5 ms·
Show HN: Hashmap.me – Simple HTTP-Based Data Storage and Retrieval
I'm excited to share Hashmap.me, a small tool I've built to simplify data storage and retrieval. It's a straightforward service that allows developers to store data records via HTTP requests and retrieve them easily, all without the hassle of setting up and managing a database. Initially I built this because I was tired of creating a database to prototype my own projects, I just wanted to persist my in memory cache between restarts early on.
Each hashmap you create corresponds to its own collection in MongoDB.
Perfect for small projects, quick prototypes, or learning purposes. I'd love to get your feedback and hear your thoughts!
Check it out here: https://hashmap.me https://hashmap.me
Thanks for taking a look!
- mlhpdx 3y agoI really like the simplicity of this and the approachability for students. If I were still teaching CS I’d be using it as part of the curriculum. Do you support conditional GET AND PUT (i.e. eTags)?
- MrRowTheBoat 3y agoHey! Thanks for checking me out. I do not currently support anything like that, however I think you bring up a very good point, and it could be very beneficial. One could however add their own lastModified variable as a part of the json blob they push up and implement the support themselves. From your teaching perspective of course, that may not be a great experience for the students.
- mlhpdx 3y agoYeah, there are very few APIs that support conditional requests but they’re super important topics and it’d be great to have a way to demonstrate them.
- MrRowTheBoat 3y agoAppreciate the insight, I'll consider it!
- politician 3y agoSecurity people: What are the odds this becomes part of the command and control chain for a botnet in the next 30 days?
- RockRobotRock 3y agoSo what? I could C2 a botnet right now with base64'ed hacker news comments. You don't need a captcha to register an account.
- Retr0id 3y agoHN has a system for reporting and responding to abuse.
- RockRobotRock 3y agoYeah I feel you I'm just trying to point out the fact that there are a lot of ways to read and write arbitrary data pseudo-anonymously.
- Retr0id 3y agoAs a one-off there are many ways, but if you want to scale things up then you run out of options pretty fast. OP potentially just made themselves the new lowest hanging fruit.
- RockRobotRock 3y agoGood point.
- japanman185 3y ago[dead]
- mlhpdx 3y agoSo rate limiting on GET, then, too? How would you prevent abuse while keeping it simple?
- WhitneyLand 3y agoI think it’s pretty cool. It’s got that HomeDepot tool aisle vibe of being appealing even if I don’t have an immediate use for it. For a second I thought it would be nice to not auto append a UUID to the hash, but I can imagine it’s simpler not having to check for or manage collisions.
- MrRowTheBoat 3y agoAgreed, I think a fuller version could require authentication and then you'd be able to have whatever name you want maybe?
- pdanpdan 3y agoWouldn't it be more semantically meaningful if you would use "...api/store/<hash>" with GET and PUT? That way you would also get better caching.
- MrRowTheBoat 3y agoI like your idea of switching the endpoint specifically for caching, would be a great improvement for the service. This does run on Next.js which offers some sort of caching out of the box. When it becomes a problem, it will definitely be necessary. Thanks for the suggestion!
- hlesesne 3y agoCouldn’t this just as easily be a front end to an object store like s3 - without the need for mongodb?
- MrRowTheBoat 3y agoYes! This could be done in many different ways with different technologies.
- MrRowTheBoat 3y agoAnnnnnnnnd someone just infinitely created a bunch of empty hashmaps and maxed out my collections. :) Thanks HN <3
- deleted 3y ago[deleted]
- MrRowTheBoat 3y agoDeleted 255 collections. Investigating throttling of some sort...
- tony-allan 3y agoI would love some feedback on the imagative ways the service has been abused since you created it.
- MrRowTheBoat 3y agoSo far the worst thing is that someone is trying to actively stop my service from being functional? Idk, I guess it's more fun than other things? Anyways they mass created hashmaps using UUIDs. Someone lower in the comments made a great point on this, unfortunately this is why people have to crack down on things and require accounts and stuff like that before you can use a service. :) Service is up and running, but we'll see for how long.
- tony-allan 3y agoGreat idea putting all actions behind a token. This removes most types of abuse. Still, a great place to backup my video library! I once thought about doing this using RDF/Tuple based data where most elements are forced to be UUID-4's (whose purpose and meaning are invisible) except for values. I imagined a public service without a token.
- tony-allan 3y agoI would like to see being usable from a browser (with the key, value and token as query parameters): https://hashmap.me?key=key1&value=value1&token=tony-test-d873b5e5-6986-4c27-904c-e5713002e5cd https://hashmap.me?key=key1&value=value1&token=tony-test-d87...
- MrRowTheBoat 3y agoThanks so much for the suggestion and checking me out. I think for Read it makes a ton of sense to be able to provide a key to only get that specific key from your dataset. I could add support for allowing you to use your token in the url to avoid headers, but to be very clear that token should NEVER be exposed to other users or to the public, that token isn't changeable, and if another user has it they can modify your dataset. Maybe I could add read only tokens at some point? With your exact URL above, are you proposing the ability to Write data from the browser? I see you're providing a value so it lead me to believe you're suggesting writing a key/value pair with your token from the browser
- debarshri 3y agoYou probably should add some rate limiting on the API.
- MrRowTheBoat 3y agoI added a simple rate limit last night, thanks for your suggestion! :)
- MrRowTheBoat 3y agoHmmm, it looks like the post is flagged. I had to look up what that meant. I'm guessing I may be breaking the rule of including the website name in the title of the post. :(
- chaz6 3y agoHow can I retrieve a single key? As far as I can see, the only read api available returns all keys.
- MrRowTheBoat 3y agoHey chaz! Currently not an option, and as I write that out, you're right that it should be an option. Even if it was something like "/api/read?key=getOnlyThisKey" which returns your value or perhaps a 404 or maybe a 204, implying your response was succesful, but there was no key with the specified requested key.
- rickydroll 3y ago[Nick Haflinger has entered the chat..]