4 ms·
These are the kinds of what-if questions that scare people into using the most popular framework-- well, what if security isn't as good? What if it's not proper
by benbenolson 7y ago
These are the kinds of what-if questions that scare people into using the most popular framework-- well, what if security isn't as good? What if it's not properly cached? What if the rewrite is hard? What a load of bologna.
- debaserab2 7y agoNo, it's not a load of bologna. Rolling your own auth system is very likely not going to produce an auth system as battle hardened/tested as <popular framework>. Rewriting an entire site from scratch is rarely the correct choice and is one of the most common engineering fallacy. https://en.wikipedia.org/wiki/Second-system_effect https://en.wikipedia.org/wiki/Second-system_effect Caching is a problem you need to solve regardless of whether you're using a framework or not. These problems don't magically go away when you decide to rewrite these components yourself. You probably aren't going to write code as well as a community of coders that have contributed to a years-old codebase. Especially not on your first pass. These are all pretty legitimate "what-if" questions to ask.
- battery_cowboy 7y agoYou don't need to use heavy frameworks for auth, it's not a choice between rolling your own and using a huge framework.
- debaserab2 7y agoThe original poster said "plain old PHP" so without making assumptions I am taking that statement at face value. Still though, auth is just one arbitrary requirement I plucked from many that popular frameworks solve such as request handling, response rendering, database operations, routing, etc. Yes, you can use a hodgepodge of libraries to solve these requirements but your argument that your codebase will be leaner than a "heavy framework" using codebase gets a bit flimsier in my experience.
- battery_cowboy 7y agoMaybe not leaner, but you'll understand it better.
- debaserab2 7y agoWhy would you understand a mix-match of libraries better than a framework? You have to learn their interfaces either way to use them.
- battery_cowboy 7y agoYou'll understand your code better and the limited scope of the libraries allows for less bugs in each component and easier migration later if needed. If I use the big framework, I'm stuck with it if I ever have to change my data storage method and it's outside of the frameworks normal scope. If I use a separate library, I can change over to whatever I need. Look, I'm not saying you shouldn't use a framework, every project has different needs. I'm saying that frameworks have made people lazy and they try to fit their project into the framework they know when when it's wrong.
- debaserab2 7y ago> You'll understand your code better and the limited scope of the libraries allows for less bugs in each component and easier migration later if needed. What do you think the components in a framework are? They're just libraries, and often can be/are used standalone. I've seen no evidence that there are less bugs in a library not used for frameworks than one used for it. > If I use the big framework, I'm stuck with it if I ever have to change my data storage method and it's outside of the frameworks normal scope. There's no reason you can't use a different library within the framework. It's the exact same as writing from scratch, you're just doing it within the patterns of the framework instead of the patterns you've created on your own. > Look, I'm not saying you shouldn't use a framework, every project has different needs. I'm saying that frameworks have made people lazy and they try to fit their project into the framework they know when when it's wrong. I'm not advocating for blanket usage of frameworks either but I've yet to see a compelling reason to in this discussion thread not to.