10 ms·
Showoff
- blahed 15y agorock & roll!!!!!!!!
- kainosnoema 15y agoCongrats on the launch, guys! We've tried it and love it.
- larrik 15y agoI love this idea, and the pricing seems spot-on. However, it's not obvious if this is Ruby-only or not? I don't use Ruby, so that's kind of a big deal.
- deleted 15y ago[deleted]
- crikli 15y agoI had the same question as we do mostly PHP; I'm guessing it just uses Ruby as the host software. I installed the Gem and was able to acquire a URL but kept getting an error: An error has occurred: {"stack":"Error: socket hang up\n at Socket.<anonymous> (http.js:1271:45)\n at Socket.emit (events.js:64:17)\n at Array.0 (net.js:825:12)\n at EventEmitter._tickCallback (node.js:126:26)","message":"socket hang up"}
- senex 15y agoHey crikli, could you send an email to support@showoff.io with any extra details that seem relevant? We'd love to track this down!
- jimmyjazz14 15y agoYou need to have some server listening on your local machine at whatever port you are creating the tunnel for. If you just wanted to test it out you could start something like "python -m SimpleHTTPServer" and then "show 8000", which will serve files from your local machine at your showoff url (I might recommend running the server in an empty directory).
- crikli 15y agoRight you are; I did that and was able to see a bunch of stuff I'd not want to share over the web. :) Sheesh. Ruby runs over 3000, if you're not running the ruby server on 3000 there's not going to be anything listening. Facepalm.
- jimm 15y agoA pedantic correction: Rails runs its server on port 3000 by default; Ruby is the language Rails was written in.
- geuis 15y agoInstead of giving this error, there needs to be a message that explicitly tells the user what's wrong. Something like: "Woops, you said your server was running on port <port>. Is it?"
- pixeloution 15y agoyou have to leave the 'show' program running or you get that error - leave your terminal window open, don't control-c out of it once you've started it, and it will work fine. I had the same issue :)
- willwagner 15y agoI was going to say that the day pass pricing is right on but if it was me, I'd want to do price testing on the monthly pass because it seems to inexpensive. I'd also consider a "Enterprise plan" which is monthly plan with possibly some restrictions based on IP or with password protection etc.
- senex 15y agoWe wrote the showoff client in Ruby. It's a light wrapper around SSH that helps manage accounts, SSH keys, &c. Since Showoff is basically a fancy SSH tunnel, it should work with any kind of webserver. If there's enough interest, we'll probably bundle up client software in ways that don't depend on `gem install`.
- hinathan 15y agoThis looks like a slick expansion of the idea here https://github.com/progrium/localtunnel/ https://github.com/progrium/localtunnel/ Will be sure to kick the tires with a side project or two.
- drtse4 15y agoYep, was going to post about that too (progrium rocks), but looks like the site the project used for its redirects is down http://www.downforeveryoneorjustme.com/localtunnel.com http://www.downforeveryoneorjustme.com/localtunnel.com
- hardik988 15y agoThe page http://localtunnel.com http://localtunnel.com does not show up, but it works like a charm when you get your own localtunnel URL.
- mtogo 15y agoWhy would i use this over a VPS? A VPS is a similar price and has similar functionality, but doesn't pose a security risk to my home workstation and comes with a slew of other benefits. The tech looks reasonably cool, but what is the use case? EDIT: Your site also makes it sound like it is HTTP(S) only. If it's not, you might want to clarify that.
- senex 15y agoHey mtogo, good question. We often develop sites on our laptops. The more complicated sites are, the more there is to sync around (databases, dependencies to install, version control commits, &c). Showoff is a quick way for us to get feedback from clients or each other without adding overhead to our development process.
- mtogo 15y agoAh, that makes sense. Thanks.
- albemuth 15y agoFunny, I thought you mentioned the VPS because you could still reverse tunnel and share the app in your laptop without deploying. I was going to say that it's still a good idea since the day pass is just $1. p.s. surprised they didn't go for 99 cents
- roryokane 15y agoThe main page seems focused on simplicity and short sentences. I think they thought that $0.99 would have looked too noisy compared to $1. It's possible that they are also pandering to people like me who dislike prices written in that way. I am annoyed by the chore of mentally adding one to every price ending in 99 cents, and I respect sellers who write prices like that less.
