Is Haskell a Good Choice for Web Applications? (2009)
jekor.com
jekor.com
One of the points of critique has been addressed now is database access. For instance, Persistent provides type-safe database access:
http://www.yesodweb.com/book/persistent
The author also mentions the problem that exceptions can only be caught in the IO monad. But this has become less of a problem, since more people started using monad transformers (such as ErrorT) to add error handling to their monads. ErrorT allows you to catch exceptions within that monad. For instance, quoting from one of my own projects:
readEntry :: MonadIO m => Corpus -> String -> ErrorT CorpusError m Text
readEntry is a function that takes a Corpus and a String, and returns Text in a monad of the class MonadIO if the function is successful. Otherwise it reports errors in the form of a CorpusError. You could now, for instance, run this function with runErrorT, and it will return an ordinary Either value in the given monad (Left CorpusError in the case of an error, Right Text when the call is successful).So if someone out there is looking to learn a foreign language, my recommendation is to combine vocabulink's approach to build up a large vocabulary, and find the best concise grammar available for your target language. If you don't remember grammar fundamentals (e.g., what's a prepositional phrase, direct object, relative pronoun, etc.), then you need to find a good book in your native language to review those concepts.
In any case, cool concept for a web site. Sorry for the off-topic post. Thanks for telling us about your experiences with Haskell. I do think that Haskell web capabilities have come a long way since 2009, particularly Yesod (I'm not familiar with Snap).
It doesn't have anything like `eval` and is much less tolerant of weird input by default than dynamically typed languages (at least in my experience). Having no or limited state also helps--bad input and other mistakes tend to be more localized when they can't possibly change anything else in the program.
If you're really crazy about security, then I suspect the Haskell code would also be much easier to analyze and verify.
Of course, since such checking is used when the number of possible inputs is too large to check (or infinite), it is not watertight. But it helps tremendously in uncovering bugs.
The implementation may still have bugs, I suppose, but you can be sure that it's at least being heavily thought about.
I imagine forms may work the same way, though I'm not sure about that.
[1] http://www.yesodweb.com/home/snoyberg/blogs/2011/08/shakespe...
Security holes don't just magically go away when software gets popular. You should be striving to not create security holes in the first place.
Anyone play around with this idea?
Recent reddit conversation: http://www.reddit.com/r/haskell/comments/mwbvj/elm_functiona...