Building an "Easy" Web Application
rudyfaile.com
rudyfaile.com
https://developer.mozilla.org/en-US/docs/Web/API/AbortSignal...
Part of the awkwardness in the post is also mixing what looks like express with promises. I think using an async function as the handler with express 5 would probably feel a lot nicer.
I agree about CORS being frustrating. I think we should have allowed totally anonymous fetch requests across domains for saved to home screen PWAs (or with a permission prompt.) Missing that feature means you end up needing native apps for a lot of things that otherwise are totally reasonable web apps. CORS does make sense though because the alternative is drive by attacks against your local network from random web pages. And since the S in IOT stands for security that seemed like a bad idea at the time.
At some point trying to write JS, I really started believe that the people who implemented CORS did it just to break every single part of the world wide web that might ever be enjoyable.
It really felt like somebody held out a beautiful idea with AJAX, and requests lacking synchronization, and then the only response was endless exploits, security holes, patches that took away functionality, and posts like the authors. "This idea seems so simple...nevermind, 'Access-Control-Allow-Origin' ERROR"
In Bottle, returning a generator or iterator will send the response in chucks, instead of all at once. The effect would be that the test results load in one by one, providing the user with feedback. No JavaScript needed.
I'm pretty sure you could use an AbortController to address this? But it's one of those things you have to know about. I completely understand the author's frustration with CORS, but I don't think JS is to blame here. I have felt a similar level of frustration whenever I try to use a language other than JS to work with JSON. Does that mean the language sucks? I would say no. I don't think this made a compelling case for avoiding JS, but I would never want to deny someone the catharsis from venting about technology.
> Three days wasted. I should have just written the PHP script .
The good news is that any leading class LLM today would certainly be able to one-shot translation of the script from Python to PHP or create it in PHP.
The JS ecosystem does indeed suck.
Isn't this the same with any language ecosystem where you opt to use the package manager?
ASP.NET + alpine.js is my current happy place. If I need a JS lib then I get it from unpkg.com and avoid npm.
Then Docker on a Digital Ocean Container App is a really easy way to CI/CD.
So much truth in this. It's amazing that JS has managed to survive (even thrive!) in spite of the constant fundamental backwards-breaking changes every few cycles. Maybe that speaks to the lack of web based alternatives than anything else.
wat
TC-39 literally has "Don't break the Web" as an explicit goal.
You are conflating "JavaScript" with something else (possibly some popular packages written in JS, for example—by people who have no control or say over the standard, usually, and with dubious taste to begin with).
By all means, avoid those packages and tastemakers. JS is still JS and still works despite their whims.
Those are functionally part of the language
Streamlit is not mentioned in the article, yet I can argue that is unbeatable and that by a large margin in how quick it is to get from a Python script to a decent, functioning web application.
In general, going one-language, full-stack (Vaadin, Streamlit etc..) is probably the right path for anyone who doesn't want do front-end but has to. IMHO of course.
PHP is the right tool for the job of making websites.
You can write a post like this about the frustrations of any language / tool / framework - just go in with random expectations and limited understanding - and when you encounter an obstacle don’t attempt to learn why it’s there.
At least Deno is TypeScript-native, so that's one whole set of build chain linkage sorted.
CORS is a basic part of browser security. Yes it’s frustrating when you first encounter it, but the next step is to understand it and why it’s actually quite a good thing that it exists. Or you could write a blog post i guess.
CORS is basically happening because of the sensitive data that browser sends by default, so if browser is not sending such info, then CORS also need not be applied
https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API/U...
Can you cite where this behaviour is defined?
+----------------------+ +-----------------------+
| User Browser | | WordPress Site |
| (viewing from | CORS Error | (blog.com) |
| example.com) | Browser enforces CORS | |
| +------------+ | Direct request | +------------+ |
| | Frontend |<-----------------------------------X | xmlrpc.php | |
| | App | | example.com → blog.com | | | |
| +------------+ | | +------------+ |
+----------------------+ +-----------------------+
Browser security blocks cross-origin
requests (CORS is browser-only!)
The bottle app presumably uses some python library like Requests. It wouldn't care about CORS. +----------------------+ +------------------------+ +-----------------------+
| User Browser | | App Server | | WordPress Site |
| (viewing from | | (example.com) | | (blog.com) |
| example.com) | | | | |
| +------------+ | | +------------+ | | +------------+ |
| | Frontend |<-------->| | Backend |<---------->| | xmlrpc.php | |
| | App | | | | (Bottle) | | | | | |
| +------------+ | | +------------+ | | +------------+ |
+----------------------+ +------------------------+ +-----------------------+
Same origin Uses requests library Different origin
Browser allows this No CORS checks here! (Server doesn't care
(Not a browser!) about origin)LLM's are surprisingly good at making diagrams in monospaced ascii or MermaidJS.
[0] https://developer.mozilla.org/en-US/docs/Web/API/Server-sent... - I don't think Bottle supports this though; you might have to move to a different WSGI server.