tokens supposed to be stored client side anyway? Aren't those tokens supposed to contain encoded information about the user that you decode server side? Why would you store the users token to begin with?
- STRML 9y agoThat's a matter of opinion and implementation. Not everyone uses JWTs. What if you want to invalidate all logged-in tokens for a user? You either need to store a blacklist (that's a relation) or set extremely short expiry times.
- ZephyrP 9y agoi think he is discussing standard cookie session ids here, not access tokens. in many web applications, all the information you need is stored within that token and signed by a server-side secret.
- pritambaral 9y agoSame thing. How do you invalidate a signed cookie?