Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ksri
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
Redis Memory Optimization Cheat Sheet
(rdbtools.com)
2 points
by
ksri
8y ago
|
0 comments
32.
▲
by
ksri
8y ago
The biggest feature in 4.0 is modules. Yet there is no mention of modules I'm their release notes. I was hoping elasticache would support a whitelisted set of modules.
33.
▲
Show HN: RDBTools – Redis Memory Analyzer
(rdbtools.com)
9 points
by
ksri
8y ago
|
0 comments
34.
▲
by
ksri
9y ago
You're right. That's why I said upfront - whitelist values in the userquery object.
35.
▲
by
ksri
9y ago
You'd add that to Squealy. JinjaSQL simply generates a SQL query with an associated array of parameters. It isn't even aware of the SQL query that's written. JinjaSQL would work just fine with any database. Squealy is a djang
36.
▲
by
ksri
9y ago
Let's assume you have a python object "userquery" that has the user specifications - including dimensions, metrics, filters and the cube to query. I'm also assuming you have whitelisted all the parameters in this object
37.
▲
by
ksri
9y ago
We hadn't thought about it honestly, mostly because we don't use MSSQL as much with Python. However, it shouldn't be too difficult to add support if we have the right drivers. I've created a ticket here to keep track of
38.
▲
by
ksri
9y ago
Jinjasql is meant for reporting use cases, so yes - it should be able to help you. However, when we made JinjaSQL, we didn't want to build a super-expressive reporting API. Instead, for every report/chart we wanted to make, we wro
39.
▲
by
ksri
9y ago
Author of jinjasql. The whole point of jinjasql is to dynamically build queries. There comes a time when you need the power of sql, and an ORM gets in the way. Think unions, sql functions, group by, more complex sql. Think dynamically gener
40.
▲
by
ksri
9y ago
Author here. The spreadsheet started off with a brain dump, and then was revised into this blog post - https://hashedin.com/2016/07/05/choosing-right-authenticatio... . Perhaps this is more in line with what y
41.
▲
by
ksri
9y ago
Author here. The doc does acknowledge basic auth as a valid approach for server side usage, but the language was a bit too pessimistic about basic auth. I just modified it to say the following If you use HTTPS, then basic authenticati
42.
▲
by
ksri
9y ago
Yes, that's a miss. I'll add it as another option. Thanks!
43.
▲
by
ksri
9y ago
For clients outside of the browser, you have a few choices. JWT token passed in authorization header, or a secure random token passed in authorization header, or a signature that verifies the client has access to a secret. The easiest way i
44.
▲
by
ksri
9y ago
Author here. I wrote a simpler blog that summarizes the spreadsheet - https://hashedin.com/2016/07/05/choosing-right-authenticatio... . It may help you to find an approach that meets your needs
45.
▲
by
ksri
9y ago
> JWT docs aren't accurate? I'm curious - which portion of the document isn't accurate? > Why not store JWT in the cookie? At that point, it becomes a "stateless session cookie". It's a valid pattern, jus
46.
▲
by
ksri
9y ago
Author here, though not the one who submitted it. >> random tokens do rely on cryptography True. Random tokens do need a cryptographically strong PRNG. But when I wrote no cryptography, I meant there is no encryption or signatures. Th
47.
▲
by
ksri
9y ago
Yes, I went a little too far with "all web frameworks". I just changed it to "most web frameworks".
48.
▲
by
ksri
9y ago
Sort of agree that the example I provided isn't the best use case for JWT. Perhaps a better example is email verification - you send a link in the email with a JWT. re. OAuth2 - I wrote the spreadsheet from the point of view of a devel
49.
▲
by
ksri
9y ago
I maintain a spreadsheet of the pros and cons of various authentication techniques - https://docs.google.com/spreadsheets/d/1tAX5ZJzluilhoYKjra-u... JWT is extremely useful when you want a one-time use token to pa
50.
▲
by
ksri
10y ago
I posted elsewhere on this thread, but take a look at JinjaSQL - https://github.com/hashedin/jinjasql . Let's you generate SQL from a string template without worrying about SQL injection.
51.
▲
by
ksri
10y ago
Take a look at JinjaSQL - https://github.com/hashedin/jinjasql . Beyond a certain complexity, Django ORM gets in the way. Constructing SQL by hand is painful and can lead to SQL injection. And that's where JinjaSQL
52.
▲
Designing Modules in Python [pdf]
(hashedin.com)
2 points
by
ksri
10y ago
|
0 comments
53.
▲
Designing Modules in Python [E-Book]
(hashedin.com)
1 points
by
ksri
10y ago
|
0 comments
54.
▲
Postgres row level security and application users
(blog.2ndquadrant.com)
1 points
by
ksri
10y ago
|
0 comments
55.
▲
by
ksri
10y ago
We use AWS elastic beanstalk. It's simple to setup a high availability environment. And if needed, you can always access the underlying ec2 instances or elastic load balancer. Jenkins has a plugin that integrates with elastic beanstalk
56.
▲
Elastic Beanstalk Gotchas
(blog.hashedin.com)
1 points
by
ksri
10y ago
|
0 comments
57.
▲
5 gotchas with elastic beanstalk
(blog.hashedin.com)
1 points
by
ksri
10y ago
|
0 comments
58.
▲
Cheat Sheet: Authentication Techniques
(docs.google.com)
5 points
by
ksri
10y ago
|
0 comments
59.
▲
Choosing Right Authentication Technique for REST APIs
(blog.hashedin.com)
1 points
by
ksri
10y ago
|
0 comments
60.
▲
by
ksri
10y ago
Updated readme to reflect that 3.x is supported as well.
More ›