4 ms·
I think my main problem with PouchDB and by extension CouchDB was that it seemed hard to add validation in the backend (including authentication/authorization).
by renke1 5y ago
I think my main problem with PouchDB and by extension CouchDB was that it seemed hard to add validation in the backend (including authentication/authorization). I remember having to build some kind of proxy that hooks into the CouchDB protocol to deny certain requests. I am pretty sure that's solved by now (or I was just asking the wrong questions back then).
- patwolf 5y agoThat was a problem I always had with replicating directly to CouchDB. They have added more authentication methods now, like proxy auth and JWT, so authorizing on a per-database basis isn't too bad. However, I gave up on CouchDB after my server kept getting hacked by crypto miners. I'm sure whatever exploit they were using has been patched, but I'm hesitant now to use a DB that's open to the world.
- lytefm 5y agoIf your CouchDB was open to the world, then that's definitely a configuration problem. Sure, earlier versions shipped with "admin party" enabled by default but the docs made it very clear to not do that in public.
- lytefm 5y agoIt's possible to use the same design docs both for client- and serverside validation. They don't look pretty, but maintaining them in readable JS and deploying them via CI works fine. Apart from Proxy Auth and JWT, just using basic Auth/session + a backend like Superlogin works for simple use cases. But sure, you'll want to set up rate limits etc using something like HaProxy once you have actual customer data on a CouchDB instance.