19 ms·
Show HN: Orange Forum – Web 1.0 style forum written in Go
- sturmen 9y agoI appreciate the philosophy. Is there a live demo so we can try it out? edit: I turned on my brain and found the link was on the homepage the whole time.
- deafcalculus 9y agoYes - https://groups.goodoldweb.com/ https://groups.goodoldweb.com/
- noughth 9y agoYup, the site links to a hosted version here: https://groups.goodoldweb.com/ https://groups.goodoldweb.com/
- bovermyer 9y agoThat's a very concise privacy policy, heh.
- binaryapparatus 9y agoWorks beautifully with w3m which has become my main site test lately. Another great example is HN itself. If it doesn't work well with w3m something is wrong with the site philosophy or execution.
- weberc2 9y ago> If it doesn't work well with w3m something is wrong with the site philosophy or execution. Point of clarification: "wrong" according to your moral philosophy about web sites, even if it's one I happen to share.
- xyzzy_plugh 9y agoWhat's the other sort of wrong?
- wastedhours 9y agoBeing objectively wrong. Philosophically wrong is using technology that limits the web from being what the interpreter expected, as in this example (there's still a rational reason in this case to do it the "wrong" way and it's based on personal morality). Objectively wrong being trying to make a website out of custard.
- sitkack 9y agoHow about doesn't crash an Ipad 1?
- z3t4 9y agoHow can a few lines of text load so fast !? Are we so far into the Obesity Crisis that people find this impressive ? :P
- nategri 9y agoAny support for images?
- deafcalculus 9y agoImages are supported, but it's disabled in the live demo.
- protomyth 9y agoGood plan for your own sanity. Is there a way to disable the signup and just load users?
- deafcalculus 9y agoSignup can be disabled. Loading users will need some SQL.
- protomyth 9y agoThanks, SQL doesn't bother me much - I just was looking at it for suitability for a student forum.
- scrumper 9y agoThe live demo is already full of trolling sigh. So yep, it's a forum. Nice and fast though. Good work.
- arunc 9y agoInteresting.. Looks sleek.. DLang forum [1] is similarly lightweight and it runs as a newsgroup, IIRC. Source code at [2] and previous discussions on HN [3] [1] http://forum.dlang.org/ http://forum.dlang.org/ [2] https://github.com/CyberShadow/DFeed https://github.com/CyberShadow/DFeed [3] https://news.ycombinator.com/item?id=3592769 https://news.ycombinator.com/item?id=3592769
- bligh____ 9y agoD is smart hipster tech not quite the Normie hipster tech go has become, so dlang will not spread good in the Normie masses.
- patates 9y agoAlso is nim forum: https://forum.nim-lang.org/ https://forum.nim-lang.org/ (Source: https://github.com/nim-lang/nimforum https://github.com/nim-lang/nimforum )
- golangnews 9y agoSee also https://golangnews.com https://golangnews.com - an HN inspired forum written in Go and hosted on a $5 instance, holds up pretty well.
- ytjohn 9y agoWow, thanks for the link to DFeed. That seems like a route I might want to pursue for a community forum I'm planning.
- devmunchies 9y agoin the demo when a response is massive it takes a long time to load. example: https://groups.goodoldweb.com/topics?id=33 https://groups.goodoldweb.com/topics?id=33 It needs to limit entries to a certain number of characters where you can click a "see all" button to see the rest of the long entry.
- deafcalculus 9y agoI missed limiting the size of user inputs. Will fix it soon.
- baby 9y agoI'd recommend you to use Argon2 instead of bcrypt for storing password. It has won the Password Hashing Competition last year and is the recommended way to store passwords. Bcrypt is not bad but it could be used with insecure parameters while Argon2 does not have insecure parameters. The way you create cookies is also insecure, you should be using crypto/rand instead of math/rand AND rather hex.EncodeToString() the result instead of just generating random numbers in the alphanumeric range.
- deafcalculus 9y agoThanks! Will fix right away.