- deleted 15y ago[deleted]
- josiahq 15y agoHappiness, is a warm socket.
- hugh3 15y agoI don't understand why it says "laptop". Why not my desktop machine?
- robrighter2 15y agoWe wanted to make it super clear that the primary use case is local development. By saying laptop it removed any ambiguity that it might be a production deployment tool.
- Travis 15y agoText is hard to read. I'm still not exactly sure why I would use this over a VPS (maybe it's for devs who don't use VPS/EC2 as their dev machine?) Is this for live demos or for sharing documents? If the former, why wouldn't I just turn on apache and give them my IP?
- cmelbye 15y agoBecause "show 3000" is much easier than setting up apache, turning on apache, forwarding ports, and giving them your IP.
- Travis 15y agoAh, gotcha. So the product that is being sold is simplicity. Are you the creator? If so, I would suggest: - more contrast between text and background - explain who the intended user is (web dev w/o strong LAMP background. I would find it easier to turn all that stuff on than to try to use a new product, and it's not worth even $1 to me to do that... so I'm clearly not your target customer) - explain what your value prop is (it's not "Now You Can Share!", it's, "Now You Can Share With One Click"). The way it's explained, it feels like a new capability... edit, formatting.
- bobwaycott 15y agoWell, to be fair, and this is personal opinion, Showoff has little to do with whether or not a developer has a strong LAMP background (or .NET, or Haskell, or insert-your-favorite-stack here). And yet it has everything to do with whether or not a developer has a strong LAMP/whatever background. Showoff is not intended to replace your stack--at all. In fact, this product came from a strong server-side background. If you find it easier to set up Apache & MySQL & DNS records and all that to show a client/person a development site/feature you are working on locally (that has not yet been moved to a server), that's fine. Slightly masochistic, but still fine. It's just that's more than most of us, as well as most of the devs we know, want to have to do to share local projects-still-in-development with our teams and clients. Example use cases: CASE ONE. You are working on a new site or feature for a Django/Ruby/.NET site on your local box. You've been banging away at it for the last couple hours, and are trying to explain it to your client, coworker, boss, or friend. You have it running locally just fine, are playing with it at http://localhost:1234/ http://localhost:1234/ and it looks pretty good. Everything's in good shape to show off your great new thing. If only they could both see it & interact with it, they'd be able to try it out and let you know what they think. How are you going to do this? -Option 1: Leverage your strong LAMP/whatever background & ssh to your development server, get all your proj files up-to-date, migrate/upgrade a db schema, restart your instance, test everything out to make sure there were no unforeseen impacts from the change before you let anyone else see it (you don't want them to hit the page & get a 500 (you do test before you let anyone try a new feature, right?)), then paste the URL to your client, coworker, boss, or friend. -Option 2: switch to a shell & execute `show 8000`, then paste the URL to your client, coworker, boss, or friend. CASE TWO. You are updating a site that's been around for a long time and is already live on the web. Some important changes and new features have been requested & you've been banging 'em out for a couple hours (or days). You need to get them before your client, coworkers, boss, or friend before they are live on the site. You currently have everything running locally at http://localhost:1234/ http://localhost:1234/ and it looks good to you. Maybe you have a few questions about whether you're on the right tracks. What'd be really nice is if you could put up what you have, let your client, coworkers, boss, or friend check it out, and maybe go thru a few page refreshes rapidly to see some other options (especially helpful with CSS changes/fixes). -Option 1: Leverage your strong LAMP/whatever background & ssh to your development server, get all your proj files up-to-date (including making sure the dev site is exactly identical to the live site and then apply your changes), migrate/upgrade a db, restart your instance, test everything out to make sure there were no unforeseen impacts from the change before you let anyone else see it (you don't want them to hit the page & get a 500 (you do test before you let anyone try a new feature, right?)), then paste the URL to your client, coworker, boss, or friend. Time to try the next change? Repeat all over again. -Option 2: switch to a shell; execute `show 8000`; paste the URL to your client, coworker, boss, or friend. Time to try the next change? Usually just a quick local Save action away & asking them to refresh. If anything, you might even argue that the people who have a strong LAMP/whatever background are exactly the target customer for Showoff -- they're the only ones who can read Option 1 and groan in disgust at doing all that just to try out a pending feature/fix. The value prop isn't merely "Now You Can Share With One Click" (and not just because there is no clicking involved) ;). It's that and much more.
