Use a product like Convex that has authorization in functions that run server side. That why you don't get firepwn:
From my teammate @codingwithjamal.bsky.social:
stack.convex.dev/authenticati...
1 year ago
1
1
0
0