Replaced JS with HTTP request
github.com
github.com
- The CDN gets to decide *what* code is delivered to *which* users. Could be a prime target for, say, another FERRETCANNON.
- If the CDN is compromised, so is your site.
- If an attacker on a local network manages to inject poisoned cache data into requests for said CDN, your site is compromised.
- All of your visitors are disclosed to the CDN owner.
- If the CDN goes down, your site does so, too. Note that the inverse doesn't apply: the CDNs superior availability has no positive effect on your site.
- Loading from another host may cause an unnecessary DNS lookup and will cause an unnecessary TLS connection.[1] http://www.theatlantic.com/technology/archive/2013/10/how-th...
It's really not clear what, if anything, can be done to stop them.
And not as much of a tradeoff if a lot of nearby visitors have also visited the same site, or users visit it frequently.
Personally I don't think a user will have anything cached other than jQuery from Google. Which in this case I removed to follow the rule of eating own dogfood.
This would mean that browser can essentially cache the exact version of the script from any source, verify it with a hash, and still have a fallback URL to download it from.
<script hash="sha-1/fa26be19de6bff93f70bc2308434e4a440bbad02" name="angular.js@1.2.10" src="xxx"></script>
The name attribute would be purely aesthetic, so no reason for a version attribute. SHA-1 is good enough for git content-addressed-storage, it's good enough for browsers.
One of the major upsides is that it's so heavily used, that a user probably already has it cached in their browser. At least that's the idea, not sure of actual numbers.
Hosting a 32kb library yourself shouldn't be that hard in the days of 50mbps+ LTE mobile internet.
For development purposes ('grab the latest version, from Google because it's convenient') I'd go with Google, for a production deployment not so much.
Last time I tried this, I ran into the problems of 1) unbounded URL length breaking down in old browsers, routers, etc. and 2) hobbled caching. (And also going against the grain of REST.)
I'd be interested if anyone has actually done something like this successfully. Did you have the issues I did? Was it worth it?
[1] https://developer.mozilla.org/en-US/docs/Web/HTML/Element/sc...