Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ratorx
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
61.
▲
by
ratorx
1y ago
Does it make it easier? The “escape” for both is to just use unsafe version of the Template -> string function or explicitly mark an unsafe string as sanitised. Both seem similar in (un)safety
62.
▲
by
ratorx
1y ago
I’m not sure you understood my example. The f-string is within a function. The function argument only accepts sanitised input type. If you create a subclass of str which has an init function that sanitises, then you can’t create a Sanitised
63.
▲
by
ratorx
1y ago
Delayed execution is basically equivalent to a function call, which is already a thing. It also has basically the same API as point of use and requires maybe 1 extra line.
64.
▲
by
ratorx
1y ago
I’m not convinced that a language level feature is worth it for this. You could achieve the same thing with a function returning an f-string no? And if you want injection safety, just use a tag type and a sanitisation function that takes a
65.
▲
by
ratorx
2y ago
Presumably the difference is index (listing links) vs reproduction (actually returning content). Also, it’s easier to remove copyright material if it’s not all crammed into an LLM first. Eg. If someone wanted to remove their website from Go
66.
▲
by
ratorx
2y ago
The analogy doesn’t hold. If the entire representation of the “code” is the natural language description, then the ambiguity in the specification will lead to incompatibility in the output between executions. You’d need to pin the LLM versi
67.
▲
by
ratorx
2y ago
Let’s say that all of the ambiguities are automatically resolved in a reasonable way. This is still not enough to let 2 different computers running two different LLMs to produce compatible code right? And no guarantee of compatibility as yo
68.
▲
by
ratorx
2y ago
Firstly, it might be worth separating the concepts of read and write consistency. For example, in your system reads are eventually consistent (because syncing is not enforced) and the situation with writes is more complicated. I think the k
69.
▲
by
ratorx
2y ago
I have never owned a Boox device, but was researching them when looking for an e-reader. The premise is good, but bear in mind that they will basically provide no updates to Android versions once the device is released. If using an internet
70.
▲
by
ratorx
2y ago
Yup, there’s no reason to believe that the proto files (which are definitions rather than data) are any more confidential than the Gemini source code itself.
71.
▲
by
ratorx
2y ago
I was referring to 3.x, but also to “minor” releases (not sure they use semver), where standard library functions and options are being removed occasionally. So it is both “not conservative enough”, whilst as you say being overly conservati
72.
▲
by
ratorx
2y ago
I don’t think it’s just slowness or stability. The original release of requests was in 2011 and the standard library module (urllib.request) was added in Python 3.3 in 2012.
73.
▲
by
ratorx
2y ago
Well, the “this script needs package manager part”. The rest of my comment about the state of the HTTP client in Python would still be valid (but I probably wouldn’t have discovered it).
74.
▲
by
ratorx
2y ago
Sure historical popularity is a good reason for people who are already familiar with it to keep using it. That is not really an excuse for why the standard library docs for the clients you mentioned link to requests though (especially if th
75.
▲
by
ratorx
2y ago
Out of curiosity, what are some problems with rustification? Is it an aversion to Rust specifically or a dislike of the ecosystem tools not being written in Python? The former is subjective, but the latter seems like not really much of an i
76.
▲
by
ratorx
2y ago
Slightly off-topic, but the fact that this script even needs a package manager in a language with a standard library as large as Python is pretty shocking. Making an HTTP request js pretty basic stuff for a scripting language, you shouldn’t
77.
▲
by
ratorx
2y ago
There’s also the case that the regulations don’t exist. And what’s more worrying is things where the negative impact is higher order. If the bread has some poison that will kill you in 5 years time etc. Currently we maintain a bar partially
78.
▲
by
ratorx
2y ago
The French legislation is targeting all major resolvers, Quad9 is not really any better or worse than others just for this. A niche resolver may get away under the radar, but only because they were not targeted.
79.
▲
by
ratorx
2y ago
I think the France legislation is aimed at most major resolvers. You might get away with more niche ones for now, but the only stable way is to self-host a recursive resolver (like unbound) that walk the DNS tree themselves.
80.
▲
by
ratorx
2y ago
Well, there’s 2 possibilities: 1) Plain HTTP, go wild with headers. No system should have any authenticated services on this. 2) HTTP with integrity provided by a transport layer (so HTTPS, but also HTTP over Wireguard etc for example). All
81.
▲
by
ratorx
2y ago
You’re right - I was specifically referring to it giving a concrete example (which may or may not be correct) of the vulnerability as opposed to the main article just pointing in the direction of the header.
82.
▲
by
ratorx
2y ago
Yeah, I guess most existing Linux stuff that is actually configured (so not SELinux etc) is geared at system processes not user ones. Transparently running all user applications in properly isolated containers would be quite neat. Does Fire
83.
▲
by
ratorx
2y ago
I found a different article that goes into more detail: https://zeropath.com/blog/nextjs-middleware-cve-2025-29927-a... This looks trivially easy to bypass. More generally, the entire concept of using middleware which
84.
▲
by
ratorx
2y ago
You don’t even need to run in a container for this. It’s possible to do this entirely in systemd service configuration. The easiest way is just to have separate user for every service and reduce stuff running as root. You can also restrict
85.
▲
by
ratorx
2y ago
I’m not saying the back door issue looks good, but it is pretty disingenuous to make a bold title (backdoor) and link to a different issue (privacy) entirely.
86.
▲
by
ratorx
2y ago
I’d go even further and say that HTTP/3 gives almost no gains for the average person using a high speed wired or wireless internet connection at a fixed location (or changing locations infrequently). However, for high latency mobile co
87.
▲
by
ratorx
2y ago
So far it’s all optional stuff. I think the editor is worth trying purely for how snappy the UI is, whilst not really missing any of the nice major features of VS Code that I actually use. Even without the AI stuff, it is an editor with a l
88.
▲
by
ratorx
2y ago
`git add -p` opens an editor to stage individual lines/hunks right? If so, would a better workflow not be the editor providing shortcuts to stage/unstage individual lines/hunks (which it can indicate in some state column) and
89.
▲
by
ratorx
2y ago
Does it even configure caddy? I can’t see how the caddy config could be generated from the env.yaml (unless it relies on the directory name etc for the path). Seems like something that could have been solved with just docker compose (by set
90.
▲
by
ratorx
2y ago
> performs similarly to a popular Caddy web server From the main landing page. Possibly the benchmarks are slightly better, but until Nginx is added it’s hard to say how significant that bump is.
More ›