3 ms·
> And no — type safety is applied at the HTTP interface. So it's basically validation middleware. The HTTP protocol does not define any such thing.
by codemusings 3y ago
> And no — type safety is applied at the HTTP interface.
So it's basically validation middleware. The HTTP protocol does not define any such thing.
- jfengel 3y agoNo, and neither does Typescript. One of the biggest weaknesses in Typescript is that it can't validate data across the wire. Which is a major use case for the language. There are various tools for it already, but the JS ecosystem has always been up for yet another framework.
- r3trohack3r 3y agoI hear you, but I don’t think this is necessarily true. It does leave type checking to your parsing logic, but the compiler can give you strong guarantees that you’re being defensive about untrusted structured data. I use a JsonObject to do type narrowing and generate appropriate error messages when I receive invalid data over the wire: https://www.npmjs.com/package/@retrohacker/json-types https://www.npmjs.com/package/@retrohacker/json-types In every codebase I’ve added this to, I’ve found invalid parsing logic. I feel like this type, or something similar, should be bundled in the official TypeScript project. That untested data comes out as “any” is not a good developer experience in my opinion. And “unknown” is basically broken for type narrowing.
- madeofpalk 3y ago> And “unknown” is basically broken for type narrowing. How? Typescript 4.9 improved it for type narrowing significantly. https://devblogs.microsoft.com/typescript/announcing-typescript-4-9/#in-narrowing https://devblogs.microsoft.com/typescript/announcing-typescr... Last weekend I actually hacked an an experiment to codegen narrowing unknown to a specific type and it works pretty well https://github.com/joshhunt/codegen-json-validator-experiment/blob/main/output.ts https://github.com/joshhunt/codegen-json-validator-experimen...
- r3trohack3r 3y agoI haven't worked much in typescript over the last 10 months, but last time I tried type narrowing on untrusted data typecast to unknown I ran into a handful of problems documented here: https://github.com/microsoft/TypeScript/issues/25720 https://github.com/microsoft/TypeScript/issues/25720 Working with untrusted types in a GraphQL project lead me to creating that JsonObject module. I wrote up what I was thinking at the time here: http://www.blankenship.io/essays/2022-12-01/ http://www.blankenship.io/essays/2022-12-01/ Maybe this has improved.
- madeofpalk 3y agoYes. The main one is `foo in obj` now correctly narrows to `unknown & { foo: unknown }`. This allows you to correctly narrow an unknown to a fully typed object, as my code sample shows :)
- beders 3y agoThe compiler can't help you at all when reading and validating data at runtime. You mean you could use a library that helps you with checking the shapes?
- r3trohack3r 3y agoThe compiler will tell you when you are accessing data you haven't validated yet. Using the json-types module above, you assign your incoming json object to the JsonObject type. Then you type narrow by validating the payload contains the properties you are using. So you can: const user = (await body.json()) as JsonObject; // This is properly type narrowed and will work if (typeof user.emailAddress === "string") { // do something with user.emailAddress } // The compiler will let you know you can't trust // user.name to be a string at this point. This // would have generated an exception at runtime // for a malformed payload if the compiler didn't // catch it. user.username.split(" ") // You can also do type narrowing with early returns if(typeof user.age !== number) { return new Error("user.age is expected to be a number"); } // You can now use user.age with type safety ```
- codemusings 3y ago> No, and neither does Typescript. One of the biggest weaknesses in Typescript is that it can't validate data across the wire. Which is a major use case for the language. Not sure what particular use case you have in mind but which language has built-in functionality to validate chunks of bytes without some kind of type definition? To me this is an orthogonal problem to language design. Every web framework has to serialize and deserialize data. What I was getting at is that TypeScript is perfectly suited to define type safe data structures wihtout reinventing the wheel. If you're going to parse type definitions for your validation middleware you might as well use something that can also applied to your business logic.