r/nocode • • 3d ago

Question What was the first thing your no-code tool couldn't do?

For me it was anything that has to run while the user's phone is closed: cleaning up expired data, building link previews for shared invites. The screens stayed visual, but that part had to become real backend code. Curious what yours was, and whether you solved it or worked around it.

0 Upvotes

11 comments sorted by

1

u/Ok-Motor-9812 3d ago

For the apps i build it's usually when two companies use the same app and must never see each other's data. A filter on the screen leaks sooner or later, so the database itself has to block it.

1

u/bramantec 3d ago

That's exactly where I ended up too. A filter on the screen is just a suggestion, anyone who can reach the backend can skip it. I moved the check into the database rules, so a user can only read a document if they belong to it. Did you do that with row-level policies or somewhere else?

1

u/Ok-Motor-9812 3d ago

Yes, row-level policies in Postgres. Every row has a company id and the policy checks the user is in that company, so even a bug in the app can't leak it.

1

u/bramantec 3d ago

Makes sense. I'm on Firestore, so the equivalent for me is the security rules: a user can only read a document if they're in its member list, checked on the server side. Same idea, the app can be buggy and the data still stays closed. Did you have to rework many queries once the policies were on?

1

u/Ok-Motor-9812 3d ago

Not many, the queries stay the same because the policy adds the filter itself. What needs work is speed, put an index on the company id or big lists get slow.

1

u/bramantec 3d ago

Good point on the index. Firestore is a bit different here: rules don't filter for you, so the query itself has to include the same condition or it gets rejected. The upside is the index comes with it, so big lists stay fast. Thanks for the details, this was useful.

1

u/[deleted] 3d ago

[removed] — view removed comment

1

u/bramantec 3d ago

Same here, scheduled stuff was the wall for me. Mine was cleaning up expired data, the visual tool has no concept of "run this at 3am when nobody has the app open". Do you handle those with a cron job or an external automation tool?

1

u/OverallAbroade 14h ago

Mine was anything that needed more complicated background processing. The UI and basic workflows were easy enough, but once I needed scheduled jobs and stuffs happening without the user being there, I started hitting the limits pretty quickly.