5 ms·
Would love to see something like this for RESTful Web Services built on Go with /users, auth, rate-limiting, etc already working out of the box.
by sinatra 11y ago
Would love to see something like this for RESTful Web Services built on Go with /users, auth, rate-limiting, etc already working out of the box.
- loosescrews 11y agoI wrote something like that a while back: https://github.com/iangudger/basicGoAPI https://github.com/iangudger/basicGoAPI No rate limiting, but it has pretty much everything else. If you want to add it I would welcome a pull request :)
- abtinf 11y agoYour project is GPL licensed. Is that your idea of a joke? There is a place for the GPL, but this is not it.
- papaf 11y agoI have found the GPL is workable in web projects: https://programmers.stackexchange.com/questions/132485/does-a-website-running-modified-gpl-software-have-an-obligation-to-release-their https://programmers.stackexchange.com/questions/132485/does-... I understand why people don't like the GPL but its not a showstopper for most business applications.
- abtinf 11y agoYou are grossly misguided and should consult a lawyer. Linking to a random programmers stackexchange question is an unwise way to make licensing decisions. Per GNU's own faq at https://www.gnu.org/licenses/gpl-faq.html#UnreleasedMods https://www.gnu.org/licenses/gpl-faq.html#UnreleasedMods: A company is running a modified version of a GPL'ed program on a web site. Does the GPL say they must release their modified sources? The GPL permits anyone to make a modified version and use it without ever distributing it to others. What this company is doing is a special case of that. Therefore, the company does not have to release the modified sources. It is essential for people to have the freedom to make modifications and use them privately, without ever publishing those modifications. However, putting the program on a server machine for the public to talk to is hardly “private” use, so it would be legitimate to require release of the source code in that special case. Developers who wish to address this might want to use the GNU Affero GPL for programs designed for network server use. In case you missed it: However, putting the program on a server machine for the public to talk to is hardly “private” use, so it would be legitimate to require release of the source code in that special case. There are numerous other potential consequences to the GPL and the question of when propagation occurs is ambiguous.
- Vendan 11y agoIn fact, you are actually the one who is grossly misguided. Per that exact quote, The GPL permits anyone to make a modified version and use it without ever distributing it to others. What this company is doing is a special case of that. Therefore, the company does not have to release the modified sources. Specifically Therefore, the company does not have to release the modified sources. The faq is explicitly stating that the GPL would not require releasing modified source, and that if you want to force the releasing of modified sources, you should use the AGPL, as it has a clause to cover network server software
- robbles 11y agoAre there any precedents for this side of the GPL being enforced? How would you even know, or prove, in the first place that a company was running a modified version of the GPL'd source on their servers?
- tikhonj 11y agoAs your quote says, it would be a legitimate request... but not one made by the GPL. Instead, if you wanted to require this from your users, you would have to use the Affero GPL which was written for this very purpose (ie to close the "application server loophole" in the normal GPL).
- detaro 11y agoYou probably are thinking of the AGPL, which would make that requirement. Normal GPL doesn't.
- olalonde 11y agoI could also see this implemented as a standalone proxy which would forward requests to an app server (possibly adding custom headers like `X-User: someusername`). I was actually thinking of going with exactly this kind of architecture for my next project but wasn't sure if the re-usability benefits would be worth the extra work. Anyone has experience with this kind of setup?
- xienze 11y agoRate limiting isn't something your app should be concerned about. That should be handled a layer up, e.g. nginx. Chances are it does a much better job than whatever you could come up with.
- danneu 11y agoMaybe if it's trivial blanket rate-limiting on a single server. Anything more complicated that needs synchronization/database access, I'd rather just read and maintain application-level middleware. It's not rocket science.
- czbond 11y agoLook at Tyk for this, it should be handled at a layer higher than any individual API IMHO.