Are there any resources or community posts that explain how retool works and what code / queries are exposed to users? I'm trying to get a handle on what security consideration I should take into account when building an app.
For example can an app user modify a sql query to change the input parameters or raw query?
In essence I'm looking for a high level understanding of what runs backend or in the browser and
Hi @DavidS Thanks for sharing the links you found!
For security purposes, I'd also recommend ensuring that you are using prepared statements (also linked in the Preventing query spoofing doc). This is on by default, and only admins can turn off prepared statements from the resource page.
More generally for public apps, publicly shared apps allow for unauthenticated, open access to the embedded app. If you need to give users access to confidential information or dangerous functionality, they would have to login with a Retool account.