Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
hmsimha
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
31.
▲
by
hmsimha
5y ago
I'd go with `Math.max(...arr)` personally. Math.max is a variadic function, no need to add a reduce into the mix.
32.
▲
by
hmsimha
5y ago
What if the package bundles were stored on IPFS? They would be hash-addressable, and also verifiable (no danger of package hosts inserting malicious code), and npm would just be responsible for building, verifying that a given bundle based
33.
▲
by
hmsimha
5y ago
Minor clarification, the latter example will only await until both have resolved *or* one rejects. To await the resolution of all promises, you should use the truly gamechanging `Promise.allSettled` , though you will have to transpile it if
34.
▲
by
hmsimha
5y ago
> But more importantly, you should investigate how your LB or webserver talks to the web app. In many cases that part won't be TLS encrypted and therefore on an HTTP/1.1 channel. Or even HTTP 1.0 . I found out recently while in
35.
▲
by
hmsimha
5y ago
Defaulting to SameSite=lax is a (relatively) recent development, as per the doc you linked. Yes, I don't think cookies with SameSite=Lax will be sent to a cross-domain host when the request type is a POST, even when the navigation is t
36.
▲
by
hmsimha
5y ago
I believe this also requires that OKCupid has not set the 'SameSite=lax' attribute on their cookies, which is good practice as well; the browser won't send the user's cookies on cross-origin POST, PUT, PATCH, or DELETE r
37.
▲
by
hmsimha
5y ago
Containerd is the docker runtime, so it's still used to run/manage containers on the kubelet. Crio is another option: https://kubernetes.io/docs/setup/production-environment/cont... . I think the di
38.
▲
by
hmsimha
5y ago
Containerization, certainly, but you can run kubernetes just fine without Docker (I was under the impression most large-scale deployments now use Cri-O - https://cri-o.io/#what-is-cri-o )
39.
▲
by
hmsimha
5y ago
Devtools can actually be detected to a certain extent - https://github.com/sindresorhus/devtools-detect
40.
▲
by
hmsimha
5y ago
Even more worse: it's a stackoverflow from yourself 2 years before, which you then closed because you "figured it out" (without expanding on how)
41.
▲
by
hmsimha
5y ago
Relevant XKCD https://xkcd.com/979/
42.
▲
by
hmsimha
5y ago
I giggled, but then realized former an0n users might take it as an opportunity for cooperation. Whether or not it is, it may be effective in getting some to turn themselves in for that reason.
43.
▲
by
hmsimha
5y ago
For anyone capable of using React, there's no barrier to 'learning' sass (you can be productive with it in about 30 seconds). Admittedly there might be some additional work around configuring compilation to work with the rest
44.
▲
by
hmsimha
5y ago
For people like me who read the linked twitter thread before reading the comments (admittedly guilty of getting outraged before hearing both sides): There is an "unvote" button underneath the headline.
45.
▲
by
hmsimha
5y ago
Speaking to the section on "Vendor claims" > An attacker (or malicious insider) in control of the vendor’s network can change the code that is served to your browser, and that code can obviously access your passwords. This isn’
46.
▲
by
hmsimha
5y ago
It would make it much easier for users to visually parse the JSON section if you added `font-family: monospace` to the textarea element
47.
▲
by
hmsimha
5y ago
I grew up in the U.S., spent ~7 years volunteering at a soup kitchen (not an actual soup kitchen, but a program which cooked and served meals to the public), and I had no idea what "food pantry" was. The term I'm familiar wit
48.
▲
by
hmsimha
5y ago
Just to add to the above, this is specifically when your pages are server-side rendered. Hydration is a concept of taking a server-rendered page and making it interactive with Javascript. You can have your NextJS/React app server-rende
49.
▲
by
hmsimha
5y ago
Ahh OK, interesting. That seems like more of an HTML issue than a CSS one (putting the close button element outside of the container element which it's associated with). I'll carry on doing things the way I already do then. Thanks
50.
▲
by
hmsimha
5y ago
> Or, using absolute position to, say, anchor a close button to the top right of an element. Sure, the way you did it happened to put it visually in the right spot, but it's not actually in the right spot according to the layout eng
51.
▲
by
hmsimha
5y ago
The implication here seems to be "when using HTML semantically", because I think everything you're talking about can be done with CSS if you're willing to abuse HTML. Take this CSS accordion which uses hidden form elemen
52.
▲
by
hmsimha
5y ago
This seems really neat. Curious if you saw this magic SQLite -> Static file tool shared here a couple of weeks ago: https://news.ycombinator.com/item?id=27016630 IIUC It would enable this tool to work with a dataset in s
53.
▲
by
hmsimha
5y ago
I don't think I am. If I'm testing a react app on localhost:3000, and it normally calls out to an api of mine also, I may want to feed it some dummy data. Let's say I use python http.serve on port 5000 in a directory with fil
54.
▲
by
hmsimha
5y ago
You could still want CORS if, for example, you're testing a front-end service that typically calls out to a remote resource. Maybe you typically deploy both same-origin in production, but for dev you want to be able to feed it some spe
55.
▲
by
hmsimha
5y ago
You're limited in how much data you can store in a cookie
56.
▲
by
hmsimha
5y ago
> The CSRF attacks you're describing have been solved by browsers with the SameSite attribute on cookies. This is only partially true; It requires the users to have browsers which respect this. Which is probably true for 99% of user
57.
▲
by
hmsimha
5y ago
This is great! The takeaway for me is that with squash merge you get one commit with all the changes which (optimally) has the full context in the commit message. My typical workflow is basically the same, but with putting all that context
58.
▲
by
hmsimha
5y ago
Cryptocurrency staking is effectively the same as dividends for investors, though staking rewards are often more predictable.
59.
▲
by
hmsimha
5y ago
To be clear, it's not really stream history that I'm after. Just the result of a database query upon connection ( `select all items from table X with time > (now() - 1hr)` )
60.
▲
by
hmsimha
5y ago
This is something I have an immediate need for (and was about to build myself) to use with a PostgreSQL/TimescaleDB instance. Is it possible to have new subscriptions get up to an hour of historical data before streaming starts, or eve
More ›