What have you used PostgREST for?

Public and private web apps for a French media company. Dumb backend, most of the logic was in the frontend (React) and in async workers (Node.js, with direct access to the database without ORM).

Serious question, if you do most logic in the frontend then where do you do the server side input validation and where do you do the business logic? If I fumble around with your client side code and you don't check that then I could theoretically do whatever I want in your database.