- tptacek 9y agoThe math/random point is well taken. The hex.EncodeToString() point is a nit. Generate 128 bits of randomness, and then encode it however you'd like. The track record of people trying to get "generate random numbers in the alphanumeric range" isn't great; it's an opportunity to reintroduce bias. Start with a random token of sufficient size, then encode. The Argon2 vs. bcrypt thing is unhelpful. It does not matter what password hash you use, so long as you use a hash designed for password storage (ie: not "salted SHA-2"). Bcrypt is fine. I prefer scrypt, for the obvious hardware tradeoff. I don't recommend Argon2 to people (or tell people to stop using it) because of the library support issues. But I think it's specifically a bad idea to tell people to switch password hashes from bcrypt (or PBKDF2) to the trendy new hash. The security benefit of "upgrading" from one password hash to another is marginal. (Obviously, the benefit of switching from "salted" hashes to real password hashes is not).
- ktta 9y agoWhere do you think Argon2 should be present before it is considered to have good library support? AFAIK, it is in libsodium, debian, ubuntu, and other distros. And I think one can also make mistakes with scrypt when choosing parameters which Colin himself acknowledged. So isn't it time to go ahead with Argon2?
- 9y ago
- maxpert 9y agoLikes on bringing such a retro concept back; but seems like you don't have any kind of spam control :D would be nice to have one.
- jksmith 9y agoHell yeah golang templates rock!
- throw2016 9y agoThe old style forums are showing their age and need to be modernized but not abandoned. See the Archlinux forums based on Fluxbb. It's fast and effective. The newer ones led by Discourse, Nodebb and Flarum have completely gone in another direction in reinventing how discussion forums should be and perhaps gone too far. They feel strangely 'rootless' and completely lack the 'community feel' of user forums. This looks promising for something fast, lightweight and easy to deploy.
- JoshMnem 9y agoThe UIs on those three should be dialed back (animation, JS), but Discourse is pretty good otherwise. I've looked at all three: * Flarum had nausea-inducing animation, and now it overrides natural scroll behavior. (Please never do that to users.) * NodeBB had some problems when I was using it. If JS is disabled, even the homepage links don't work. Forums should be server-rendered. * Discourse could be improved by removing most of the animation and Material Design creep (bad for motion accessibility), but other than that, it's the best at the moment. It would also be nice to have easier, full theme customization. Maybe it's in there somewhere, but I haven't found it yet. I would like to see forum software that has the feel of classic forum software (like Flux), not in PHP, that is server-rendered, with a very minimal default theme (no animation) and minimal JavaScript, and that has many of the modern features of Discourse.
- jayroh 9y agoI guess this is as good a time as any to mention that something like that exists (and to toot our team's work over the years): I started the project years ago and in the last few have gotten really great support from glebm and some others to get it to the point where it's a really lovely, stable, and fast piece of work. We consider it the best Ruby/Rails-based alternative to Discourse out there (as an aside - wewere honored that Ryan Bigg would point people our way when he stopped maintaining Forem[1]) You said: √ I would like to see forum software that has the feel of classic forum software (like Flux) √ not in PHP √ that is server-rendered √ with a very minimal default theme (no animation) √ and minimal JavaScript √ and that has many of the modern features of Discourse. I think those check out. In any case I suggest you check out the website[2], the repo[3], and the demo[4]. [1]: https://github.com/rubysherpas/forem#no-longer-maintained https://github.com/rubysherpas/forem#no-longer-maintained [2]: https://thredded.org https://thredded.org [3]: https://github.com/thredded/thredded https://github.com/thredded/thredded [4]: https://thredded.org/thredded/ https://thredded.org/thredded/
- swlkr 9y agoI love this, this is how I've been writing my latest projects, with very little js and it's been a huge productivity booster.
- Aardwolf 9y agoSo much whitespace in the demo. Real web 1.0 forums can fit way more thread titles on screen ;)
- czep 9y ago> So much whitespace in the demo. This. If you want old school, go with 10px Verdana, and pad sparingly. I want information, not negative space dammit! With pine, my email editor in 1995, I could read 40 subject lines on a 640x480 screen. With Gmail (in compact mode) on an MBP retina, I get 36. Progress, indeed. Designers 1, Users 0.
- HumanDrivenDev 9y agoThe amount of padding in modern websites drives up the wall. The idea that I bought a 24" monitor just so I can read text in fullscreen is ridiculous. One trick I often use is to have the window take half (or less) of the screen and spoof my browser to be Chrome on Android Kit Kat. I just wish there was a change to have a different browser spoofed per tab, or maybe a "whitelist" of websites that are designed well enough that I won't pretend I'm on a phone.
