Hacker News new | ask | show | jobs
by e12e 1757 days ago
Am I reading this right? There's no security or granular access control? If you connect a resource, like a postgresql db - anyone with access to the front-end client (anyone with the api key; that is everyone) - can read and write to all tables?

That's... Not great?

https://slashapi.com/docs/pgsql#content-api-endpoints