9 ms·
This is a nice overview of modern front-end development but I'm constantly disappointed with what 'web framework' means in node-land. None of these things are s
by moojd 4y ago
This is a nice overview of modern front-end development but I'm constantly disappointed with what 'web framework' means in node-land. None of these things are strictly necessary when building a web app but authz/authn, user management, databases, server-side logic vs client-side logic, are pretty much always needed. When I see the phrase 'web framework' these are the things I am interested in seeing and they all seem to be treated as afterthoughts in the node community. Most tutorials either point you to paid/proprietary services or to really bad local solutions like back in the hotscripts days of php. If you google 'node user login' the first tutorial has you storing a password in plain text and checking the password with the equivalent of '=='. The first result when googling the same for php, python, and ruby all returned solutions using a hash.
- tofuahdude 4y agoIts pretty hard to trust a lot of the eng content on the web right now; so much blogspam, self promo stuff from frankly underqualified people who are trying to build up a profile to get hired. Somehow I still don't feel that way about StackOverflow. Google and random results though... yikes.
- your_username 4y ago
- aliqot 4y agoUntil now I had not found an eloquent way to express that emotion, but you come close. Somewhere around the time node got very popular, I started to notice a lot of impeccably branded (is that the right word? trendy maybe?) websites with tutorials that used all the right buzzwords to get me interested. Once I'd step through the content, it'd be very low quality. Despite the smooth lines and round edges, a lot of them were riddled with inaccuracies, assumptions, unabashed spelling and grammar issues, stolen content and lots of candid offtopic observations.. Not to mention they all loaded very slowly. I used to joke about it mockingly during the early node days that you could judge the trajectory of a project based on the ratio of bytes dedicated to persona and branding vs actual content. Anything passing the 1:2 ratio generally didn't last long.
- moojd 4y agoI am optimistic though. We are still in the early days of server-side javascript. It took 20 years for the greater php community to coalesce around a handful of quality libraries, frameworks, and solutions to things like user management instead of everyone rolling their own or using things like '$_GET["pass"] == "foo"' they they grabbed from a google search. Node is barely over a decade old. We are already seeing patterns mature in the node ecosystem and I hope things keep progressing that way.
- lowercased 4y ago> It took 20 years ... Node is barely over a decade old. We are already seeing patterns mature in the node ecosystem and I hope things keep progressing that way. But... much of the earliest web work (PHP, etc) occurred in the early days of search. Example of quality code, best security practices, etc all were fairly .. rudimentary and hard to find. Just because it took 20 years starting 20 years ago doesn't justify 20 years starting from 10 years ago. There are infinitely more and better resources for just about everything these days.
- tannhaeuser 4y ago> early days of server-side javascript Err ... Netscape's LiveWire introduced server-side Javascript in 1996 even before Java became widely used on the server side. The module convention, the (synchronous) core modules of Node.js, and its canonical http middleware API and express.js/Connect/JSGI is from the CommonJS initiative, a co-op of 2000's SSJS framework developers [1]. [1]: https://www.commonjs.org/ https://www.commonjs.org/
- brentm 4y agoVery accurate. There was a time that I enjoyed this stuff but now it just takes too much effort to filter.
- ushakov 4y agothis 100% sometimes i Google stuff i already know just to verify i remembered it correctly lately i've been refreshing my memory on Vue JS and this website comes up a lot: https://thewebdev.info https://thewebdev.info the solutions i read there were often incorrect and misleading i can't imagine becoming a developer today, when most of the stuff you read on the internet bullsh*t of course you can browse the docs, but some docs are tedious to comprehend when all you're looking for is a simple one-line answer
- JustSomeNobody 4y agoIt's almost always been like that. When NoSql was the new hotness, there was blogspam and fistfights everywhere. When DI frameworks were the new hotness, there was blogspam and fistfights everywhere. I could go on. Devs see something new, learn enough to be annoyingly dangerous and blog like crazy. Other devs will glazed-eyed follow along because it makes their resume shiny.
- begueradj 4y agoMaybe that's the fault of those "who know" but don't write and contribute online ?
- Kerrick 4y agoThe only framework of that scale and quality I’ve found in node-land is Adonis [0]. It’s why I chose Adonis 5 for my latest product—it needed to be built in JS or TypeScript but I wanted the “batteries included” feel of Laravel or Rails. [0]: https://adonisjs.com/ https://adonisjs.com/
- ilrwbwrkhv 4y agoUnfortunately they just directly copy laravel line by line when I had last seen it. It doesn't use the strengths of JavaScript as much.
- jstummbillig 4y agoAny specific criticism?
- rk06 4y agoLaravel is awesome, and "laravel in js" sounds good. Perhaps you can point out issues or improvements which could be possible by leveraging these strengths if javascript?