- sitkack 9y agoAdded your ideas to my notes file.
- wybiral 9y agoNot enough background textures or tables with 3d borders either.
- sitkack 9y agoI believe you are looking for these http://www.ibiblio.org/java/formatter/javadocs/images/ http://www.ibiblio.org/java/formatter/javadocs/images/
- deafcalculus 9y ago
- mseebach 9y agoOk, sorry, bitter old man coming through: this is Web 2.0, not 1.0. For all the buzzwords, Web 2.0 was defined by the dynamic interactive solicitation of user input as opposed to Web 1.0 being just static HTML. I don't think we've coined a good catchphrase for fat applications implemented in tons of Javascript with only lightweight AJAX calls to the backend. And then, of course, there's Web 0.1: https://thedailywtf.com/articles/Web_0_0x2e_1 https://thedailywtf.com/articles/Web_0_0x2e_1
- aaron-lebo 9y ago"Web 2.0" came around about 2004ish with Digg and other sites using AJAX. Or at least static content was not the defining factor. There were plenty of forums around in the late 90s with dynamic content.
- mseebach 9y agoWikipedia disagrees. https://en.m.wikipedia.org/wiki/Web_2.0 https://en.m.wikipedia.org/wiki/Web_2.0
- aaron-lebo 9y agoYeah I was looking at that too. The definition is kind of nonsensical. Slashdot met that definition in 1997 but nobody was calling it that at the time. Web 2.0 became a very popular buzzword with Digg, Flickr etc. Or at least that's how I remember it, the author is not "wrong" for referring to it by a very popular definition. Also see: http://www.paulgraham.com/web20.html http://www.paulgraham.com/web20.html I think everyone would agree that democracy and Ajax are elements of "Web 2.0."
- mseebach 9y agoWhat's nonsensical about it? Slashdot was very avant-garde, so fits well for a term coined in 1999. I agree that AJAX represented somewhat of a technological watershed, but wikis and blogs (which came of age pre-AJAX) represented a social watershed, a much better anchor for the democracy that PG seems to consider only from a technical perspective.
- coconutoctopus 9y agoas a junior dev, i aspire to do something like this one day. how would i go about achieving this? my knowledge is mostly in asp.net and javascript.
- Eyas 9y agoLooks like you'll need to start moderating this already, as of an hour ago, at least. The process of setting up a public sandbox for users to play with seems like it should be easy, but abusive/obscene posts by users make a testing sandbox unusable/NSFW very easily.
- always_good 9y agoI built a forum from scratch once and it is a comical amount of work. The initial CRUD weekend-ware is straight forward. LIMIT/OFFSET for pagination. Throw in some Markdown support. Seems easy enough. But the devil is in all the individual features that make a forum usable. Like getting notified when someone @mentions or replies to you, marking threads that you've posted in, tracking the high watermark per user per thread so you can create a "go to first unread post", implementing a decent search, making deep pagination fast, a PM system, trying to generalize it. A serious amount of breadth between weekend #1 and production if your users want the feature set of Xenforo. The main positive I can say is that my forum is cheap to host.
- KajMagnus 9y agoI've had certain forum software sometimes as a side project, sometimes as my man full time project, during the last 7 years. So yes there's lots of work. But in my case lots of time was "lost", in learning web development / React.js / Angular / Dart / other stuff, and porting from the-wrong-technology, to another the-wrong-technology, and building the wrong things that no one wanted. I think the Discourse (forum software) team were a few people, like, 3? and they spent some year(s) developing the initial version of Discourse. So ... yes some weeks/weekend? for the initial version, and ... >= 3 years ? for a "real" version :- P Is your software anywhere online, e.g. GitHub?
- hasenj 9y agoI think the lesson here is to stay away from frameworks as much as possible.
- KajMagnus 9y agoIt was other things than frameworks too — also databases, and (to some degree) programming languages. For example, I started with using only file based storage. Then I switched to Oracle — because I needed to learn Oracle better, beause of some contracting work I did, and then from Oracle to PostgreSQL. & I tested Dart (a programming language) too (and Angular-Dart). Actually now in the end, I've found some frameworks that I like (love?) and ... without them, I'm afraid everything would instead have beeen a terrible mess. These frameworks help me structure the code and reduce my total amount of code: React.js, and Play Framework, and Nginx + some Lua (instead of doing everything in the app server). My personal lesson is ... Do use frameworks but not the wrong ones :-) and it can take long to undo a use-the-wrong-stuff decision.
