4 ms·
> static websites This is a nice intention and would be great for security. It works fine for displaying opening hours and upcoming events, etc. However, as so
by jamesrr39 3y ago
> static websites
This is a nice intention and would be great for security. It works fine for displaying opening hours and upcoming events, etc. However, as soon as you want to search for books, or you want some log in feature to see which books you have loaned out and when they need to be returned, it's clear that a purely static site just doesn't cut it for today's expectations.
- Lacerda69 3y agoSorry the dumb question, but why not? Can't I make a static page that offers search (reload on every query with results) or profile (reload every time soemthing is changed in the profile)
- chrisandchris 3y agoI think your understanding of "static" website is off. A static site does not have any backend, thus cannot provide you with search results because it cannot do any computing at all (just provide you the same (static) content again and again).
- deleted 3y ago[deleted]
- benterix 3y agoActually some subset of this functionality is possible with static or semi-static pages but actually the problem is not so much about a page being static or dynamic but about being read-only vs getting user input. As soon as you need to deal with user input, there are inherent security issues. You can go around these by having some presets in the profile and providing cached results for the most common search types but this is more or less as far as you can go.
- fieldcny 3y agoThis is incorrect, any request made by a browser to a backend will by definition accept user input whether it wants to or not. I can change the values of the presets I can add headers, remove headers change the value of cookies, add cookies, remove cookies etc etc.
- benterix 3y agoStrictly speaking, you are correct. But in this case dealing with user input such as headers and their modifications is the responsibility of the server just like dealing with potentially malformed HTTP replies is the responsibility of the browser. What we are talking here though is the possibility of interaction with the remaining elements of the system (application, database). If these are read-only, the attacker loses these attack vectors.
- johngladtj 3y agoAny reason it can't just have a JSON page somewhere, and then the search simply be a JavaScript app that looks through that static JSON for all the entries that contain a given token in it's list of keywords? Most people don't need overly complex searches...
- LorenzoGood 3y agoThat would be so slow