3 ms·
For basic tasks, I'd also advocate for using the Go standard library. But for any non-trivial project you need to use some library, at least Gorilla toolkit. Im
by terminalcommand 8y ago
For basic tasks, I'd also advocate for using the Go standard library. But for any non-trivial project you need to use some library, at least Gorilla toolkit. Implementing everything by yourself would take ages.
I think if you're used to a framework, you don't need to reinvent the wheel by sticking to the Go standard library. Know that the Go standard library exists and how it works but use frameworks for productivity.
In Goland, you jump to definitions and see things for yourself anyway. Even while using the standard library you generally read most of the code to be able to understand it. A framework would be no different, you'll read parts of its code rather than just passively looking at the documentation. Idiomatic Go encourages you to engage with the code, rather than just consume it.
There are many frameworks out there that leverage Go's advantages (simple code, single binary, fast, very little RAM usage) while maintaining a higher level programming interface. I'd encourage you to try some of these frameworks.
Examples that come to mind are:
Gobufallo [https://gobuffalo.io/en https://gobuffalo.io/en]
Revel [https://revel.github.io/ https://revel.github.io/]
Iris [https://iris-go.com/ https://iris-go.com/]
To learn the basics of security handling in Golang, you could learn the basic web security concepts from OWASP Top 10 lists and other sources. The things you'll need to work at are mostly: preventing SQL Injection (the standard db driver does a good job in parameter substitution), implementing CSRF protection, Securely Generating And Storing Sessions (Gorilla toolkit will help here), and securing your databases (especially passwords) by only storing passwords hashed and salted.
As Django is a full-fledged very high level framework, you might find it easier to look up on some Flask documentation to see how barebone web programming works. Golang + gorilla toolkit gets you on a microframework level (like Flask).
The other frameworks I mentioned Gobufallo, revel etc. will provide you with a more familiar environment, as they come with code generators and templates.
When it comes to best practices, I'd advise to learn more about idiomatic Go programming and learn about some fundamental web security topics.
I remember that I was also very scared that if I attempt to code any site by hand I'd leave a lot of security holes behind. But the truth is, most of the security flaws stem from complexity. If you know the basics such as sql injection, safe encryption algorithms etc. and keep your code clean, there is no need to be scared.
On a side note: if you had the patience of being able to get through the steep learning curve of django, you won't have a hard time doing things the old fashioned way by using httplisteners and httpwriters. IMO people tend to stick with microframeworks and CGI because they are simple.
- sharmi 8y agoThanks for the input terminalcommand. Lots of interesting pointers. Which framework do you use?
- terminalcommand 8y agoThe only serious web application I've written (a social blogging application) was written in Flask. I was relatively new to web programming and taught myself everything from using template engines to SQL to server management. That's when most of the web programming concepts clicked with me. I've attempted to use Django on multiple occasions but was put off by the sheer magic it entailed. (This was me before I singlehandedly coded a social media application and saw first hand how a project could consume all your mental resources. I made the mistake of jumping into things yelling "fail early fail fast" back then) Currently I'm back on working on personal projects. Nowadays I mostly write networking applications in Go, I've recently been writing an irc library. I learned a lot about parsing, networking protocols etc. As for Go web frameworks, I've been meaning to test these frameworks for a long time, if I were to start a project now, I'd go with gobufallo. When I had done my research on it (August 2017), it seemed to have excellent documentation and tooling.