Hacker News new | ask | show | jobs
by kazagistar 4195 days ago
I think the code runs in both places. In the client, it describes the messages it will send, and in the server, it describes the messages to expect. So the server still verifies that the database requests are only permitted ones.