7 ms·
Rails 6: B-Sides and Rarities
- stevenpetryk 7y agoI still see Rails as perhaps one of the best frameworks to start a new generic web project in. The out-of-the-box functionality is just so perfectly tuned, and the fact that they're focusing on features that appeal to larger applications just shows how Rails has helped companies grow.
- ksec 7y agoAny Reason why Rails still does not include an any decent Auth by default? Edit: I remembering keep asking this question but obviously no answer was satisfactory enough that stick to my brain.
- hit8run 7y agoI think the defacto standard is devise but they want you to be flexible enough to roll your own or whatever serves you. I would like to have it built in though.
- petepete 7y agoThis sounds about right. And if you want something in between without rolling your own, Sorcery is excellent. https://github.com/Sorcery/sorcery https://github.com/Sorcery/sorcery
- jjgreen 7y agoLooks interesting, thanks
- ken 7y agoI'm not familiar with recent versions of Rails or its authentication situation, but whenever I hear this said about some mandatory functionality of a system, it sounds to me exactly like "We haven't yet figured out how to do ___ well". It reminds me of the old days when I'd get a library which would say "We want to be flexible, so just pass in any memory allocation function here!", or Linux distros that said "We want to be flexible, so just write any boot script here!" Then a year later, some competitor ships with a default, and everybody switches over to that because it's obviously better (and you can always customize it if you need to). Especially so with Rails, whose entire existence seems to be picking good-enough defaults.
- mplewis 7y agoThere are many ways to do auth. Some Rails auth gems are more prescriptive than others. All of them involve large tradeoffs in various directions. It would be weird to bless just one of them as the "right" way to do auth in Rails, imo.
- aaronbrethorst 7y agohas_secure_password is built in, and works as long as you include the bcrypt gem in your Gemfile. I've never found Devise or any other 'off the shelf' solution to be satisfying for me because authentication seems to vary just enough between projects to make it easier to use has_secure_password and rewrite auth from scratch. Personally, I think it would be cool if someone built an user account/authentication experience as a generator (along the lines of Rails scaffolds), so that you could see all of the generated code and modify it without having to get elbow-deep into the bowels of what I find to be an overly-abstract gem.
- ravenstine 7y agoThat's been my experience with Devise and similar libraries for other frameworks and languages. If it fulfills all needs for a project, that's great, but I tend to find that it's simpler just to build authentication around authentication "primitives" like has_secure_password. The thing I do like about Devise is that it has views for everything including password reset out of the box. The abstractions it provides end up being more of a headache than they are worth. To be honest, I'd rather see more gems for these sorts of purposes that are just a collection of off-the-shelf views that can be easily tied in to one's authentication solution of choice. By installing Devise, you bring all of the extra non-view baggage it comes with into the application's memory space even if you don't use it. Yuck. (no offense!) Actually, I just reread your comment and I think your scaffold/generator approach is also a nice way to go. It's just too bad that there hasn't been as much development effort towards these sorts of things recently in the Ruby community. I'd build it, but have gotten away from Ruby because the community is obsessed with applying object-orientation to every problem, over-abstracting, metaprogramming, etc.
- owens99 7y agoHave you tried Devise? It’s not default but it’s one of the best Auth tools I’ve seen in any stack. I love it and use it in tons of apps.
- brightball 7y agoBecause every application doesn't need it and it's virtually effortless to add Devise, which is the defacto standard at this point.
- intelliderp 7y agoAuthentication is currently a tire fire all across the web, regardless of framework. It's not unheard of for login issues to consume the efforts of a full-time senior dev on a team. Not including RESTful APIs, the "best practice" for auth has shifted rapidly in the past 10 years from OAuth2 to OpenID to JWT... these frameworks take considerable effort to learn, add to that the fact that the major identity providers (FB, Google, etc.) are undergoing major legal challenges across the world. It's becoming the case that only large teams can actually put together a login page. In this environment, I think hesitancy is warranted.
- Kalium 7y ago> Any Reason why Rails still does not include an any decent Auth by default? If memory serves, Rails has quite good authentication built in by default. If that's not what you meant, could you clarify?
