5 ms·
Haskell is famous for it's quite an academic nature. But the ecosystem has drastically improved in recent years, so that that image is really outdated by now.
by _query 4y ago
Haskell is famous for it's quite an academic nature. But the ecosystem has drastically improved in recent years, so that that image is really outdated by now.
E.g. with Haskell Language Server we have nice autocompletion. Recently dot-notation has been added, so you can now write `someValue.someField` as in other languages. And the documentation is improving as well.
If you're doing web development, a good starting point is IHP (https://ihp.digitallyinduced.com/ https://ihp.digitallyinduced.com/ https://github.com/digitallyinduced/ihp https://github.com/digitallyinduced/ihp). IHP is Haskell's version of Laravel/Rails/Django. It's really a superpower to have Haskell's type system combined with the rapid development approach of Rails :) (Disclaimer: I'm founder of the company that makes IHP)
- grumpyprole 4y agoSecurity must be big selling point versus these other solutions?
- whateveracct 4y agoSecurity in Haskell isn't especially better than any other general purpose language. You do have a lot more tools to help though. For instance, you can make your web app fail to compile if you accidentally try to serialize sensitive information to JSON or plaintext. GHC will tell you exactly where you almost had a data leak.
- bcrosby95 4y agoIt's actually a bit harder than you're implying, because any request coming to the server could have sensitive information in it. But, yes, wrapping your data helps solve some of the problem in any language. For instance, in Java we hold passwords from requests with a Password class rather than with a String class, whose .toString will return "xx" rather than the actual password.
- grumpyprole 4y agoI was asking about IHP specifically. Yes Haskell is just a tool and one could simply build PHP with it.
- pizza 4y agoI'll play devil's advocate with the hope that it facilitates a response by someone who understands the topic far better than me: what is security?
- grumpyprole 4y agoOne example of security is not munging strings together and shipping it off to the database or some other "eval" with full privileges. A programming language with lightweight static types makes it easier to parse outside data into a typed representation, then transform/evaluate/compile as necessary. This is of course Haskell's bread and butter.
- icrbow 4y agoSecurity is resilience with respect to your threat model. The usual security objectives are confidentiality, integrity, and availability. Nothing is "secure" forever and ever. For each objective you need to state some assumptions that are required to uphold it. Haskell allows you to express more assumptions in code, not just comments, to be enforced at compile time. And with some careful handling Haskell types provide a solid foundation without going into full deductive verification mode.
- schwartzworld 4y agoIHP looks amazing! I think I'm going to have to give it a go for my next project. Is it being used in production anywhere besides your company?
- montmorency88 4y agoHey, at Comhlan Ltd. we have a few projects in production built with IHP. The largest public facing one is a visitor booking system for an irish regional hospital group we've had out since January. Happy to answer any questions but short answer is GHC+nix+IHP has made for a really robust development/deployment experience. (Disclaimer: I'm founder of Comhlan and we are a IHP platinum partner as well).
- agumonkey 4y agoThis is worth a 2h talk :)
- dustingetz 4y agoSo, how do I get a sane Haskell editor environment on MacOS?
- cosmic_quanta 4y agoYour best bet is probably to use VSCode + Haskell plugin, version 2.0+ (which handles the installation of everything via GHCup, I believe), barring any macOS-specific problems I don't know about. That's the setup I use on Windows and Linux, and it's great
- _query 4y agoCheck out this video on how to use VSCode with IHP https://www.youtube.com/watch?v=_8_8XYO6rgY https://www.youtube.com/watch?v=_8_8XYO6rgY
- chrsig 4y agoInteresting, I hadn't heard it adopted a dot notation. Does this mean you can have different records with the same field names now?
- rowanG077 4y agoYou can already have different records with the same field with the "DuplicateRecordsFields" extension: https://ghc.gitlab.haskell.org/ghc/doc/users_guide/exts/duplicate_record_fields.html https://ghc.gitlab.haskell.org/ghc/doc/users_guide/exts/dupl... What is meant here is that instead of writing `fieldName record` you can write `record.fieldName` mirroring imperative language.
- oconnore 4y agoI think of Haskell along with other languages that allow for shipping small, single-file binaries with a garbage collected, high level language. The straightforward alternatives I'm aware of include Nim, OCaml, Crystal, and Go. Go is the most popular of this set, but to me seems like it barely qualifies as "high level". On Tiobe, the next most popular language from this set after Go is Haskell. I like Haskell just fine, but what I really care about is "a more high level GC'd language than Go that ships binaries".
- leonidasv 4y agoWhy do you think Go "barely qualifies as high level"?
- oconnore 4y agoI think it's trying to stay fairly close to C, with additional features selected judiciously. Systems programming was identified as an important design goal (e.g. having close control of memory layout). See also: https://en.wikipedia.org/wiki/Go_(programming_language)#Omissions https://en.wikipedia.org/wiki/Go_(programming_language)#Omis...
- philjohn 4y agoI work for one of the companies on the list, and touch Haskell every now and then on the job - maybe it's because I worked with quite a few functional languages when I studied for my degree (Artificial Intelligence, started in 1998), but I really really enjoy it.