- granshaw 4y agoIt’s also the most rails like node framework (is it still?), which emphasizes DX, expressiveness, convention over configuration, etc which in my book is a plus
- DanHulton 4y agoThis is largely why I built Nodewood [1]. Every time I wanted to start a new project, almost always a SaaS idea, I'd skip over the "boring stuff" like building user management, subscription management, teams, admin, all that, to get to the meat of the business logic, to make sure I had a valid idea. But I still needed all that stuff eventually, so I'd have to lose time later building it all in! So I decided to just build it all once so I could re-use it, and then I found that others had the same problem and are happy to pay a reasonable amount to have it solved for them, and now it's doing pretty okay for itself. It did end up taking a lot longer and involving a lot more work than I expected, but I figure that's alright, it just means a more-reliable base to start from each time. [1] https://nodewood.com https://nodewood.com
- rlyshw 4y agoIm building with featherjs[0] right now and I love it. Jwt, user handling, routing, and (most notably to me) real-time functionality is all built in. Probably the most rails-like backend framework I’ve worked with in Node so far. [0] https://feathersjs.com/ https://feathersjs.com/
- jacobsimon 4y agoSorry but that’s a pretty un-generous take on the state of the Node ecosystem. There’s so many mature solutions for all of these problems and tons of great examples online. That said, I agree that in the Vercel/Next universe, everything on the backend seems to be an afterthought.
- ksbrooksjr 4y agoThe fact that googling 'node user login' returns an insecure result is more indicative of the quality of Google's search results than it is of Node. Node has had a built in password hashing function since before it even hit version 1.0 (pbkdf2) [1]. It also has a built in timing safe comparison function for safely comparing values without leaking data via timing attacks [2]. The crypto module is actually pretty extensive. If you're looking for a traditional web framework (something similar to Flask or Sinatra) I would take a look at Hapi (which has no third party dependencies and is maintained by one of the original authors of the oAuth spec), or you could always try Express (the most popular Node framework), or Fastify (the fastest Node framework). [1] https://nodejs.org/dist/latest-v18.x/docs/api/crypto.html#cryptopbkdf2password-salt-iterations-keylen-digest-callback https://nodejs.org/dist/latest-v18.x/docs/api/crypto.html#cr... [2] https://nodejs.org/dist/latest-v18.x/docs/api/crypto.html#cryptotimingsafeequala-b https://nodejs.org/dist/latest-v18.x/docs/api/crypto.html#cr...
- DangitBobby 4y agoI am still holding my breath for a Node framework that does everything Django does for me. Honestly, we are most of the way there but for three holdouts; 0 config auth, easily extensible admin, and migrations. User stuff isn't so bad with bcrypt but I'd really like to be able to type `framework create superuser` and `framework create user` instead of fiddling with user access and re-imaging user groups and permissions for the hundredth time. Admin stuff always seems to be something relegated to a separate tool. No, please, please, please include it in the framework. Most frameworks have you choose your own ORM (which is fine if they consistently use the same one in documentation), but for some reason Node ORMS always treat migrations as an afterthought or second class citizen (if they even consider it). Changing table structures in development to add a new column? Half of them just say, sorry, we're going to have to blow that away. The rest have either manual migrations or partially automated migrations written in the SQL dialect you happen to be using during development. My favorite of the lot I've seen so far is Prisma and even they have recently indicated they don't want to support transactions in migrations because they don't want to give you a "false sense of security" (well yeah, how about a real sense of security?). To be fair, even in python land Django is really the only one to have ever gotten migrations 100% right.
- tomduncalf 4y agoThis is exactly why I used RoR for a recent freelance project which required a fairly simple (but full featured, user accounts etc) backend despite being a JS developer for the last 15 years and not really having any Ruby experience. None of the Node options seemed to cover all the bases and/or inspire trust, and I didn’t feel much like piecing together a bunch of random modules for a small project. Overall I guess it was a mixed experience, I missed the JS language (just because I know it well, Ruby has a lot more syntax) and Typescript but I liked having all the things like auth, migrations etc. which are not my speciality taken care of in a way that I could trust and easily Google thanks to it being so widely used. I’m not 100% sure if I’d make the same choice again, the mental overhead of going to a language I don’t usually use to make changes is a downside as is the lack of type checking (though I believe there are better options in the Ruby world now), but on the other hand I could do the whole thing with very little code (relatively) and it was a good experience to see just how much work a well designed framework can save you. I should add I did try Django but had my heart set on GraphQL (just because I wanted to try using it for real) and the options in the Python ecosystem didn’t scale well. Overall I liked Django’s ORM better and the Python language, but I felt like you got more out of the box with RoR, the ecosystem is higher quality, and I had to do fewer hacks to get stuff working. All depends on the scale of the project and how much code you want to write I guess.