10 ms·
Meteor releases authentication, accounts system, and new screencast
- ehutch79 14y agoI'm really glad auth finally got in this. With the biggest obvious stumbling block knocked off the list, I have some questions; Is this production ready? Should I be using this for a greenfield project? What is database access like? Postres, Mysql? SSL connections to mysql? what's a typical setup/deployment look like?
- norviller 14y agoI agree auth is a huge success, but no alternate DB support is a not starter for most I imagine. Any other non relational DB support would be a huge win, most people that I have talked to are blocked by Mongo's license.
- Skywing 14y agoNow I need to ask, what's blocking about Mongo's license?
- densh 14y agoHow in particular are they blocked by Mongo license? It's AGPL but it only applies to changes made to the database source code itself. It doesn't impose any requirements on your application if you are just talking to Mongo over the wire.
- norviller 14y agoIt is not unheard of for businesses in both the public and private sector to not allow AGPL code or use of applications released under this license. For example, I worked at a public library for years, and the policy was no AGPL, even if we had no intention of touching the source. Same for a local university. [Edit to add anecdote]
- densh 14y agoI know a few large scale corporations that license Mongo from 10gen including their commercial support. I really don't see any issue here. http://www.mongodb.org/display/DOCS/MongoDB+Commercial+Services+Providers http://www.mongodb.org/display/DOCS/MongoDB+Commercial+Servi...
- norviller 14y agoNot all people trying to use meteor have the money for commercial licensing / support.
- amalag 14y ago<sarcasm>Nice to see libraries and local universities are thinking ahead for when they want to modify the source code of their database </sarcasm>
- speg 14y agoIt's an early preview for a reason. That's why auth wasn't in til now. Not because it wasn't planned, but because the product isn't done yet. Wait for 1.0 before you start greenfielding.
- eranation 14y agoThe other top HN page article today doesn't add to my confidence in MongoDB so more persistence options will be interesting. But still, production ready or not, this can be an excellent MVP creator.
- vikstrous4 14y agoI know these guys have good intentions, but they seem confused about the guarantees that SRP provides. It does allow the server to verify the user's password without receiving it, but it doesn't help in any was against offline attacks. If the "password" (in this case verifier) database is compromised, the attackers will still be able to brute force the passwords. If they implemented it correctly, they will be salted, but this only makes the attack slower. Furthermore, nothing can protect you if your password is password. Also, I hope that they don't think this removes the need for SSL. It does not. In a web application the server sends the client the javascript to run. A man in the middle can modify it and defeat the whole point of SRP.
- saym 14y ago> Furthermore, nothing can protect you if your password is password. I'm not sure why you threw this line in with the rest of your response. I don't see what point you're making.
- vikstrous4 14y agoWhat I meant by that is that a brute force offline attack will always succeed if your password is easily guessable regardless of what hashing or password verification protocols are used.
- kzahel 14y agoI have an exercise: is it possible to create a javascript file (served over https) that, when included in a non-https HTML page, is able to determine whether any other scripts were included on the page or will be included on the page by a man-in-the-middle? If this were possible (I suspect it is not), then it might be possible to have secure javascript code running over a non-HTTPS url. (the motivation for this is to have some form of security and still be able to load websockets and make CORS xmlhttprequests to other (non-secure) hosts - with the assumption that these hosts may also be man-in-the-middled). For now, the only alternative is to use something like a packaged app, if you want to make sure your code is actually your code, and still be able to load insecure resources.
- hbbio 14y ago"Meteor 0.5.0, available today, allows you to write secure realtime client-server applications in pure JavaScript. It's the only system of its kind in the world." That's an outright lie. cf. http://opalang.org http://opalang.org
- ville 14y agoBut aren't Opa applications written in Opa, not pure JavaScript?
- vikstrous4 14y agoI also have doubts about the effectiveness of their security, so I'd like to challenge that part of the statement too.
- deleted 14y ago[deleted]
- Derander 14y agoFrom the linked page: client function client_function(x, y) { ... } This seems at least slightly different from "pure javascript". There are more examples on the page, particularly the neat sugar for database stuff. I don't think it's accurate to say that this is an outright lie.
- hbbio 14y agoOpa generates pure JS code, even though it's indeed a variant of JavaScript with some added features (the ones you mention) and some removed. But then, there's also Derby and probably others.
- Cogito 14y agoJust curious, as I don't know enough about the two, what makes Opa similar enough to Meteor that the claim "[Meteor is] the only system of its kind in the world" is an outright lie?
- norviller 14y agoDoes anyone know if the server code is being exposed to the client?
- rbn 14y agoThere are 3 types of code. Server only , Client only and both.
- myhf 14y agoLooks like they finally took the suicide joke off their homepage.
- leif 14y agoit's still blank unless you execute the javascript
- xutopia 14y agoWhat was the suicide joke?