- jsdalton 15y agoAwesome. I'm definitely a potential paying customer. Two suggestions and a question: * How about a free trial for unlimited access or some other kind of cancellation guarantee? * Minor one, but the dark contrast on your website UI is about equivalent to the background on a typical lightbox...i.e. it reads "disabled" to me on first glance. One question: I assume I could map a CNAME record to the showoff URL? (So cookies work, etc.)
- senex 15y agoWe're going to add CNAME support soon. Thanks for the feedback about the color scheme. If you sign up for an unlimited account and you're _really_ unhappy, send an email to support@showoff.io and we can talk about a refund :)
- jsdalton 15y agoCool good to know. :) Less a matter of the money, more a matter of wanting to easily play around with the "full strength" version to see if it really works for me. I happen to be working on an account/authentication service right now, so being able to rig it with a working domain name (via CNAME) so cookies work with my app is definitely big on my list.
- mtkd 15y agoTeam payment options would be good too - $25/M 7 user option or something.
- russellperry 15y agoContrast could be better but I like the layout and fonts. Simple.
- gregschlom 15y agoI second the dark contrast point. My first reaction on the site was "omg, what can I do to put some color and some life here". I even tried playing with the bookmarks on the top right corner to see if they would light up the site.
- nikcub 15y agoI just use dyndns.org. free and easy to use and update
- thomasdavis 15y agoYes indeed, not as easy as "show 80" though
- nikcub 15y agonope, easier - I have the following aliased as 'ddu': lynx -dump -auth=user:mypass "http://members.dyndns.org/nic/update?hostname=myhost.dyndns.org I have 'ddd' set it to a random IP, so that I can determine when it is active and not have to deal with random proxy scans etc. If you aren't UNIXy you can use one of the dozens of update clients: http://www.dyndns.com/support/clients/ http://www.dyndns.com/support/clients/ dyndns is just one provider. you could host it yourself. There are dozens of routers and clients that support DDNS protocol, no need to reinvent things.
- mtogo 15y agoDynDNS works, but not if you're behind a NAT or firewall that you have no control over (e.g. a coffee shop).
- chapel 15y agoAt first I thought this was Ruby based since it was installed via gem, but at the footer it says it is built using Node.js. This is a fine example of the power of Node.js as well as the versatility. On a side note, this reminds me that isaacs (creator of npm) has pushed npm to be for development and not for deploying to end users. Hence using gem instead of npm.
- senex 15y agoWe're planning to make more "normal" installation scenarios if we see good interest. Using gem was a quick way for us to get the idea out.
- chapel 15y agoI like the idea, and had you not have used Node.js I was going to spend a few hours and create a clone using Node.js since it would be that easy. Mind you not that easy if I were to match your level of service and the site. Hope it has a lot of success.
- PanosJee 15y agoNode is a network library and you can easily create a TCP server. That s all. On the other hand ruby is great for writing scripts and nice DSLs so the whole concept is implemented very nicely.
- chapel 15y agoNode.js is more than a network library, but you are right it is easy to create a TCP server. I have created many scripts using Node.js and I am not the only one.
- thomasdavis 15y agoMan, the whole site was a pleasant experience to browse. I was browsing it because it was just fun to. The idea is perfect and I encounter this problem daily and always too lazy to bother setting up a dynamic dns. Signing up for an unlimited plan right now. Well done.
- dholowiski 15y agoWow that's brilliant. I'm definetley a potential paying customer. That's cheaper than spinning up an Amazon EC2 micro instance to develop on at $5 a month. I'm not a big fan of dark gray background with darker gray text though.
