As a newcomer to the meteor, I found that insecurity is one of the first impressions that people usually experience because of the meteorโs historical debut, and that the meteor took measurements to solve this problem. Therefore, I pay more attention to this issue, as I study it. Following the to-do list tutorial, I noticed, to my surprise, the if (Meteor.isServer) {} block is displayed in the browser. The tutorial outlines 2 out of 12 steps to move client code to the server side to make it secure. But if the server code is also displayed in the browser, didn't that defeat the whole goal? How can a meteor be a safe platform in this regard?
source share