4 ms·
That's what this article is arguing against. The "good practice" is more precedent than anything. Sure, we can argue that it "adds security" to the mix by addin
by AgentK20 10y ago
That's what this article is arguing against. The "good practice" is more precedent than anything. Sure, we can argue that it "adds security" to the mix by adding a separate layer between the user and the actual place where billing info and passwords are stored, but if that front layer gets breached then you're still screwed. From what I understand, the article suggests the reverse of what you're saying. Not necessarily moving the business logic _into SQL_, but what if the DB actually had a very extensible framework and libraries that let you serve HTTP _directly_ from the DB? How would that change reactive websites whose sole "backend" is a SQL<->JSON+Permissions system? What about if the DB itself supported a psuedo-PHP runtime, or better yet closer to native code?
Granted, I'm not saying it's a good idea. I do see a vast array of benefits, primarily in the sense of scalability, from separating the business logic from the DB, but it's an interesting topic to ponder nonetheless.
- vog 10y ago> What about if the DB itself supported a psuedo-PHP runtime, or better yet closer to native code? Note that in PostgreSQL, user defined functions can be written in many languages, including SQL but also Python (very well supported) and PHP (not so well supported, but doable).
- josephg 10y agoPost author here. I actually think it would be much cleaner to support an event log API and run this stuff out-of-process. My database shouldn't have to support the language-de-jour, and I don't want my react rendering process slowing down my database servers. You can totally decouple this stuff with a clean kafka-like eventlog API, but postgres doesn't provide one.
- agentultra 10y agoYes it does. There many ways you can do it too. See the docs for NOTIFY/LISTEN for an easy built in solution. Use a trigger to write to a log table for durability. And the time travel functions. All with the powerful query engine. There are projects to stream all operations straight into Kafka. The nice thing about Postgres is that it's also extensible. PipelineDB, Citus, etc.