14 ms·
Htmx Is a Erlang
- masfoobar 3y agoMaybe I am missing something, here. Generally speaking - when you make an HTTP request - you are likely returning: XML <root> <users> <user> <id>1</id> <name>foo</name> </user> </users> </root> [or] JSON { "users": [{ "id": 1, "name": "foo" }] } [or] HTML: <div class="users"> <div class"user"> <span class="user-id">1</span> <span class="user-name">foo</span> <button class="btn btn-small">edit</button> </div> </div> [When using HTMX, you would add some additional tags. You are still just returning HTML] <div class="users"> <div class"user" hx-target="this" hx-swap="outerHTML"> <span class="user-id">1</span> <span class="user-name">foo</span> <button hx-get="/user/1/edit" class="btn btn-small">edit</button> </div> </div> What makes this anymore (or any less) dangerous? What is the problem? I guess responses is more in line with -- "they tooook our jooooowbs!" From what I read elsewhere. "React creates jobs. HTMX doesn't"
- eddd-ddde 3y agoThe whole "htmx is the most dangerous thing to exist" is so funny to me. Someone that does not understand sanitisation boundaries has no business working on web development. This is how you end up with html in your database, people just render whatever piece of data because it "just works" in frameworks like react (I've seen it myself in production).
- moritzwarhier 3y agoReplace htmx with alpine js and I think the twitterers have some point. Eh, probably even with htmx. It is true that the average WordPress developer might not care about XSS, and to refute one specific point: I have seen third-party returning HTML, plenty of them. Deliberately acting on the contents response instead of directly executing code from said party forces you to think about XSS. But it's not specific to htmx of course, it would be the same when using innerHTML or something while using a field in a JSON API response. It's true that frameworks like React have safer defaults than Vanilla JS in that regard.
- nesarkvechnep 3y agoA Erlang, yeah…
- jlundberg 3y agoThis read has a surprising amount of depth and funny style. Recommended if you enjoy conversations about web security.
- aidenn0 3y agoYMMV: I agreed with the points, but found the depth to be rather minimal and the style to be completely off-putting.
- ahmedfromtunis 3y agoThe style is rather confusing, and hinders comprehension rather than improve it. The text jumps from one topic to the other so abruptly that I had to check multiple times if I'm still reading the same article.
- ezekg 3y agoIt also jumps between relevant embedded tweets and irrelevant tweets, which I found hard to comprehend. I guess I'm just not jiving with the author's thought process.
- coolhand2120 3y agoReading that entire thing was a struggle. Really feels like _everyone_ is wrong here. Yes the current state of FE development is overly dogmatic and cultish. But it always has been. On the other hand the frameworks and build systems are solving actual problems, they're not there for looks. 5-7 second skeleton loaders are there because backend systems are slow, not because of the front end application. You can say "oh but you can pre-render", but there are times when you can't. You could render the whole thing on the backend, but then you'll wait 5-7 seconds at a white page vs. progressive loading. Whatever is taking 5-7 seconds (LCP) is not going to get faster for you in your region by some magical front end dance. Not every business is the same and no one solution will work for everyone. And concluding that we should "go back to jQuery" really speaks volumes of the author. jQuery was not "the good old days". The problem with FE is that they seem to be wannabe nodejs BE devs instead of the W3C experts they should be. If FE devs focus on web standards and less on Rube Goldberg machines they would be well served.
- shakabrah 3y agohere here. I am very thankful that when i started out a decade ago the first book i read was Designing with Web Standards. I still recommend it to noobs but i can’t necessarily blame them for not getting through it when there are more shiny things like React and Vite to learn about. To read that book now would be largely a history lesson because we no longer have to fight to maintain some quirk between a handful of browser versions. But man, knowing about semantic markup and really getting why that is a thing in the first place is super important.
- felixgallo 3y agothere is no way any competently written back end system takes 5-7 seconds for any reason whatsoever. A middling back end system with median complexity is doing 10-100K requests per second per server and is near-perfectly horizontally scalable.
- herrkanin 3y agoNot everyone has the luxury to work with competently written backend systems.
- moritzwarhier 3y agoReally enjoyed the tangents and the point makes sense. I hate idiotic frontend hate and I am not a fan of htmx, but I still like its approach - if it makes sense for the website. I think every developer who has worked using a CMS using traditional templating + "ajax" has reinvented parts of it at some point in their career. At least I have. If I would find myself in this scenario again, I'd gladly reach for htmx. Apart from the social media observations, topics tend to be random here, but I like train-of-thought writing.
- slj 3y agoThe jab at pg referenced in the tweet screenshot’s caption was quite funny
- qwertthrowway 3y agoAlso, check out elixirs EEX (a mix of erlang and htmx, in spirit)
- _dain_ 3y agoyou know I think this guy doesn't like elon musk. just a feeling
- camdenlock 3y agoIt’s very trendy
- davedx 3y agoIt's powerful to have your front-end library automagically run code returned by your API, sure. But you can't hand-wave the security concerns of that away by ridiculing the people trying to discuss them. There is a fundamental difference between your server returning data versus returning code. If you don't want to accept that, fine, it's your project, or career, whatever. But if you conduct extensive ad hominems against people (I'm not a fan of "Devrels" but jeez, that part of this post felt like blatant character assassination) instead of just debating the facts then you're a douche and no better than the people you're disparaging. I think HTMX is an interesting project that I'll probably give a try at some point. But breathless cultish hype of it has already turned me off. I don't even know if React got this much attention!?
