Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

To me it just looks like unacceptable carelessness, not an indictment of the alleged "lack of explicitness" versus something like gRPC. Explicit schemas aren't going to help you if you're so careless that, right at the last moment, you allow untrusted user input to reference anything whatsoever in the server's name space.




But once that particular design decision is made it is a question of time before that happens. The one enables the other.

The fact that React embodies an RPC scheme in disguise is quite obvious if you look at the kind of functionality that is implemented, some of that simply can not be done any other way. But then you should own that decision and add all of the safeguards that such a mechanism requires, you can't bolt those on after the fact.


this

I always felt server-action had too much "magic"


All mistakes can be blamed to "carelessness". This doesn't change the fact that some designs are more error-prone and more unsafe.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: