Comment by supriyo-biswas
Comment by supriyo-biswas a year ago
The fact that clients write directly into the database and that it's widely encouraged.
There are security rules in Firebase to prevent this, but bolt-on security models that the user has to explicitly enable haven't shown to work.