- thenduks 15y agoFortunately sites you create and 'showoff' don't need to use the showoff.io stylesheet :)
- gridspy 15y agoThe advantage of Amazon EC2 is that it doesn't go down when your laptop turns off.
- bobwaycott 15y agoConversely, the advantage of Showoff and its kind is that it does go down when my laptop turns off.
- FaceKicker 15y agoEC2 micro instance is $54 a year, so it's only cheaper if you only want 10 months or less.
- jasonling 15y agoFree for a year (at least): http://aws.amazon.com/free/ http://aws.amazon.com/free/
- seiji 15y agoWhy is your site so pretty? I feel lucky when I style a <ul> enough to not make me gag.
- pixeloution 15y agoI've got MAMP Pro running on my notebook and have a half-dozen "local" urls ( only valid URLS for me ) - is there a way to point this service at those URLS in addition to localhost?
- senex 15y agoYup, try using something like `show --host=mysite.local 80`.
- pixeloution 15y agotried this and its still connecting to the folder http://localhost http://localhost points to
- pstack 15y agoWhen I see new projects and ideas that take off, my response is usually a curmudgeonly observation about how stupid and pointless it is or how it's so obvious and trivial that I can't believe anyone would waste their time making it. This is not one of those. This is one of those cases where I'm not a bit jealous because something so obvious or inane or dumb took off and became Twitter, but because it's just so damn fantastic. This is one of those things that is so elegant and smart that it makes me feel like a complete idiot. This is going to do very well.
- leon_ 15y agowell, it's trivial after reading ssh's man page. though the execution is nice and everything is packaged that relatively tech un-savvy users can make use of it.
- dholowiski 15y agoAbsolutley. This is a non-obvious but simple idea executed well and the creator deserves to make buckets of money.
- progrium 15y agoI feel that localtunnel was also executed quite well, is free and open source, and has been around for a while now: https://github.com/progrium/localtunnel https://github.com/progrium/localtunnel Where are my buckets of money? Oh yeah, I don't care.
- sovande 15y agoOh but I detect that you care. Well, the difference between this and an obscure open source project buried on git hub is for a starter to at least have a web-site at localtunnel.com!
- progrium 15y agoI care about my work and it being used and contributed to if people are interested in it. I don't care about money, which is why it's open source and run as a free service. My code is MIT and I would love it if people took my code and made a pay-for service like this with it... but instead, they (to be fair, probably unknowingly) duplicate effort and obscure my work. If a fancy website is all I need, I guess that's what I'll be doing this weekend. And I guess SSL and CNAME support...
- ionfish 15y agoThe usability of the payments form is poor. It doesn't state which fields are required (if it's all of them, it should say so at the top). I understand not remembering the credit card number or CVN between requests, but it also forgets the expiry date, and the country. I had to resubmit several times because of this. Fortunately in my case I had the patience to go through it regardless, but given the amount of research indicating people's willingness to drop out of payment processes halfway through, this is something really worth fixing.
- geuis 15y agoOne note about the setup. When you have multiple ssh keys available, the "pick one" menu looks like this: Choose the public key you'd like to use: [0] id_dsa.pub [1] id_rsa.pub [q] Quit This should start with 1, not 0.
- Timothee 15y agoConsidering the likely audience, starting with 0 seems adequate. (see http://en.wikipedia.org/wiki/Zero-based_numbering http://en.wikipedia.org/wiki/Zero-based_numbering)
- tmhedberg 15y agoTrue, but when using numbers to make a menu selection, it makes more sense to start numbering at 1, because of the way number keys are arranged across the top of the keyboard. It's slightly less intuitive to have the key corresponding to the first menu option positioned far to the right of the subsequent options.
- Timothee 15y agoGood point about the positions of the keys. In fact, I had never thought that one could argue that the '0' key should be to the left of the '1' key… keyboards predate computers, so I see why this is not the case, but it could be argued.
- geuis 15y agoYes, I think I understand why it starts with 0. However, this is about context. When I am coding, I know indexes start with 0. When I am picking from a list of items in a menu, the context is starting from one. When you go to a restaurant and you order the first thing on the menu, you don't say "I'd like to have the zeroth item" do you?