- meehow 9y agoI think you guys are awesome. Keep up good work. Battery, CPU and RAM of my laptop are having the same feeling. Can I deploy it as fcgi script on cheap shared Apache hosting?
- deafcalculus 9y agoThanks! FastCGI is currently not supported. If your shared hosting allows you to run a binary that accepts connections on some port, it should work with Apache as a reverse proxy. I'll add fast cgi soon. It should be easy enough since golang's net/http supports it.
- emrekzd 9y agoThe term "Web 2.0" is an unfortunate choice and as a consequence it has been rarely used correctly. Funny enough I've been to a Web 2.0 Conference about 10 years ago where almost every speaker used it incorrectly. Web 2.0 has nothing to do with a technical revision or change in the Web. It was used by Tim O'Reilly back in 2004 (and became popular) and refers to the rapid change in the way the web is used, more specifically the switch from static web to user generated content. I'm sorry but your forum is all about UGC, and AJAX has nothing to do with Web 2.0.
- Xeoncross 9y agoFive years ago I wrote a 5KB PHP forum system I called https://github.com/Xeoncross/forumfive https://github.com/Xeoncross/forumfive It relied on BrowserID though so it's no longer working and I was thinking about re-doing it using Go so I'll look at this.
- dzonga 9y agothe live demo could hardly render well on my browser.
- shpx 9y agoHere's one written in lisp ;) https://github.com/arclanguage/anarki/blob/master/lib/news.arc https://github.com/arclanguage/anarki/blob/master/lib/news.a...
- candiodari 9y agoThe irony is that because of the lean structure behind the server, this forum actually responds faster than most webfora that do use AJAX/SPA. Funny given that the whole purpose of AJAX/SPA was to reduce response time. That's it's reason for existing. Turns out it just complicates things ...
- hasenj 9y agoWhen you say "irony", are you genuinely surprised by this?
- flukus 9y agoNo, but I've seen comments on here from people under the impression that rendering on the client is a more efficient use of CPU, or that rendering a page in HTML is significantly more resource intensive than rendering the data in json. There is a generation out there that doesn't seem to know that server side rendering exists.
- laumars 9y agoThe benefits from client side Vs server side are really a matter of scale. If you're running a personal forum / whatever then you're not going to notice a whole lot. But when you start having several hundred thousand or more concurrent users then being able to cache your pages in a CDN and only generating JSON responses via APIs really can have a profound impact on your server side resources.
- techdragon 9y agoYou can cache server rendered pages in a CDN or Varnish or whatever you like, and there's also the use of the proper http headers to drive client side cache control. All of this works for server side rendered content.
- laumars 9y agoObviously there are a great many layers to caching (there's a whole multitude of other solutions out there that you've also missed off :p). However with regards to the specific points you've raised: 1) You cannot cache server rendered pages in a CDN (see footnote) if those pages contain user specific information (like this topic does). Information such as a user name, message read status - even on public messages, etc. If you do CDN cache those pages you'll leak user-specific information to other users. This is why you need tools like Varnish that cache page fragments rather than whole pages; or why you serve up HTML templates and then populate user information on the client side via RESTful API calls. 2) For similar reasons as above and again very relevant to the project in this discussion, HTTP Cache-Control headers also wouldn't help with the HTML if your backend is generating the HTML. In fact in those instances you'd probably want to set your max-age to 0 (again, speaking strictly about dynamically generated HTML. Static assets like JS, CSS, and images are a different matter but they're not server generated dynamic content). Granted with browser caching there isn't the risk of leaking user information to other users; the risk is just the browser not fetching an updated forum view / whatever. Caching is one of those things that are easy to set up but also very easy to get wrong. Footnote: Akamai might support it - if you're willing to pay their premium - as it's an immensely sophisticated product. However it's not an option I've seen when using Akamai and the other solutions I've used definitely don't support caching page fragments.
