5 ms·
Well, look at the code :) I did, it was educational. Node.href contains the values that are linked on the up/down arrows. // ping server var ping = new
by npk 19y ago
Well, look at the code :) I did, it was educational. Node.href contains the values that are linked on the up/down arrows.
// ping server
var ping = new Image();
ping.src = node.href;
return false; // cancel browser nav
}
The clever part is in using the image object as an ajax-like connection, response isn't check, and I'm not sure if it's async. Question: is this a common javascript idiom? Is it browser portable?
Mynameishere: The answer to your question is it updates the number and makes an immediate request to the server.
- palish 19y agoEr.. So that means it's a GET request, and GET requests which modify state on a website are bad. Things like Google Web Accelerator silently visit all the links on the page and cache the result in case you decide to visit that link. So there might be some problems for people using those (For example, their accelerator might accidentally upvote all the comments in every comment page they visit)
- benhoyt 19y agoGoogle Web Accelerator won't follow the link, because it's got query parameters (a ? in the URL). See their help: http://webaccelerator.google.com/webmasterhelp.html#prefetch3 http://webaccelerator.google.com/webmasterhelp.html#prefetch3 It's just as well, too -- GETs are used so often for this kind of stuff that any web acceleration tool which ignored this would break lots of sites.
- ralph 19y agoGWA did use to follow all GETs, including those with parameters, and did cause all kinds of grief because of poorly written web sites, so they added the query parameter check to work around it.
- palish 19y agoYep, I just confirmed this by viewing the source code, then visiting http://news.ycombinator.com/a?fnid=oO6e74w9Mq http://news.ycombinator.com/a?fnid=oO6e74w9Mq manually. It upvoted the "bandsintown" article. A misbehaved web accelerator could upvote every single article on the front page, and every comment in each comment page that they visit.
- palish 19y agoOkay, so I just downloaded Google Web Accelerator and it doesn't upvote the links.. It must be smart enough not to. I'm worried about other ones that people may be using though. (Doesn't fasterfox do some kind of prefetching?)
- npk 19y agopalish, interesting. Something I've never thought about. Do web accelerators typically not follow POST requests?
- palish 19y agoThey can't reliably, because POST requests usually get data from forms when you click 'submit'. The other way to initiate a POST is using xmlhttprequest, setting the method to 'POST', and then sending your data.
- paul 19y agoIt's just an adaptation of the old, non-js html, in which the arrows were just links, and it's written such that it will work in the old way if the js doesn't work for some reason (like I never bothered to test it with all the browsers). Anything that assumes that GET links can be arbitrarily followed will break stuff all over the web. GWA needs all kinds of heuristics to avoid that kind of thing. (maybe they avoid sending cookies or session ids?)
- palish 19y agoExcept it's vulnerable to an iframe exploit. See: http://news.ycombinator.com/item?id=27615 http://news.ycombinator.com/item?id=27615
- paul 19y agoFalse (that GET causes the problem), see http://news.ycombinator.com/item?id=27629 http://news.ycombinator.com/item?id=27629
- Bogtha 19y ago> Anything that assumes that GET links can be arbitrarily followed will break stuff all over the web. Arbitrarily performing GETs is something condoned by the HTTP 1.1 specification. Anything that assumes that GETs won't be arbitrarily followed is clueless. You'd think people would have learned this the first time around. Don't write out-of-spec code and then complain when conforming code comes along and trashes your app. It's your bug, not theirs. > GWA needs all kinds of heuristics to avoid that kind of thing. How reliable. Wouldn't it be better to follow the spec so this kind of guesswork wasn't necessary?
- ralph 19y agoYes, educational as you say. node.href just returns an empty text/html document when fetched. Does this happen synchronously or not? What do browsers do when they're given text/html as the content of an image and what do the specs define they do? When is ping freed? Is it automatic when it goes out of scope and does that suggest that the image fetch is synchronous?