@Teodor I checked the source on some showcases, and my own app and found that all the server connect components with their URL & GET parameters are exposed in the source. Isn't that something to be concerned about?
Applying server side security as given in below tutorial does help, but is that enough?