Show HN: One hostname to rule them all
onehostname.com
onehostname.com
Also, good luck writing a sane content-security-policy if you do this.
It's trickier than it seems, though, because you need to get the right combination of Host/X-Forwarded-Host right for a given hosting service. And you frequently need to rewrite HTML to fix links. Not rocket surgery, but usually I'd rather put my hours into dev and not tweaking a proxy.
You don't have to host all your stuff on one server at all.
- protocol/scheme (optional)
- hostname (mandatory)
- path (optional)
Notably, there is no query portion or fragment portion; browsers are expected to ignore those. Path matching works like a prefix if it ends in a slash. If it doesn't, only exactly that path matches.In CSP3, the secure protocol/scheme (https, wss) always matches, even if you explicitly specify http://. In CSP2, the implicit scheme matches either; an explicit scheme only matches that scheme. This is typically not useful behavior because you probably have HSTS anyway, so people just use hostnames and only rarely specify the protocol. Most values in practice seem to just be hostnames in general; paths too are rare.
With multiple domains, you at least can limit the blast radius of an XSS; on the same domain, most protections can be circumvented. E.g. there's no cors protection, so if different apps use different implementations of csrf, just fetch a the other app's page over XHR and parse out it's csrf token; it's probably their or in a cookie which you should be able to read.
https://developer.mozilla.org/en-US/docs/Web/API/Document/co...
for anyone interested in the topic, https://www.usenix.org/system/files/conference/usenixsecurit... is a must read
E.g.:
blog.example.com -> example.com/blog
api.example.com -> example.com/api
docs.example.com -> example.com/docs
... and so on. Supposedly for SEO benefit, but there's the obvious security risk of running all traffic through a third-party.
Is that true? I'm seeing vague claims ("Subdomains accumulate positive signals differently than root domains") without anything of substance to back up their veracity or relevance.
https://moz.com/blog/subdomains-vs-subfolders-rel-canonical-...
http://www.bloggingflail.com/subdomains-vs-subdirectories-se...
https://medium.com/mention/how-we-increased-search-traffic-3...
Why, what is the theory?
Do you have any concern that the "help folder-ize subdomains" business may go away with a Google algorithm update?
I'm not too worried about Google's algorithm changes. SEO is one "free" benefit of putting everything on a single hostname, but there are lots of reasons it's desirable. You get better speed (especially with tls and http2), more control, even vanity. What we're really helping people do is manage their stuff that's scattered across 15 different services and make sure they're all delivered to end users well.
But I can also find articles saying that subdomains are good for SEO, and Google itself says that subdomains are treated the same as subdirectories.[1]
I'm hoping for more than anecdata.
[1] https://www.youtube.com/watch?v=fKQULFm2BQA&feature=youtu.be...
Or, an opportunity to completely fuck yourself when someone breaches them and starts logging all your customer login requests
One problem I haven't figured out with this app-level routing, though, is how to have a reliable status endpoint. The distance the pinging server needs from the app's running process is at odds with this routing strategy.
HN didn't know this already?
I'm honestly not going to be surprised when "println as a service" appears AND people use it
That way you'd keep the XSS protections of CSP, while still not breaking things like github pages or a zillion other subdomain hosted services.
> Want all your applications on One Hostname?
Uh...no? Should I? I have no idea!
Oh look. Tiny, low contrast text at the very bottom of the page linking to an article that loses my interest before it gets to the point.
This could have been 24 point bold arial black on white: "We made a service called Fly to help you convert subdomains into load-balanced subdirectories to strengthen your brand and improve[0] your SEO. yada yada yada..."
[0] - citation needed, lol
If it was a black on white page I would have read it, acknowledge it and close, perhaps add it to Pinboard for later use and never look at it again. The way it is now I've clicked the links and read the whole article, almost.
Sorry. Correction. It tells you that you can sign up for...something.
Once I failed I turned in to HN comments.
UX on this website is awful, but it has a possibility to be an amazing one. Just a few small changes and people will link to this page as an example of UI. But for now is pretty bad.
Without any useful information without having to look on another page, wouldn't it just go into unnoticed?
I hope you enjoy the comic gift!
In the spectrum of HN consciousness there's a large chunk of rule-bound literalism. Part of the work of this community is for that to breathe a little and not need to impose itself everywhere. Then everything works better and life becomes more sparkly.
I get enough of this from work, thanks. There's a fine line between decoding twee whimsy and billable hours that most of these submissions stomp past obliviously.
The first rule of writing is: respect your reader's time (or else they won't read you). I'm all for not taking things to seriously, but if I have to spend 5 minutes to work out if this is an entertaining flight of fancy that I might just learn something from, or an untargeted waste of marketing budget, then I'm going to Have Opinions that I want to Share Online.
That's not my point at all: I work in software, so I love to stare at some cryptic message and mutter and make notes. But when I uncover the answer is "Be sure to drink your Ovaltine", then I'll feel ripped off.
I keep seeing product announcements using this technique of dressing it up in twisty little language, as if they're afraid that what they're saying isn't interesting enough to stand on its own. They slap on the appearance of entertainment, without considering how well it fits with their message (prioritising form over function).
why's (poignant) Guide to Ruby is a fantastic example of how to do it right: the whimsy doesn't detract from the message, but helps frame it and gives the right context for the reader to build the mental model of programming that _why intended to convey.
We probably assigned this post to different buckets but I agree with you that both buckets exist.
> if I have to spend 5 minutes to work out if this is […] an untargeted waste of marketing budget, then I'm going to [write a comment about how I wish people would stop doing it]*
I'll try being clear next time.