Volatile – A key-value pair API
volatile.wtf
volatile.wtf
> GET /?key=key&val=value
GET is supposed to have no side effects, according to RFC2616 9.1.1.
I'm no webdev, I think JS has been hyped so much around me I forgot plain html can actually do things...
When all API are GETs, the browser, which is likely to be open when you read this, is all you need.
And your service is also incorrect due to the issues with side-effects mentioned elsewhere in the thread.
An inline form on the webpage that POSTs the result is not a "webpage/separate tool". Option 2 would be to use the browser's dev console.
The dev console is a separate tool. And I'm still sure it is much quicker and easier to open a new tab and type in an URL, than to do a POST with dev console.
The "create a key-value pair" operation described here actually is idempotent.
The requirement on GET is that it must be safe, meaning no side-effects, for a variety of reasons, not just browser behaviour.
The difference is described in detail in RFC 7231 section 4.2, or the older RFC 2616 section 9.1.
One way you might call modification time changes idempotent is if you don't care about modification times.
Another way is much subtler: Although an updated modification time represents a change, the point of HTTP idempotent requests is that repeating them automatically is harmless. This matters because some requests may be repeated automatically by some clients under some network conditions.[2] Updating the modification time twice to a near-current timestamp might satisfy the idempotency condition for the purposes of the application.
[1] This isn't as handwavy as it sounds. It means that because it's the application that determines whether the effects of a request count as "semantically" idempotent (or semantically safe), the application should choose the appropriate HTTP method (or "verb": GET, PUT, POST etc) for the application's needs. The application's choice of HTTP method matters because client libraries, proxies and servers perform different methods in different ways in the protocol.
[2] For example, if sent as the second or later request on a persistent HTTP/1.1 connection, just as the server closes the connection, then the client might retry any requests that are for an idempotent (or safe) method. So it may automatically retry GET, PUT and DELETE but not POST.
My point exactly :)
The parent comment uses "safe" to mean doing it zero times is the same as doing it once or more. This is not a definition I've heard before, but maybe it's common in this context. A more normal term would be "free of side effects".
Multiple existing and established services were created as proofs-of-concept, silly jokes, experiments, and other "non-serious use" projects. Many of them have survived and we are forced to bear with their sloppy design all the time.
Have you ever used e.g. JavaScript?
Given the lack of auth, it should be possible to overwrite other people's keys, or did I miss something?
Hence, "volatile".
Really, really volatile.
Oh, it has word indexing (sort), relations (link), tree structured meta-data (meta) and it's distributed!
Also it's completely async. concurrent (joint parallel) so it has zer0 IO-wait! :)
Most HTTP is sync. because non-blocking IO and concurrent memory access are hard to make without side effects that our society does no not like; like dropping slow clients or using locks and chasing threading bugs f.ex.
My web/app-server is one of the few that does it all without bloat: parallel + async. with concurrent data structures and non-blocking IO; it means all cores can cooperate on the same problem at the same time without waiting for anything.
IO-wait is where most current sync. server solutions loose ~20% of the CPU when a system is under high utilization.
Comparable to what you loose on the kernel which is what many people are trying to remove with user-space networking.
It's also because of IO-wait that services break, a completely Joint Parallel system is very hard to break, it gets increased latency instead.
All Joint Parallel systems have a queue built in because there is no point to spawn more threads than there are cores.
I'm trying to find a name for it because things usually needs a name to spread, and Joint Parallel is the best I got so far.
What is the tech behind this ?
Shameless plug: if anyone's looking for a key-value pair API with a more rich API with support for buckets, access control, and server-side scripts, check out https://kvdb.io (disclaimer: I built it)
:~$ curl -v https://volatile.wtf/?key=65cd62ba-274c-4844-9ce4-c5d8bedcb959&val=baz
[1] 6628
:~$ * Trying 138.197.77.98...
* TCP_NODELAY set
* Connected to volatile.wtf (138.197.77.98) port 443 (#0)
* ALPN, offering h2
* ALPN, offering http/1.1
* successfully set certificate verify locations:
* CAfile: /etc/ssl/certs/ca-certificates.crt
CApath: /etc/ssl/certs
* TLSv1.3 (OUT), TLS handshake, Client hello (1):
* TLSv1.3 (IN), TLS handshake, Server hello (2):
* TLSv1.2 (IN), TLS handshake, Certificate (11):
* TLSv1.2 (IN), TLS handshake, Server key exchange (12):
* TLSv1.2 (IN), TLS handshake, Server finished (14):
* TLSv1.2 (OUT), TLS handshake, Client key exchange (16):
* TLSv1.2 (OUT), TLS change cipher, Client hello (1):
* TLSv1.2 (OUT), TLS handshake, Finished (20):
* TLSv1.2 (IN), TLS handshake, Finished (20):
* SSL connection using TLSv1.2 / ECDHE-RSA-CHACHA20-POLY1305
* ALPN, server accepted to use http/1.1
* Server certificate:
* subject: CN=volatile.wtf
* start date: Nov 11 19:13:05 2019 GMT
* expire date: Feb 9 19:13:05 2020 GMT
* subjectAltName: host "volatile.wtf" matched cert's "volatile.wtf"
* issuer: C=US; O=Let's Encrypt; CN=Let's Encrypt Authority X3
* SSL certificate verify ok.
> GET /?key=65cd62ba-274c-4844-9ce4-c5d8bedcb959 HTTP/1.1
> Host: volatile.wtf
> User-Agent: curl/7.58.0
> Accept: */*
>
< HTTP/1.1 404 Not Found
< Date: Tue, 12 Nov 2019 07:40:51 GMT
< Server: Apache
< Content-Length: 0
< Content-Type: text/html; charset=UTF-8
<
* Connection #0 to host volatile.wtf left intact [5 bytes data]
> GET /?key=65cd62ba-274c-4844-9ce4-c5d8bedcb959&val=baz HTTP/1.1
> Host: volatile.wtf
> User-Agent: curl/7.49.1
> Accept: */*
>
{ [5 bytes data]
< HTTP/1.1 201 Created
< Date: Tue, 12 Nov 2019 07:46:14 GMT
< Server: Apache
< Content-Length: 0
< Content-Type: text/html; charset=UTF-8
<Unless the author took preventive measures to prevent this, key lookups tend to be vulnerable to timing attacks, for example.
curl -i "https://volatile.wtf/?key=foo&val=%F0%9F%92%A9"
HTTP/1.0 500 Internal Server Errorexample: in the `and_then` key, a user (over)writes the next line in a developing narrative. next user repeats. etc. set up a little poller to fetch the key periodically to preserve the history.
If you wanted to monetize, but still keep it free (of course, you could and should have paid tiers too), you could send back an additional 255 characters of ad-text, with the agreement being, "you use the free service, you are obligated to display the ad-text somewhere, if it's a web app..."
Advertisers pay for the ad-text.
You collect the revenue.
Wishing your service luck!