MongoFirebase - MongoDB + Firebase security/updates


Table of Contents

General Information

What is MongoFB

MongoFB is a combination of MongoDB and Firebase. You can run your MongoDB anywhere you like, and sign up for your own Firebase account. MongoFB provides an API so you can query, index, and aggregate your data (all the things you wish your firebase could do). MongoFB uses Firebase as its master source of data, so you get built in Security Rules, Authentication, and can listen for updates on any document of any collection, or any field of any document (all the things you wish your mongodb would do).

  • Firebase
    • Security/Authentication
    • WebSockets
  • MongoDB
    • querying
    • indexing
    • aggregation




Sever Configuration

MongoFB can be included in your express or zappajs server, using middleware.

mongofb = require 'mongofb'

app.use mongofb {
  root: '/api/1'      # the root url to host mongofb on
    max: 100          # the max number of results to store in a local LRU cache
    maxAge: 1000*60*5 # the max age of any result in the LRU cache
    url: ''           # the url of your firebase
    secret: ''        # your firebase secret - only needed if your firebase has security rules
    db: 'test'        # the mongodb to connect to
    host: 'localhost' # the host of your mongodb
    pass: ''          # the password to connect with
    port: 27017       # the port to connect to
    user: 'admin'     # the user to connect with
    options: {}       # other connection options [ref](#

Server API


Serves the javascript client


Let's the client look up the public url of your Firebase


The client calls here to get a new ObjectID before writing to Firebase


After an insert, update, or remove, a client will tell the server it needs to
update data in Firebase. The server will then pull the most up-to-date data
directly from Firebase and write it to MongoDB for querying.


Perform a db.collection.find on your MongoDB. Pass your query as query
parameters to this endpoint. The result is returned as an array.

special options
 - limit: limits the number of results in the response


Perform a db.collection.findOne on your MongoDB. Pass your query as query
parameters to this endpoint. The result is returned as an object


Perform a db.collection.findOne by {_id: ObjectID()} on your MongoDB. Pass your
query as query parameters to this endpoint. The result is returned as an object.

This endpoint functions more like a standard resource url as no query parameters
are used.  This method also lets you query for specific fields of a document.

example: /API-ROOT/posts/510b56c221168da296f27bd5/author/name

The above might be a posts collection for my blog. With this I could directly
access the author's name of post 510b56c221168da296f27bd5.

The corresponding Firebase URL for that data would be

Server Hooks

Sometimes you may want to modify the response from your api, or set default values for parameters, or do something special if the user is authenticated. This is all possible with MongoFB Hooks.

You can define your hooks in your server configuration. The current hooks available are...

new_query = collection.before.find(query)

new_doc = collection.after.find(doc)

Example Usage

app.use mongofb {
  firebase: config.firebase
  mongofb: config.mongodb
  root: '/api/1'
        find: (doc) ->
          # hide private user information to other users
          return doc if @user?.auth?.id ==
          {_id: doc._id, public: doc.public}
        find: (query) ->
          # an author changed their name
          if == 'joe'
   = 'joey'

          # if we search for football or baseball, also search all sports
          if query.tag in ['football', 'baseball']
            query.tag = [query.tag, 'sports']

          # force a small limit
          query.limit = 10


authenticate any request by passing a token query parameter with the value being the users' firebase token.

The @user can then be referenced in your hooks

Client SDK

How to use the Javascript SDK




# This is the equivalent to a MongoDB Database

# Connect to our MongoFB server
db = new mongofb.Database 'http://localhost:3000/API-ROOT'

# Get a collection
posts = db.collection 'posts'
posts = db.get 'posts' 

# Get a document directly
post = db.collection('posts').get('510b56c221168da296f27bd5')
post = db.get('posts/510b56c221168da296f27bd5')
post = db.get('posts.510b56c221168da296f27bd5')

# Get a field from a document directly
name = db.get('posts/510b56c221168da296f27bd5/author/name')
name = db.get('')


# This is the equivalent to a MongoDB Collection

# Get a collection
users = db.collection 'users'
users = db.get 'users'

# Insert a document (this method must be asynchronous)
users.insert {foo: 'bar'}, (err, user) ->
  throw err if err
  console.log user.val()

# Run a find query (synchronous)
docs = users.find {foo: 'bar'}

# Run a find query (asynchronous)
users.find {foo: 'bar'}, (err, docs) ->
  throw err if err
  console.log docs

# Run a findById (synchronous)
user = users.findById '510b56c221168da296f27bd5'

# Run a findById (asynchronous)
users.findById '510b56c221168da296f27bd5', (err, user) ->
  throw err if err
  console.log user

# Run a findOne (synchronous)
user = users.findOne {foo: 'bar'}

# Run a findOne (asynchonous)
users.findOne {foo: 'bar'}, (err, user) ->
  throw err if err
  console.log user

# Remove a document (this method must be asynchronous)
# only allowed to remove by id
users.remove '510b56c221168da296f27bd5', (err) ->
  throw err if err


# This is the equivalent of a MongoDB Document
post = posts.findById '510b56c221168da296f27bd5'

# Update a field in a Document
post.get('').set('new author')

# update an entire Document
post.set {author: {name: 'the author'}, content: 'long post'}

# get json for a document

# listeners
post.on 'update', (val) ->
  # called when this document is updated

post.on 'value', (val) ->
  # called immediately, and when the document is updated

post.on 'remove', (val) ->
  # called when the post is removed from the database


# A DocumentRef is a reference to a field of a Document

# Get a ref
ref = post.get('')

# add listeners
ref.on 'update', (val) ->
ref.on 'value', (val) ->

# remove listeners 'update' 'value'

# get the parent ref

# change the value of this property
ref.set('new author')

# get the json value for this ref



express = require 'express'
mongofb = require '../lib/server'

app = express()
app.use mongofb {
    url: ''
    host: 'localhost'
    port: 27017
  root: '/api/v2'
app.get '/', (req, res) ->
  res.send """
      <script type='text/javascript' src=''></script>
      <script type='text/javascript' src=''></script>
      <script type='text/javascript' src='/api/v2/mongofb.js'></script>

app.listen 3000
console.log "listening: 3000"

Javascript Client

window.db = new mongofb.Database 'http://localhost:3000/api/v2'
window.cookies = db.collection 'cookies'

cookies.insert {type: 'chocolate'}, (err, cookie) ->
  throw err if err
  window.cookie = cookie

  cookie.on 'update', (val) ->
    console.log 'cookie updated to', val

  ref = cookie.get 'type'
  ref.on 'update', (val) ->
    console.log 'cookie.type updated to', val

  ref.set 'peanut butter'

iOS Client

Coming Soon!

Android Client

Coming Soon!