- moe 15y agoIf you have a public facing server then this can be had for free: ssh -nNT -R 8080:localhost:3000 myserver.com Et voilà, myserver.com:8080 now points to localhost:3000.
- wildmXranat 15y agoDo you accept upvotes as currency? I was thinking that ssh should be able to do this.
- senex 15y agoYup, this is basically what showoff is doing. Showoff is nice because it gives you: * HTTPS * Works without access to public-facing server. * Pretty URL * Eventually will support more stuff besides just port-forwarding :)
- tekacs 15y agoAh, that last bit sounds good - look forward to it... :)
- kordless 15y agoThere's this bit about the 'show' command on your computer. I'm wondering if that's a bash script, or a standalone bit of software to forward data to their servers?
- bobwaycott 15y ago`show` is just the command that sets up the ssh tunnel. Doesn't forward data or anything like that. EDIT: It's not a bash script. It's a Ruby wrapper.
- bobwaycott 15y agoAnd there's still that ugly port number in the URL. Vast majority of clients would neither like nor understand this -- most of them don't even know what a port number is. EDIT: Also, Showoff isn't suggesting it's doing something you couldn't do before. It just does it in a simpler & pain-free way.
- huherto 15y agoI am not picky about design. But please change the colors. There is not enough contrast. I am really making an effort to read just because everybody says it is worth it.
- andrewl 15y agoVery nice tool. I expect to use it, and happily pay for it. I like subtle, minimalist design, and the look grabbed me. But I also have somewhat diminished vision, and I had to blow the page up a lot to read it.
- andrewheins 15y agoI was looking for exactly this service a few weeks ago and would be a paying customer, but I develop on Windows. A future market, if you're interested.
- HerraBRE 15y agoCheck out http://pagekite.net/ http://pagekite.net/ , it's Python and it runs on Windows just fine. We are working on a user-friendly installer and GUI, but if you're a developer you don't need that. :-)
- gorm 15y ago+1 for this. Saw a talk on pagekite earlier this year and it looks very cool and a good alternative to this service.
- andrewheins 15y agoYou sir, are a Godsend. Kudos to you.
- ChuckMcM 15y agoHmm, I also think you need a new name. 'Showoff' says exactly what it does, lets you 'showoff' your work. What's a pagekite? (reminds of the 'mint' vs that unpronouncablely named finance site naming issue). I'm an ops guy, lets say I want to give access to my next generation product to a usability lab for feedback. Can you imagine what that whole experience would feel like? I'll want some reporting of when the site was used and what was done. I'll want full cookie transparency so that the user experience will be 'real' but not require the developers to do anything special to get there. I'll want to know that I can turn it off pretty much instantly if I think there is a problem. That is perhaps a product that is orthogonal to the 'put a demo page up' kind of thing though.
- HerraBRE 15y agoRegarding the name, I actually think PageKite is an excellent name and we are lucky to have it. It's googlable, we got the .com for cheap, it's a strong trademark. If I draw you a picture of your site flying like a kite in the clouds, connected by a string to your laptop, you'll find the name is a perfect fit... :-) Admittedly, I do need to get that picture drawn. Regarding the technical side, you do get all those things. Some you get by collecting your own server logs, some (like cookie transparency and instant-off) you get through the nature of the system itself. But if focusing on the website demo market, then making things easier by adding reports etc. would probably make sense at some point. Thanks for your comments!
- dpritchett 15y agoI love it and I'll probably buy a few day passes here and there. I also think Fortune 500 security teams are going to be blacklisting this domain soon just to keep their devs from opening holes in the firewall.
- pakeha 15y agoAt the corporates I've worked at, this product would have been preemptively blocked anyway because it relies on an outbound ssh connection through the external firewall, which wouldn't have been allowed. I'm not sure if that's standard practice at other SuperGloboCorp organizations.
- eru 15y agoAt Citrix say allow outbound ssh, but not, say, telnet.