- aidenn0 3y agoYour server already returns code if you are running javascript on your frontend. Your server already returns arbitrary html (which can include executable code) unless you are running a fully static backend. HTMX moves where the trust boundary is a bit, but it doesn't change that it exists at all.
- couchand 3y ago> But you can't hand-wave the security concerns of that away... What security concerns, exactly? > There is a fundamental difference between your server returning data versus returning code. If my server returns a bit of something, and then my application code running in the browser takes conditional action based on that return value, was it data or was it code?
- davedx 3y agoSeriously? It’s data. Unless your client and server are Lisp
- nightlyherb 3y agoSecurity-wise, how is a server returning HTMX any different from a server returning HTML with forms? The clients both have the same capabilities, no?
- sshine 3y ago> also, 25,000 hours in 15 years? what kind of rookie lazy piece of shit numbers are those? [...] Since we're bashing dumb comments with dumb comments, the Twitter comment is actually saying: over 25,000 hours Assuming - 5 weeks of vacation each year - 8 hours of work, 5 days a week That's (52 - 5) * 5 days * 8 hours * 15 years = 28.200 hours If he worked any harder than that, that's still over 25,000 hours.
- snowstormsun 3y ago> ah yes, the famous XSS coming from your own backend API calls… Author does not seem to understand the concept of XSS. Of course your own API could return user-provided data to trigger XSS attacks. Entering <script>alert(1);</script> in a messenger to see whether its rendered value is escaped correctly is a famous example.
- andrewflnr 3y agoHence the mentioned hx-disable. Presumably you wrap any user content with that, right?
- snowstormsun 3y agoMaybe I missed that
- freen 3y agoIf that’s the case, and your backend doesn’t sanitize inputs, you’ve already been owned, regardless of your front end framework.
- kitd 3y agoYou missed the response though, that the same user input would also cause problems if it was supplied unsanitized via JSON.
- miki123211 3y ago> htmx, a disciple of hypermedia, available only in hardcover do not look for alternatives, has been manifesting itself into existence recently As a screen reader user with no way to read words written on paper (short of getting a scanner and spending hours on putting books through it), I have to look for alternatives. I hate it when authors do this. I get why, but it's still frustrating. There's also the fact that the author of this article decided to embed X posts as unlabeled screenshots for some unknown reason. This breaks accessibility, copy/paste, translations, flexible screen layouts and probably a bunch of other things I'm not aware of. Putting text in images is never a good idea, much less so when there's a perfectly fine embeds API for GOd's sake. I'm really saddened to see somebody who claims to care about web standards be so dismissive of accessibility concerns.
- thraxil 3y agoI don't know what they're talking about with "available only in hardcover". Hypermedia Systems is here: https://hypermedia.systems/ https://hypermedia.systems/ available in HTML online, ebook format, hardcover, or you could go to the github repo and probably transform the source into whatever format you want: https://github.com/bigskysoftware/hypermedia-systems https://github.com/bigskysoftware/hypermedia-systems X posts as screenshots suck though.
- throwitaway1123 3y ago> htmx, a disciple of hypermedia, available only in hardcover do not look for alternatives, has been manifesting itself into existence recently I think this whole sentence was meant to be a joke. This "article" is filled with juvenile humor, random tangents, and twitter screenshots. The irony of complaining about people not properly using hypermedia while omitting some of the basic accessibility attributes of hyper text markup language (alt text) is astonishing.
- troupo 3y agoI find all the marketing, advertising intentional or not, around HTMX really obnoxious. Does it have its merits? Maybe? I don't know, I can never get past the memes and shit-slinging. Or past them superficially co-opting terms they have nothing to do with like Erlang, or hypermedia. It's a toy mascarading as a serious tool.
- meowtimemania 3y agoHTMX is really pleasant to work with and in many cases means getting stuff done with way less code. I have an internal tool built with React and replaced it with HTMX. The HTMX version is much simpler and easier to add features. HTMX doesn't make sense for all use cases, but sometimes it's all around a better choice than something like React.
- c-cube 3y agoIt's related to hypermedia though? The whole point is to go back to servers returning hypermedia (ie html) instead of json. How is that not related?
- troupo 3y ago> is to go back to servers returning hypermedia (ie html) This has nothing to do with hypermedia. You can return json, xml, pdf, or binary and be 100% hypermedia-driven.
- recursivedoubts 3y agoif you want to just have a serious look at htmx, I recommend the book, which is free online: https://hypermedia.systems https://hypermedia.systems i am willing to admit that i get a little wild on the ol' twitters and understand if that isn't everyone's cup of tea (otoh, you probably wouldn't have heard of htmx if i went at things the normal way: i'm a solo dev in montana.)
- troupo 3y agoYes. I skimmed through that. It has nothing to do with hypermedia.
- gabrieledarrigo 3y agoLol, I dunno who this dude is, but it was very funny. Ps: Nathan James, pls stop