Show HN: Pen.io
pen.io
pen.io
I just stole your password. :)
<img src="" onerror="alert(document.cookie.replace(/^.+pw=([^;]+);.+$/, '$1'));">What's worked for me in the past was to generate a random string each time I create a session for the user, which is valid to create exactly one session for the user. That string is consumed with each use and a new one is generated and saved to the cookie (which again, is good for the NEXT login.)
I'm sure it's also far from perfect, and causes potential havoc for users switching devices, and that sort of thing (though, where I've applied it, that was considered a feature, not a bug -- YMMV).
Back on subject, Pen.IO looks money, but I'd be worried about running out of page names fairly quickly. Have you thought about tying those to an account? bmelton.pen.io/test isn't quite as good as test.pen.io, but in 3 months, I don't like the odds of getting a page name less than 10 characters... and this problem only gets worse as you get more popular.
http://news.ycombinator.com/item?id=3433 <-- Check out the low id, '1432 days ago'
Such an awesome thing.
If anyone wants to check it out: http://notes.hardikr.com/
edit: updated URL
Nice work, regardless.
It doesn't support Unicode?
I created http://namuna.pen.io/ with devnagari script and it shows garbled text. I hope you know that ~2-3 billion people don't use Roman Script.
I get this on both: http://imgur.com/q0PfT
Can you pls tell me what I doing wrong?
Future update idea, if you could collate pages you've created. Instead of it getting lost in the void if you forget the IRL and need it months from now.
Google jquery link:
<script type="text/JavaScript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.3/jquery.min.js"></script>However if there isn't a cached copy of google's jquery there is the overhead of a dns query and new http connection to google.
This compared to the already open keepalive from my static server increases load time dramatically.
First impressions count, and you have few vital seconds to make a good one.
<script type="text/JavaScript" src="//ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script>
<script>!window.jQuery && document.write(unescape('%3Cscript src="/js/jquery-1.4.2.min.js"%3E%3C/script%3E'))</script>
The second script looks for the jQuery global object that should exist after the CDN fetch. If it doesn't exist, it knows to get your own copy.(If you're wondering "hey, where's the 'http:' part in that src attribute?", it's because it's a safer way to ask for a resource when you don't know if the you are under http or https.)
Also, you should try to place your <script> tags near the bottom of the <body>, rather than the <head> so that they don't block the rest of the page from loading/rendering.
Over the internet (as opposed to on your dev box), I'd expect that to always evaluate to false and therefore include your local script.
You might want to look into putting that call into window.onload so that it does what you think it does.
You will almost definitely have scripts that you have included after these two that depend on the jQuery object existing (otherwise what's the point in having jQuery at all). So imagine this trick wasn't used, and you just served up a local (or CDN hosted) copy of jQuery, then started using it in later scripts. It's reasonable at that point to assume that jQuery exists - which is because each script blocks, or if it doesn't, the browser itself will still make sure they execute in order. So it's perfectly safe to use this script without worrying about the order of things.
This is exactly why I (and many others) suggest that you put all of your <script> tags at the bottom of the <body> element. They block page rendering, so if they're in the <head>, or dotted around the <body>, they're going to delay the presentation of the page to the visitor.
Even the latest browsers that do not block further object (scripts requests during the download and execution of the script will execute scripts sequentially, so his check for "is jQuery present" will not fire until the external script has either returned and executed (so the check passes, and nothing else happens) or errored (so jQuery is not present and the document.write executes, making it load from the local resource).
The reason I server my own jQuery (rather than using the CDN-with-local-fallback option given in collypops' reply) even for my own personal projects is the paranoia of not wanting to trust code from an external source. OK so Google's CDN (or any of the other players) is much less likely to get hacked than my personal servers, but their CDN is also much more likely to be the target of a DNS poisoning attack. If an attacker manages to convince many people's machines to send requests for jQuery to them rather than Google via DNS poisoning then any site using jQuery could have unwanted code injected - if I serve my own jQuery file this risk is gone (unless the DNS spoofing attack targets my domain names specifically, of course, but I'm not a big enough fish for anyone to care to try that).
They can do some VERY ROUGH back of the envelope calculations to figure out based on cache-expiry headers and number of requests how many new people you are bringing to JQuery but not much else. Dan Kaminsky proved this earlier in his DNS/TTL cache sniffing tricks.
And by the time you are large enough to have an impact, your audience will be large enough for you to justify using your own JQuery hosted URL.
In short, USE THE CDN JQUERY. :-)
Accept the content first, then authenticate when users try & save. It removes a barrier to entry, and for people just testing, doesn't waste subdomains.
I'd also recommend ditching the subomain for a subdir. Regular people don't really get it. Yes, there are major services that do it, but i know from experience that social networking has trained average folks for years to use subdirs vs subdomains (twitter, facebook, myspace).
Good suggestions on picking an appropriate measure here: http://webtypography.net/Rhythm_and_Proportion/Horizontal_Mo...
http://itre.cis.upenn.edu/~myl/languagelog/archives/003008.h... http://blog.reddit.com/2006/02/infogami.html http://webpy.org/
I'm quite fond of web.py. It appears that it is still actively maintained and can do quite a lot.
One thing that I wanted while I was editing was a tag list (like you have on the About page, but right there on the edit page).
I think you may have meant "with the world".
I'm in Chrome.
So I choose the page name for my first entry to be Test123, and I also add hashtag #StartupPosts
Then later I make an entry called BlahBlah1 and hashtag #StartupPosts , it groups the two together. Then users can search by Hashtags to find posts.
Also, common hash tags would allow people to search content from multiple users. For example #Religion would have a bunch of religion based posts, from different users etc.
<?xml version="1.0" encoding="UTF-8"?>
Hm. Anyone know why Firefox 4b11 wouldn't respect that tag? It's throwing it into ISO-8859-1.Assume that people will want to build lot of pages. Don't let the lack of sub-domains hinder this. Plus, in future you can let them build a blog or something from this set of pages. Advantage you have is you are letting them start-off with minimum resistance.
I can write one obviously, but I was hoping to find something that did the layout like pen.io does. Jekyll is close when I looked at it. Maybe I should revisit.
http://littlepoem.pen.io/ (password: password)
Anyways, small bug for your :video tag. No opening < for the iframe tag, so it just shows up as HTML.
For me, being able to use markdown or similar would be a big plus.
Parse error: syntax error, unexpected '}' in /nfs/c02/h08/mnt/41076/domains/pen.io/html/functions/common.php on line 346