- pcunite 9y agoThis post is hilarious! https://groups.goodoldweb.com/topics?id=67 https://groups.goodoldweb.com/topics?id=67
- KajMagnus 9y agoCan I ask what (if any) are your future plans with this? And what's the reason you decided to create it? (only to showcase web 1.0 style forums, or ... other reasons too?) For example are you planning to provide hosting? Continue developing the open source version and add features like spam protection? Google and FB login?
- deafcalculus 9y agoI'd been working on this on-again off-again for a while after reading Dan Luu's post on page bloat[1]. I'll provide hosting if anyone wants it. That said, ease of deployment was a major consideration right from the start. That's why I chose golang over Django/Rails and decided to offer SQLite as an option to support quick deployment for internal / low traffic sites. [1] https://danluu.com/web-bloat/ https://danluu.com/web-bloat/
- KajMagnus 9y agoOk thanks for explaining :-) (I've seen Dan's post me too in the past, it inspired me to try to remove lots of JS from some similar stuff I'm building.)
- hasenj 9y agoThis is cool. I've been thinking about this for a while. The best way to write high quality web applications is to use compiled languages and minimize the complexity of the infrastructure by using e.g. SQLite instead of PostgreSQL. I hope this trend starts to pick up more steam and become the sane default that everyone just assumes. Instead of the current mess where everyone assumes that it's "normal" to live in this messy world of countless abstractions and frameworks and micro servers, etc.
- iamd3vil 9y agoSQLite is ok if you don't have much traffic (for example personal blogs), but you can't replace a db like Postgresql with SQLite if you have lot of concurrent traffic.
- hasenj 9y ago99% of the internet can use SQLite. Not just "personal blogs". Just about anything that's not facebook/twitter/google. I think you underestimate how much load it can handle.
- muxator 9y agoSupposing that your server-side tech uses multiple workers to render pages, I suppose you have to serialize the access to the SQLite file. What is the best way to do this?
- deafcalculus 9y agoSQLite can handle concurrent reads, but needs to lock the entire DB when writing. Multiple workers shouldn't be a problem per se, but if you need multiple workers to support the traffic, then maybe a client-server db like postgres is a better choice.
- hasenj 9y agoWriting does not lock readers if you use the WAL feature (Write-Ahead Log, introduced in 2010) https://sqlite.org/wal.html https://sqlite.org/wal.html > WAL provides more concurrency as readers do not block writers and a writer does not block readers. Reading and writing can proceed concurrently.
- kgthegreat 9y agoTake a look at https://hashnode.com https://hashnode.com if you want to see fast MERN[1] stack forum [1] https://hashnode.com/post/hashnode-looks-pretty-amazing-its-very-fast-smooth-and-looks-client-heavy-i-am-curious-about-the-stack-used-in-hashnode-ciij5a1k101mplc536dav792z#ciijdrq8w01uxlc53ci1jvn5j https://hashnode.com/post/hashnode-looks-pretty-amazing-its-...
- foxhop 9y agoI really like this movement of going back to the basics, web 1.0 style web apps/sites. I do feel however that there can be a compromise, I think we can build our web applications in the 1.0 style and power them up in the 2.0 style, allowing the capability of the client drive the presentation of the application. For hints on how I'm doing this for Remarkbox (https://www.remarkbox.com https://www.remarkbox.com) - please read http://russell.ballestrini.net/capability-driven-presentation/ http://russell.ballestrini.net/capability-driven-presentatio...
- vog 9y agoThis is a nice goal, especially if you need portability all the way down (... to IE 5.5 or something). However, for any larger web application, this increases the testing effort dramatically, as you need to test all possible sets of capabilities (i.e. all kinds and versions of browsers and other clients). This becomes quickly unbearable burden, unless all functionality is 100% provided and battle-tested by the framework.
- woodrowbarlow 9y agothe term for this is "progressive enhancement".
- foxhop 9y agoI think the term is still being decided, I referenced where I learned the terms here: https://resilientwebdesign.com/ https://resilientwebdesign.com/
- reacharavindh 9y agoI looked into your work - remarkbox and read through all the while hoping/wishing for there would be a self-hosted version that is not prohibitively expensive for a free personal blog. No luck for me. Back to tinkering with self-hosted isso[1] comment system to make it work for me. https://posativ.org/isso/ https://posativ.org/isso/
- foxhop 9y ago
- lecarore 9y agoResetting the form if there's any error in the input is not the nicest UX. Like special characters in the name of a group