6 ms·
Padrino Framework 0.11 is here
- pspeter3 14y agoCongrats on the release! I wish there was a node version of you guys.
- DAddYE 14y agoI think you shouldn't wait so long ;)
- pspeter3 14y agoI used to use padrino for my projects. I'm one of the few people who actually finds thinking in callbacks easier and I like using the same language in both the client and server so I switched to node. I think you guys are a fantastic project though!
- ortuna 14y agoLooks good, congrats!
- dinedal 14y agoCongrats on the release! Excited about the new http_router, and the new app as a gem feature! When I saw you guys at the meetup in SF, there was some chatter about concurrency features being added, did these make it into this release?
- DAddYE 14y agoNot yet, is planned for 1.0
- ams6110 14y agoPadrino is a Ruby web framework, for those who are not familar with it.
- tekacs 14y agoWhilst I think that the Padrino framework is an excellent effort, I would like to remind everyone (chiefly the project organisers) that as things stand, the framework has no meaningful notion of security for the admin interface. I flagged this up about two years ago, now, but stopped using the framework shortly thereafter and never pushed any fixes of my own. The complete lack of meaningful authentication appears to still be there all this time later. For reference, see: https://github.com/padrino/padrino-framework/issues/384 https://github.com/padrino/padrino-framework/issues/384 and http://tkcs.in/Nlrc http://tkcs.in/Nlrc Though I would hope that Padrino admin isn't in fact being used in production by anybody who hasn't read the source, a quick search at the time showed otherwise.
- tekacs 14y agoAnd please, do correct me if I'm wrong (if this has in any way been fixed since).
- DAddYE 14y agoTekacs: 1) We use bcrypt: https://github.com/padrino/padrino-framework/blob/master/padrino-admin/lib/padrino-admin/generators/templates/account/activerecord.rb.tt#L32 https://github.com/padrino/padrino-framework/blob/master/pad... 2) Auth is an API we generate that for YOU, but you can change the code generated to fit your needs.
- tekacs 14y agoHuzzah, with regards to the point of BCrypt (presumably the second link goes to currently dead, but left-in-the-codebase helpers). On the other hand, the first (original) point (the GitHub issue) still stands to this day - it would make sense to either improve the default implementation of Auth to be usable (as per most every sane framework out there) or to provide a warning somewhere (at least on the Padrino guide for admin & auth?) would it not?
- DAddYE 14y ago3) session_id is different from session_secret (generated also for you with SecureRandom, but also there you can change it)
- satyap 14y agoYay! We use padrino. Yay!
- ronnqvist 14y agoThankyou so much! I've been waiting for this release in order to get Twitter bootstrap for a project that I'll just have to get out the door! Give me a bitcoin address and I'll tip you one. :)