- raimondious 14y agoThere was a guy who said something along the lines of "I'm going to slash my wrists if I have to keep doing web development the old way much longer!"
- deleted 14y ago[deleted]
- amix 14y agoBasing this on the screencast I think this looks amazing and they seem to be very productive. This said, I am unsure if this would produce codebases that are easier to maintain, since there is not a clear separation of concerns and everything seems to be connected. I think doing client-side JavaScript is hard and messy (even with Backbone or Ember) I could not imagine this would be any easier if I had to handle the backend on the client-side as well (especially a backend that's updated in realtime). This said, maybe the current struggle of the client side is because the data is on the backend and needs to be fetched, updated and handled using a client-server model. With Meteror the data seems to live on the client-side which maybe makes things easier.
- taude 14y agoAgree on all fronts. However, for getting something up and running, MVP, and for 99.9% of sites that don't need to scale past couple-hundred thousand users (just making up a small figure here), this type of solution might be more than sufficient... I don't know, though, but I do know that I'll keep following the project. They make great screen casts, and have interesting ideas.
- propercoil 14y agoalways when i see meteor i think it's the reverse polling comet server i used 2 years ago
- deleted 14y ago[deleted]
- davidlumley 14y agoWhile I'm not confident that being this tightly coupled to MongoDB is a great (or even a good) idea, I'm really glad to see Meteor get closer to 1.0 especially seeing as it's not another Rails clone. The other concern I have is how testable is a meteor/derby codebase? I don't think I could commit to using something in a team environment without being able to _easily_ test things.
- taude 14y agoBased on the way they were calling all the inserts and and data changing from the command line, it seems like testing wouldn't be difficult. Agree on the tightly coupled to MongoDB, though. Hopefully by the time it's released there's suport for traditional relational databases.
- rbn 14y agoI've used the Auth Branch for a few month now. You can see it in action at http://www.classfy.com http://www.classfy.com (P.S: make sure you have the "www", or else you wont be able to access the page)
- dylanpyle 14y agoIt's super confusing to have your 'naked' domain and www. subdomain point to different things. Clearly, it also requires you to explain it every time you post somewhere. What's the reasoning behind this?
- chrisweekly 14y agoThis is a huge milestone for a very, very interesting and ambitious project. I wish instead of nit-picking about the marketing language in a release announcement, people would take a minute to appreciate just how amazing this platform is becoming. Yes, ok, derby.js and socketstream and nowjs and opa and realtime-project-foo and etc, sure, maybe they are awesome too, but so what? Meteor is incredible, and contributing to this rising tide floating all the realtime framework boats. And that is something to celebrate imho. To the meteor team: high five, keep it coming, and thank you!
- prawn 14y agoI saw the following tweet from PG within the last hour and wondered if it was a reference to some tech company launch. Then I came here and saw this story. Still not sure... @paulg: "Did anyone else see a fireball heading east over Silicon Valley at 7:44? (Meteor?)"
- izak30 14y agoNope. That is in reference to an actual, physical event, not a startup. My guess is that it's related to this: http://menlopark-atherton.patch.com/articles/orionids-meteor-shower-2012-where-to-watch-in-menlo-park http://menlopark-atherton.patch.com/articles/orionids-meteor...
- prawn 14y agoAmusing coincidence then!
- nivertech 14y agoPg had a typo: it should be "Firebase" not "fireball" ;)
- zobzu 14y agoIf the auth is top of the art, why doesn't it have persona? :)
- leke 14y agoI'm still trying to figure out the difference and advantage to learning this over node.js.
- clux 14y agoPROS: it reduces the delays you have due to the paradox of choice CONS: it makes the choices for you
- jemeshsu 14y agoAre Meteor or Derby frameworks to be used on the premise that you have only browser clients? If my Meteor/Derby web app has server component, how easy it is to build native iOS and Android clients to access the same data on the server?
- marknutter 14y agoNot as straightforward as in other more established server-side frameworks, I assume. It's part of the reason I'm reluctant to ditch my server-side framework of choice (Rails) in favor of an all-encompassing solution like Meteor. There are more than just javascript clients that need to access my APIs.
- talleyrand 14y agoI just like the Velvet Underground reference on the new party app demo.
- ajays 14y agoThis looks very interesting, but can anyone tell me how scalable is this? All the examples I've seen are small scale; but can it support, say, 1000 clients? 10_000 ? Higher?
- lars 14y agoMeteor.com runs on meteor, and it survived their own launch, which was bigger than anyone seemed to expect. In practice, that's probably the biggest thing to run on meteor at the moment. The framework is built around long lived requests, which push data to the client. There doesn't seem to be anything unscalable about that, since Facebook and many other huge sites are doing it. That essentially leaves node.js and mongo, both of which should lend themselves to scaling pretty well.