3 ms·
I first heard about Ent on HN about 2 years ago. At the time I was evaluating every ORM in Go to find something that would fit the bill and Ent happened to be e
by ivanvanderbyl 4y ago
I first heard about Ent on HN about 2 years ago. At the time I was evaluating every ORM in Go to find something that would fit the bill and Ent happened to be exactly what we needed. We've now been using it for 2 years and it's been one of the best bets we made on a technology choice.
Things that have worked really well:
* Auto DB migrations using Ent+Atlas. Ent implements a lot of great low level defaults that I just don't want to need to think about (foreign key constraints, indexes, naming of join tables etc)
* Generating our GraphQL API from Ent Schema
* Generating Protobuf definitions for internal tools to talk to (now using Buf for the actual tooling, but having the protos generated saved a huge lot of time).
* Being able to quickly craft really complex multi-edge joins without really thinking through the SQL allows for quick implementation of new features.
* Query optimizations such as using WINDOW clauses for pagination in GraphQL queries (I wouldn't have even thought this was possible).
* The generated code is quite a lot of lines, but it's really nicely structured and idiomatic, making it easy to extend.
There's been heaps of other neat finds along the way, but that's a summary.
Shout out to Ariel and Rotem for being excellent stewards of the Ent community and helping us solve some complex problems along the way.
- lordofgibbons 4y ago>* Generating our GraphQL API from Ent Schema How do you make sure you don't accidentally expose an-authorized data to the user with auto-generating GraphQL APIs? Does Ent have built-in authorization validation?
- ivanvanderbyl 4y agoI should have mentioned this, Ent has built in authorization at the row level: https://entgo.io/docs/privacy https://entgo.io/docs/privacy There are some gotchas with this, but like all auth you need to take the time to think through it and once you do it is extremely powerful. This approach means you can essentially forget about needing to scope queries to specific users throughout your codebase as Ent will automatically apply that part of the query wherever it is needed. I know there's been some comments on this thread and others about coupling auth to your ORM, I think it's necessary as it's otherwise too easy to forget this somewhere deep in your code and accidentally expose everything to the wrong user.
- rotemtam 4y agoThanks for the kind words, Ivan! You're awesome