- faizshah 7y agoYea it's really sad that at the hackathons I've been to you can hardly find one other rails developer. With rails you can build things fast and spend more time focusing on building cool unique features. But I go to hackathons and I can't collaborate with anyone using Rails or Ember. Also google cloud has a ton of awesome integrations for ruby and rails so you can build lots of fancy features quickly as well. The rails community needs to do more outreach to universities and students.
- aaronbrethorst 7y agoTen years ago, you'd find plenty of people using Rails at hackathons—back when it was the new hotness. Maybe hackathons tend attract people who are interested in building stuff with 'cool' technologies as opposed to building cool stuff.
- neilv 7y agoWe've had so many generations of Web frameworks, but presumably it's still not a solved problem, because we keep moving to new ones. Of course, sometimes the latest thing has a useful mix of properties that is worth the move. Though many hottest ones turn out to be popular only for a year or so, and then people lose interest. I wonder how much a factor in the churn is the individual engineer desire to have the newest framework keywords on our resume, even when we can tell it's mostly a gratuitous rehash, because a lot of hiring is for keywords. Or maybe more often we're looking for the new tools to provide additional advantage for projects (not resumes), but it's difficult to assess the holistic net payout until we've invested heavily in it for a year, whereupon we repeat with the next tools that seem to promise advantage. I'm all about trying new tools all the time, especially as little side/toy projects, but it's odd that we are often betting important projects on less-proven new tools, when you'd think by now we'd have figured out and proven tools that would be hard to beat. (And I say this as a fan of certain tools that aren't proven enough, but which I wish a few startups would use for getting to demo/launch, so I can humbly see one way this happens.)
- aaronbrethorst 7y ago
- dcosson 7y agoEh. Rails is fine, and lots of other things are fine too. Rails is amazing on day 1, even week 1 of a new project, vs piecing together your favorite separate smaller libraries into a web framework. That can be just what you need for a side project that you want to get up and running fast. But if you’re planning to build a business around it and work on this codebase for years, it’s crazy to optimize for day 1. (Not saying rails is necessarily a bad choice in the long haul, just that you should be picking it for better reasons than being easy to get up and running).
- snowwolf 7y agoThere is an argument that you should absolutely be optimising for day 1. One of your biggest advantages as a startup is agility. Until you've hit upon product/market fit, you want to choose tools that enable you to iterate fast.
- dcosson 7y agoI'm talking about literally day 1, not just like the first phase of the company. If a startup is exactly a single day (or single week) ahead of the competition such that the productivity on that day is make or break, that goes way beyond agility and is probably just not a very good opportunity.
- c0achmcguirk 7y agoI haven't done heavy work in Rails in four years. I miss all the bells and whistles.
- maitredusoi 7y agoI've decided to never quit those "bells and whistles", other frameworks just aren't good enought in competing with those... That is why I am optimizing my rails stuff with a few trick made in crystal lang (like the websocket server and a bunch of MTTQ like jobs ;) . For me, until ruby 3x3 gets out, crystal is a good help with scaling up processing.
- freehunter 7y agoI do a bit of Node.js stuff at work (not a programmer by trade, just lightweight stuff) but on my side project it's Rails first and foremost. As the sole developer, I need to just get stuff done. Performance isn't a concern at the small scale I work on. I've experimented with other frameworks and besides Django I've never found anything that's end-to-end the way Rails is. I don't have to think about the framework or the technologies, I just write some code and I'm done with it. I don't have to interact with the database directly, ActiveRecord handles it for me. It's pure productivity, which as a solo developer is the most important thing for me. For some front-end pieces where I need more flexibility, Vue nests in nicely with Rails where it's needed and gets out of the way where it's not needed. There's nothing in the JS world that even begins to compete with Rails as an end-to-end solution.
- perfmode 7y agoHow is helix these days? The idea of calling out to Rust was super compelling when I first read about helix. Is that problem still being tackled?