- IgorPartola 15y agoThis looks awesome. I would not use something like this because I have lots of ways to make it happen without paying extra (as in I already have a bunch of servers I can use for ssh tunneling). However, I can see how you would get a bunch of dedicated users. Good luck. My only question is: won't this service be completely obsoleted by IPv6? I already use IPv6 instead of having to VPN into a NAT'ed office from my NAT'ed home. Just giving someone who has IPv6 connectivity a URL that uses one of my IPv6 addresses will accomplish something similar, will it not?
- HerraBRE 15y agoNot really. Just because you have an IPv6 address doesn't mean you won't be trapped behind a firewall that blocks incoming connections. And when you have an IPv6 address and want to show something to a person with an IPv4 address... then you will definitely need either showoff or pagekite, or something like that to act as a bridge.
- kaffeinecoma 15y agoPerhaps I missed it in the FAQ, but how do you turn it off? CTRL+C? I understand that you're aiming for simplicity here, but it would be handy to have a menubar icon (or whatever is appropriate for the given platform) to indicate that it's running or not. Or maybe you actually have that, but it's not clear that you do from the website.
- dpritchett 15y agoCtrl-C doesn't do it for you?
- kaffeinecoma 15y agoPresumably, but I haven't tried running it. I'd kind of like to know how to turn off something that's going to do port-forwarding on my machine before starting it up.
- dpritchett 15y agoThe /usr/bin/show script simply locates the gem and runs it in a Ruby process. You can kill it like any other console program. Inspect the gem if you're curious. The interesting part of the gem starts off like this: def showoff(rhost, rport, lport=80, host='localhost') @session.forward.remote lport, host, rport [1] http://rubygems.org/gems/showoff-io http://rubygems.org/gems/showoff-io
- bobwaycott 15y agoA menubar icon (assuming you're meaning Mac OS (or any OS really)) is not something you get from a simple shell script, typically. Please correct me if I'm wrong.
- bxr 15y agoNormally a gui tool doesn't advertize how you invoke it from the commandline, but there are plenty of cases where the command-line invoked application doesn't retain the foreground while running. This tool is probably non-interactive at the console, I have zero expectation that it won't fork off into the background.
- southpolesteve 15y agoThis is so completely awesome. Just yesterday I was looking for something similar. I will start using this immediately.
- HerraBRE 15y agoOut of curiosity, how did you go about your search?
- deleted 15y ago[deleted]
- deleted 15y ago[deleted]
- erik_p 15y agogreat idea - definitely why haven't I thought of this pain point that I run into all the time. No fussing with dynDNS, opening ports, or scrambling to deploy a public interweb accessible version of dev code. Kudos, man.. kudos.
- Erwin 15y agoDoes this use SNI ( http://en.wikipedia.org/wiki/Server_Name_Indication http://en.wikipedia.org/wiki/Server_Name_Indication ) to allow for multiple vhosts on same IP? (since they use a *.showoff.io wildcard certificate). As I understand it, SNI does not work on IE7 on XP (Konqueror apparently has trouble with it too).
- jimmyjazz14 15y agoIt is not using SNI so it should work fine on IE7 and others.
- huhtenberg 15y agoMay want to fix this - http://i51.tinypic.com/2a00yyv.png http://i51.tinypic.com/2a00yyv.png - this is in FF4 on Windows XP. (edit) I meant the text overflow, not the lack of the background image (which appears to be a problem on my side).
- senex 15y agoThanks, we'll take a look!
- lutorm 15y agoI think your web page is very unclear. "Share a project on your laptop" doesn't really specify that I can share a web server on my laptop. Maybe that's implicit in the HN community, but my first thought was that it was a tool for automatically posting updates of my screen to a web site, which I thought was an awesome idea. Then I read the comments here, and with some disappointment concluded that it's forwarding a network port...
- senex 15y agoAh, interesting. Thanks for the feedback!
- sarenji 15y agoGenuinely curious: Could anyone tell me what the difference is between showoff and localtunnel[1], aside from a payment plan? Great looking site, by the way, but I keep bracing for a JavaScript popup with the page so dark. [1]: https://github.com/progrium/localtunnel/ https://github.com/progrium/localtunnel/
- bobwaycott 15y agoThe payment plan provides easy named URLs at showoff.io currently. This is the first minimally viable version. More features are forthcoming.
