4 ms·
As someone who frequently prefers to "roll their own" code for simple things rather than import complex 3rd party dependencies, I have to ask: is the world of w
by danielbarla 6y ago
As someone who frequently prefers to "roll their own" code for simple things rather than import complex 3rd party dependencies, I have to ask: is the world of web development - with all the implied focus on security - really the right place to start encouraging people to create their own frameworks?
- jkoudys 6y agoOdd that the author ends on saying to make apps secure from the start, when this is often the intent in using bulkier frameworks to do "simple" things. It's also odd to criticise abstraction on abstraction since that's what literally all computer programming is. The simplest and least abstracted approach would be running SQL directly.
- danielbarla 6y agoI guess the author is arguing that we currently over-abstract, which is quite possible. At the end of the day, it will always be some kind of balancing act. My point is that web applications are, at least from a security standpoint (but also some others) anything but simple, and I'm fairly sure most attempts at creating a focused, lightweight, custom framework are littered with security issues. There are counter-examples in both directions, but this is just my general experience; people who know all the pitfalls you would have to avoid also don't generally want to try to implement all that by themselves.
- fendy3002 6y agoThe answer is it depends on the maturity of framework and how it manage extensions. There are many framework out there that is hard to add another extension / plugin when it's not included in configuration. Some example maybe if you want to connect to multiple db, elasticsearch library, redis, etc. It's sometimes hard to do something when the app booting due to the nature of framework. On the side note though I find Laravel is mature enough for standard use.