- Make sure server does not allow remodIds from outside the userId given from auth. - Just add a server test for this