- kenhwang 7y agoHaven't heard much from Helix since 2017, and it does appear to be inactive since. The limitation to only Strings, Integers, Floats, and Booleans made it pretty hard to use in practice given how Array/Hash/Object-centric Ruby is. Though the latest Mozilla blog post about Rust FFI using protobufs makes me think rolling the same approach on top of Helix's groundwork with Strings should make it possible to pass around meaningful objects with a bit of overhead.
- ekump 7y agoI use Rutie[0] to handle passing complex ruby objects to Rust and it works well. You can also use Rutie-Serde[1] which handles even more of the heavy lifting for parsing Ruby objects into Rust structs. [0] https://github.com/danielpclark/rutie https://github.com/danielpclark/rutie [1] https://github.com/deliveroo/rutie-serde https://github.com/deliveroo/rutie-serde
- _hardwaregeek 7y agoI wish Rails had a way to use less features. API mode is great, but when I'm writing a GraphQL API for instance, I don't use controllers, I don't use views, I don't really use routing. I do use the excellently integrated ORM, database migrations, auth libraries (mostly devise), config environments, deployment options and CLI interface. I could just delete the folders, but that's not the point. Rails is sitting on an amazing foundation but there's only one possible house that you can build.
- deleted 7y ago[deleted]
- mullsork 7y agoYou can opt out of loading the library code for views/mailers/etc. Not sure if there's a way to skip the routing layer though. I'm sure you're aware of that already but just in case, you can skip loading the entire framework.
- ewalk153 7y agoUse a Sinatra app and include ActiveRecord. There are a few gotchas like making sure to clear connections at the end of requests. https://stackoverflow.com/questions/41400202/replacing-activerecordconnectionadaptersconnectionmanagement-in-activerecord https://stackoverflow.com/questions/41400202/replacing-activ... I’d love to see more examples of picking pieces of rails and combining with other libraries.
- _hardwaregeek 7y agoThe only concern I have is that because AR isn't designed as a separate gem, there's no guarantees about breaking changes. But I suppose that's unlikely.
- deleted 7y ago[deleted]
- timdorr 7y agoWhen you use `rails new`, there are a bunch of `--skip-*` flags to turn off various features of the framework: https://gist.github.com/aklap/ee4bb619a77b80bf0c934a9948dc49a2#file-rails_new_output-txt https://gist.github.com/aklap/ee4bb619a77b80bf0c934a9948dc49... Those carry through to the boot process and never even get loaded into memory: https://github.com/rails/rails/blob/master/railties/lib/rails/generators/rails/app/templates/config/application.rb.tt#L10-L19 https://github.com/rails/rails/blob/master/railties/lib/rail...
- sara1732 7y agoThey found world's biggest fish Even you can't believe how big fish is this That's unbelievable http://bit.ly/2FHl4pM http://bit.ly/2FHl4pM A cute dog is dancing in video Just watch this video and try to control your laugh http://bit.ly/2ZK1XVs http://bit.ly/2ZK1XVs See how a Turkey saved the life of his friends Even those birds also have love in their hearts http://bit.ly/2WhAiZS http://bit.ly/2WhAiZS Guy made world record He drive car on two wheels See his video how he is driving http://bit.ly/2ZOYaWX http://bit.ly/2ZOYaWX See the video of this man he is catching balls and he is wearing blindfold http://bit.ly/2Vx4Mdl http://bit.ly/2Vx4Mdl
- revskill 7y agoThere're a problem with Pull request in many large OSS. Sometimes i see many mysterious PRs which says nothing in the description. It seems the author really doesn't want to expose any details of the why and what of the PR itself. Visitors, devs REALLY want to learn more about Pull requests, they're not just users.
- nickjj 7y agoInteresting site. At first I thought my browser was somehow set to 250% zoom. So then I zoomed out to 50% but the font sizes are still as big as they were at 100%.
- zodiakzz 7y agoWeird. Apparently they decided to (ab)use CSS viewport units everywhere just to jump on the cool kids bandwagon, completely breaking browser zoom functionality. This is not what viewport units are for. The site is also nearly illegible at 610px browser width because of it.
- nvarsj 7y agoYeah I couldn't read the article - fonts are giant on my 32" and I couldn't scale them down.