- user24 15y ago> This is the first minimally viable version. This one sentence transformed my opinion from "huh, I can do that myself" to "cool, I'll look forward to seeing what else these guys come up with". Well done for launching your MVP :)
- bobwaycott 15y agoThanks for the kind words. The team hopes to not keep you waiting too long. :)
- maheswaran 15y agoi havent tried showoff.io and little curious about how about internal reference translations? for example css files? does this <link rel="stylesheet" href="localhost:3000/mystyle.css"/> translates to <link rel="stylesheet" href="myserv.showoff.io/mystyle.css"/> ???
- danparsonson 15y agoOut of interest, why use absolute URLs at all if the files aren't on a different server? Won't you have to go through and change them all when you deploy? Anyway, re: translations, I believe it's a tunnel so your local server is visible to the outside world as myserv.showoff.io - thus, no translation of anything.
- maheswaran 15y agomy bad, internal references will be relative only (<link href="../Images/favicon/16x16.ico" rel="Shortcut Icon" /> ) so no need for translation. i dont know why i thought what i thought
- senex 15y agoHey maheswaran, Showoff doesn't touch the body of the requests, so you'd need to use relative URLs, change the "domain" config variable each time you make a new showoff tunnel, or set up an unlimited account where you can choose a permanent subdomain like "myserv.showoff.io".
- skinnymuch 15y agoUntil you can't/don't pay the monthly charge and you have to change all your URLs.
- Xk 15y agoThere's an XSS on the page: Try to login or create an account. Enter this as your username (or password, as long as it's not valid: you need an error), hit submit. Error + XSS. </script><script>alert(1);</script> You escape quotes, which is good, so I can't break out of the JSON request. But you have to remember how the HTML parsing of a page works. </script> will break out from within a javascript string.
- Xuzz 15y agoI know this is off-topic, but you can use eval(String.fromCharCode(XX, XX, XX, etc)) to run arbitrary JavaScript, even if quotes are escaped.
- Xk 15y agoThat's not the reason why people escape quotes. Imagine the case where he had not escaped quotes, but had escaped < and >. In that case, I could put a doublequote/singlequote to break out of the JSON. Then I could just put whatever javascript I wanted and run it. But that is true, trying to filter specific character sequences for example, "eval" is never a good idea.
- swolchok 15y agoI'm a little surprised that no one has mentioned webfsd (http://linux.bytesex.org/misc/webfs.html http://linux.bytesex.org/misc/webfs.html), which I use to solve this problem (specifically, as webfs -r .). Caveats: - I'm sure showoff is better if you're firewalled. - It's probably slightly easier to share just one file in a directory with showoff, but this could be remedied with a script that made a temporary webfs root and symlinked the shared files thither.
- jamesgeck0 15y agoI've used Opera Unite like this occasionally, via this [proxy plugin](http://unite.opera.com/application/272/ http://unite.opera.com/application/272/). Unite's fallback proxy servers are usually on the slow side, though. It doesn't support HTTPS, though.
- sciurus 15y agoIs the source code for the server running at showoff.io available? One thing I like about pagekite is that both the client and server are open source. If you have a team of people who regularly need to to allow access to local servers, setting up your own pagekite server seems attractive. https://github.com/pagekite/PyPagekite https://github.com/pagekite/PyPagekite
- Dramatize 15y agoI really like the design of the site. Nice work.
- johnrob 15y agoSince this uses SSH, how do you deal with the fact that any user could login to the remote server? Is there a custom daemon running that implements the SSH protocol, or does the client use the real SSH daemon? If it's the latter, someone could easily get a command shell. In that case, there would have to be some sort of sandbox to make sure that user can't do anything dangerous. I'd love to hear how the creators deal with this - great product btw!
