4 ms·
> After working on several products through my career I found that we spend way too much time on building API backends. Most APIs also need constant updating, a
by justsomeuser 4y ago
> After working on several products through my career I found that we spend way too much time on building API backends. Most APIs also need constant updating, and this costs time and money.
> It's always the same thing, figure out what the UI needs then build an endpoint for it. Most API code involves struggling with an ORM to query a database and mangle the data into a shape that the UI expects to see.
Most business API's have business specific per user read/write access roles.
I am starting to think that a better solution to GraphQL and other DSL's is to:
- A. Make the iteration speed of adding a new plain HTTP endpoint very fast.
- B. Use a typed language, and some kind of macro to extract the types into an Open API spec.
This way everything is just a regular function in your general language:
- http_handler(request) -> response
- user_has_access(user, resource) -> bool)
etc.
Regular functions have no external dependencies, are easy to understand, edit and stand the test of time better than DSL's.
If GQL does what you need out of the box, it seems a win. But I would assume some endpoints need to fall back on the above approach anyway giving you a mixture of GQL-generated and hand-written handlers.
- strbean 4y agoSounds close to FastAPI[1]. Anyone know of equivalent / better frameworks in other languages? [1]: https://fastapi.tiangolo.com/ https://fastapi.tiangolo.com/
- martypitt 4y agoWe build Taxi (https://taxilang.org https://taxilang.org), which is the type system for APIs, and then Vyne (https://vyne.co https://vyne.co) which uses that types to automate all the plumbing. It's pretty close to what's being described here, and removes the boilerplate in API orchestration.
- samarthr1 4y agoHow is taxilang different from openapi? Does it have client code gen capabilities?
- mirekrusin 4y agoWe use not so much frameworks but combination of lightweight libraries: - runtime assertions [0] - to map unknown values at i/o boundary into statically typed code (rpc input parameters, sql results etc) - template based sql combinators to sanitize sql/generate sql [1] - jsonrpc over websockets - for bidirectional comms between f/e and b/e It works very well for us for hundreds of rpcs - it's easy to manage things like permissioning/narrowing visibility and other aspects you need in business/enterprise-like setting ie. performance monitoring is very easy/straight forward. [0] https://github.com/appliedblockchain/assert-combinators https://github.com/appliedblockchain/assert-combinators [1] https://github.com/appliedblockchain/tsql https://github.com/appliedblockchain/tsql
- astockwell 4y agoHaving used APIs from SOAP to REST to GraphQL and back, I would agree. It got to the point in a recent project (written in Go) where just slapping another endpoint on, even with fairly particular nesting depth, was a 5 minute ordeal. That contrasts in my mind against another recent project using interpolated GraphQL which has been a struggle on almost every front: struggle to CRUD data, struggle to fetch certain corner cases, struggle with the performance/mem usage of the autogenerated graphql -> sql translation, struggle to bolt on custom graphql handlers for things not mapping neatly to models, struggle to debug/test, on and on. Just write a goddamn JSON handler.
- cyanydeez 4y agoPostgraphile allows for user roles,etv
- coredog64 4y agoThis is where something like OPA shines. Given a context, you can make an up-or-down decision as to whether or not the request is allowed. Then your not having to wedge security into your ORM reshape code.
- eandre 4y agoI’ve been building [1] for the past few years and it’s pretty close to what you’re describing (and also does much more). [1] https://encore.dev https://encore.dev
- klysm 4y agoI think tRPC.io works well for this, but haven’t used it for anything big. Curious what other folks think of it.
- eurasiantiger 4y agoThat assumption is wrong. GraphQL can deliver auth, file downloads, even streams.
- gsvclass 4y ago+1 to that additionally there is nothing like subscriptions, defer, async on the REST side of things. These are really great capabilities to have towards building snappy data rich apps.
- gsvclass 4y agoGraphJin can be used within your own http handlers (REST) sort of like an ORM. Or you can use the @script directive to add a JS script to handle the before and after of the request. Here's an example of a relatively complex query that you'd need when building something like a blog. GraphJin will compile this nested query into a single efficient SQL statement. https://gist.github.com/dosco/f604c47c1d643fb62072f62c4f6f7072 https://gist.github.com/dosco/f604c47c1d643fb62072f62c4f6f70...