Electron集成MongoDB Realm时应用ID/API密钥的安全存储问题
关于Electron中Realm应用ID存储的疑问
我正在开发一款基于Electron、Next.js、MongoDB及Realm的应用,查阅MongoDB官方的《使用React快速集成Electron》指南时,发现内容详实,但对其中一处存在疑问。
指南中提供的写入Realm示例代码如下:
const app = new Realm.App({ id: "<Your App ID>" }); // create a new instance of the Realm.App async function run() { // login with an anonymous credential await app.logIn(Realm.Credentials.anonymous()); const DogSchema = { name: "Dog", properties: { _id: 'int', name: "string", age: "int", }, primaryKey: '_id' }; const realm = await Realm.open({ schema: [DogSchema], sync: { user: app.currentUser, partitionValue: "myPartition", }, }); // The myPartition realm is now synced to the device. You can // access it through the `realm` object returned by `Realm.open()` // write to the realm } run().catch(err => { console.error("Failed to open realm:", err) });
代码中直接以明文形式写入Realm应用ID,用于实现Realm写入操作。由于Electron应用的特性,他人可轻易提取该应用ID,进而对Realm进行写入、删除等操作。我疑惑这是官方指南的疏漏,还是需要开发者自行实现应用ID的保密存储?
此外,我想了解:
- 在Electron应用中是否可安全存储应用ID/API密钥?
- 若必须通过第三方API获取密钥才能实现安全存储,是否意味着官方指南存在疏漏?
- 或者明文存储应用ID仍能保证应用安全?
我了解到Firebase与Amplify在Electron环境下也存在类似问题,原以为MongoDB针对Electron的官方指南会提供相应的解决方案。
内容的提问来源于stack exchange,提问作者TheReezen
相关产品推荐
相关产品推荐

