4 ms·
I’ve been programming ~15 years, and from my perspective, those frameworks helped us move on from a world riddled with XSS, “better than fail whale”-level relia
by progrus 4y ago
I’ve been programming ~15 years, and from my perspective, those frameworks helped us move on from a world riddled with XSS, “better than fail whale”-level reliability expectations, and software ossification (Gmail, Facebook, etc).
Today, the frameworks bite me in the ass about once a week, but I think it’s worth it to get safe React with strict TypeScript, and plenty besides.
Caveat: All infrastructure requires a lot of maintenance, though! YAGNI still applies, and hopefully you have (or are on) a team dedicated to supporting the tools that you do need.
- chrischattin 4y ago??? XSS has long been a solved problem. Security is definitely not an argument for using front end JS frameworks as they add attack vectors and complication to the stack.
- progrus 4y agoIs your solution something like “always remember to sanitize user-generated content”?
- dc-programmer 4y agoIt’s definitely not a solved problem. Most developers absolutely would not escape their outputs if left to their own devices
- shadowgovt 4y agoAssuming your entrypoints are typed, TypeScript makes it much harder to accidentally mishandle data of the wrong type and frameworks make it much harder to inadvertently change state at a distance in a way that was unintended. These are the two most common ways that undesired behaviors are introduced to JavaScript UIs.