5 ms·
What some people seems to forget is that doing something simple is simple in every lang with any framework. Can we have a sample with allowed hosts, cors, auth
by AtNightWeCode 4y ago
What some people seems to forget is that doing something simple is simple in every lang with any framework.
Can we have a sample with allowed hosts, cors, auth, input validation, open api docs, request logging with true IP addresses, XSRF/CSRF attack protection and so on?
- TacticalCoder 4y ago> Can we have a sample with allowed hosts, cors, auth, input validation, open api docs, request logging with true IP addresses, XSRF/CSRF attack protection and so on? The 2000s called and want their "Pet Store" back!
- AtNightWeCode 4y agoAn API first "Pet store"? ;) It is pretty much industry standard within the C# and Java community to provide Open API docs. It also displays the flaws of the API designs at an early stage. Stops one from going live with something embarrassingly bad as the Hashicorp API:s for instance.
- synthc 4y agojokes aside, this is all pretty much required functionality for mature applications
- stuntkite 4y agoI had not pushed a project public in a while and recently had to kick something off and I hadn't been testing fully to get things into open space. CORS/CSRF and really getting my head back in the space of SSL being properly handled took me way longer than I'm comfortable to admit. These are things that I consider myself fairly comfortable with but chops had atrophied and browser enforcement leaves less wiggle room for failure. Also static file management really tapped me in my nuts. It's really easy to think you've got it all figured out when it's just running on your local machine or a private network or to quote Mike Tyson "Everyone has a plan until they get punched in the mouth." This experience has reinforced for me how critical getting CI/CD is to the process of taking something from a sketch pad to something that no only ships but other people can work on. Not saying that has to be a huge production, but it's just as crucial as how to post a form or connect to a data source. Looking at you JS bros that think they can cobble together an ORM that won't be a massive chore.
- harryvederci 4y agoMost of what you're asking for is described in the docs, with examples. If you're looking for an example project using Joy, I think janetdocs[0] may be a good example. Some Janet experience may be good before diving into that repo, because it imports Joy with `:prefix ""`. Also keep in mind that 99% of this seems[1] to have been made by 1 guy (Sean Walker), I think in his free time. [0]: https://github.com/swlkr/janetdocs https://github.com/swlkr/janetdocs [1]: https://github.com/joy-framework/joy/graphs/contributors https://github.com/joy-framework/joy/graphs/contributors
- AtNightWeCode 4y agoFair. But when I click the docs link on the page I get 89 lines...
- harryvederci 4y agoHmm I see, that link may be a bit unfortunate, as it only shows the introduction to the docs. More pages are here: https://github.com/joy-framework/joy/tree/master/docs#readme https://github.com/joy-framework/joy/tree/master/docs#readme PS: I did a very minor contribution to Joy once, so minor that I actually forgot about it :) I don't use Joy myself at the moment as I'm using my own framework, but the Joy docs + source code helped me out a lot in figuring out how to do authentication, csrf, etc!