"Session-Security" in R-Shiny and AWS Fargate

Viewed 173

I am currently thinking about the best way to deploy my RShiny app. After trying to host my app on a dedicated server via Shinyproxy, Docker and Nginx - but this solution was (surprise!) not really scalable. The RAM requirement per user was too high for that.

I'm currently considering hosting the app via a Docker image in AWS Fargate, where RAM resources scale up and down as needed.

I'm now wondering about security, though.

Brief background: My goal is to add my app as a tool to an online store. Here it can and will (hopefully) happen that several users will use the tool at the same time. It's important that users can't mess with each other's data - that's why I thought of ShinyProxy, so that each user gets their "own R session".

Now I am wondering what this looks like with AWS Fargate. Could it be that if multiple users are active in the tool at the same time, there can be mutual interference?

If so, does anyone have any ideas on how to prevent this? Unfortunately, publishing ShinyProxy via Fargate is not possible as far as I know.

I hope I could formulate my question understandably and someone of you can help me.

Thank you and have a nice day!

1 Answers

Brief background: My goal is to add my app as a tool to an online store. Here it can and will (hopefully) happen that several users will use the tool at the same time. It's important that users can't mess with each other's data - that's why I thought of ShinyProxy, so that each user gets their "own R session".

Probably depends on what you need for your use case. Shiny actually has no user management per default - in the sense of limiting access to your application for certain groups and requiring authentication (can be done by hosting with Shinyapps.io and others).

But you probably do not really need this anyway - your problem sounds more like a scoping issue. (you should read this information about it)

Sure, there might only be one R process, but it actually supports multiple client connections (sessions). You can define, what objects these sessions share. This is totally independent from where you host your app.

Everything you put into the shinyServer() function in the server.R file will only be visible within the user session. (every user has it's own session)

If you need to share variables between sessions, you have to put them in the server.R file, but outside of the shinyServer() function.

Related