4 ms·
We had a pretty similar experience with elm around cookies. The elm-lang/cookie repo README starts with "Cookies are an ancient mistake of web browsers. They ma
by beh9540 6y ago
We had a pretty similar experience with elm around cookies. The elm-lang/cookie repo README starts with "Cookies are an ancient mistake of web browsers. They make a bunch of security problems quite easy, so consider this an expert library." However, they never address reading cookies, so if you're using a framework that does CSRF protection with cookies, you have to use ports, which adds quite a bit of complexity for something as simple as making an API request.
Elm looks great on the surface, but once you start digging in you really start to realize it's "there" way or else. It's too bad, the ideas have a lot of promise, but we pivoted away quickly after running into the "core arrogance" a couple of times and went with Typescript/React/Redux.
- frosted-flakes 6y agothere -> their
- clintonb 6y agoI remember seeing that repo a few years ago when assessing using Elm for a project. I, also, went with Typescript and React based on that README and the issue full of folks pleading for the package to be restored.
- deleted 6y ago[deleted]
- hombre_fatal 6y agoWell, you should be using `httpOnly` cookies (i.e. unusable from the browser) and setting them from the server. Your browser client will automatically send them. document.cookie is a security vulnerability that's hard to find in any respectable documentation. It's up there with sql string concatenation.
- jfkebwjsbx 6y agoSQL string concatenation is fine. You mean parameter concatenation (into the query string).
- hombre_fatal 6y agoCall it whatever you want, but everyone knows what "SQL string concatenation" is referring to wrt injection. I don't think a finer point is necessary.
- ggregoire 6y ago> The elm-lang/cookie repo README starts with "Cookies are an ancient mistake of web browsers. They make a bunch of security problems quite easy, so consider this an expert library." What an arrogant and opinionated way to start a documentation.