My main concern is the following :
since meteor is based on JavaScript, it can be changed/tampered @ client side, so what happens if I change or create new collections and start to spam the db will it be only @ client side (memory only) or on both sides i.e: server side too.
is user input is cleaned from xss before the save in the server side ?.