- progrium 15y agoCheck out localtunnel which is open source and does the same thing: https://github.com/progrium/localtunnel https://github.com/progrium/localtunnel
- senex 15y agoHey johnrob, that's a good question. Showoff is currently implemented in three parts: a Ruby client that's essentially a lightweight wrapper around SSH, a custom unix shell implemented in Node.js, and a server written in Node.js. When a client connects to the showoff server, the custom shell is started. It only supports a showoff-specific API, so there's no way to execute arbitrary commands. It's similar in spirit to custom git shells like gitosis.
- hardik988 15y agoThe website looks really great, and I've had great success using localtunnel and I'm very happy with it. Kudos to the folks over at Twilio for opensourcing localtunnel. Not to take anything away from Showoff, the execution looks near perfect.
- dools 15y agoThis is similar to http://proxylocal.com/ http://proxylocal.com/ that was posted on HN a few months ago.
- dools 15y agoI'd much rather be able to do this over an SSH port forward than having to install a Ruby gem. I think the http://browserling.com/ http://browserling.com/ guys are working on a solution where you can proxy your local web server over an SSH tunnel for previewing your website in multiple browsers without deploying it.
- bobwaycott 15y agoThat is exactly what this is. Ruby is merely an elegant wrapper. Installing a gem is quite lower in frictional value than setting up the proper tunnels (especially if you don't already know how). To each his own. :)
- mkrecny 15y agoGreat idea yes. Anyone heard of tunnlr - they've been doing this for ages.
- seats 15y agoHere's the one question/problem I see- How often do you really want to show someone something badly enough that you are willing to block your local dev environment to do so? I could see it working if you are interactively talking to someone in chat, but over email, often times you could be waiting hours for someone to actually try out what you want them to see. You could certainly get around this by setting up a separate local 'dev-show' environment, but if you are going to all that effort you really could/should just set up a dev version on a vps/cloud server. If you are talking to someone interactively, chances are they are another dev, which means they really don't need to see your environment running, they should be capable of using their own. Also, in this thread I really feel people are exaggerating the level of effort to set up a 'showable' environment on a cloud instance. For rails as an example, I can go from server launch to a running app with db in less than 15 minutes (easily) with manual config and I really doubt I'm the exception here. Remember, this is a 'dev' environment still, your apache/nginx config doesn't have to be airtight, it just has to work for the single user you are showing it to (all defaults on everything is going to work at least as well as the built in rails server). Not to mention the fact that if you aren't thinking about automating deployments yet, it's a really good investment of time and would work just as well for this case.
- bobwaycott 15y agoThe thought of helping a dev run my code in his/her environment, or moving it out via git push/pull to one of my dev servers (a process that takes but a minute or so when I'm being really slow) decreases in attractiveness the longer I have been working on feature/fix X is. Even within our organization, few devs work on the same project, but sometimes I want someone's thoughts/opinions/suggestions. Some of the devs are in the office, some aren't. Whether they are or not, the fact that I am the only one who has been working on feature/fix X for the last couple weeks means another dev is nowhere close to being able to just run my project as quickly as I can show it off. Sometimes I want to be able to help a client see a quick implementation of something in a local clone of their live site to show them that their suggestion for feature/fix X isn't such a great idea (like I tried to tell them when they asked for it). I want to block my development when needing to show something off for as short a period as possible. The time & friction of firing off `show` (or whatever local variant I might be using, like any of the others mentioned in these comments (e.g., localtunnel)), is close to zero. This is time & friction to me, not them. No matter what process I follow, all they have to do is click a URL. Showoff offers me the shortest path from A to B.
- voidfiles 15y agoSo, the short story here is to use localtunnel? https://github.com/progrium/localtunnel https://github.com/progrium/localtunnel
- meow 15y agoGr8 idea, but I wonder how many would be willing to use it (especially when there is an option of firing up a amazon ec2 instance when needed).
- teyc 15y agoThe design is absolutely beautiful too. Congrats. Did you do the design yourself?
- allanscu 15y agoThe concept is so simple and needed. I've run into this problem so many times. I like it. Wow!
- known 15y agohttps://addons.mozilla.org/en-US/firefox/addon/browser-server/ https://addons.mozilla.org/en-US/firefox/addon/browser-serve... has similar functionality