HNHacker News
TopNewBestAskShowJobs

mathias

3,588 karma · joined December 26, 2009

Web standards enthusiast. https://mathiasbynens.be/
submissionscomments
mathias··on Chrome’s Headless mode gets an upgrade: introducing –headless=new
Did you know that “old” Chrome Headless (2017–2023) was a separate, alternate browser implementation that just happened to be shipped as part of the same Chrome binary? It doesn’t share any of the Chrome browser code in //chrome.

--headless=new in Chrome 112 on the other hand works the way you'd expect.

mathias··on Theheadless.dev – open source Puppeteer and Playwright knowledge base
https://github.com/puppeteer/recorder
mathias··on A horrifying globalThis polyfill in JavaScript
The article includes a working polyfill that includes old IE support.
mathias··on A horrifying globalThis polyfill in JavaScript
Author of the referenced article here.

The article includes a working polyfill that includes old IE support, so I’m not sure what you’re complaining about.

Also, saying “jsvu is the justification for the polyfill” doesn’t make much sense. jsvu is just how I happen to test in various standalone JavaScript engines. There are other, non-jsvu ways of getting such binaries, e.g. compiling one yourself, and there are JS engine binaries that jsvu doesn’t provide (Rhino, Ringo, Nashorn). jsvu usage does not correspond to anything you seem to be talking about, and comparing its download count with IE10 usage is one of the more extreme apples-to-oranges comparison I’ve seen. ️

mathias··on V8: A Year with Spectre
Thanks :) Glad to see people appreciate simplicity (and the performance that comes with it).
mathias··on V8 release v7.2
We do indeed measure improvements against more than one website. We wouldn’t want to improve website X while regressing the rest of the internet. See https://v8.dev/blog/real-world-performance (from 2016):

> We now monitor changes against a test suite of approximately 25 > websites in order to guide V8 optimization. In addition to the > aforementioned websites and others from the Alexa Top 100, we selected > sites which were implemented using common frameworks (React, Polymer, > Angular, Ember, and more), sites from a variety of different geographic > locales, and sites or libraries whose development teams have > collaborated with us, such as Wikipedia, Reddit, Twitter, and webpack. > We believe these 25 sites are representative of the web at large and > that performance improvements to these sites will be directly reflected > in similar speedups for sites being written today by JavaScript > developers.

mathias··on Public and private class fields
The article links to the explanation by the proposal champions: https://github.com/tc39/proposal-class-fields/blob/master/PR...
mathias··on ECMAScript regular expressions are getting better (2017)
I mean, they have been solved. With the exception of String#matchAll (which is currently a Stage 3 proposal), all these features are part of ES2018 and shipping in Chrome. Other browsers implement some of them already and are working on shipping more.

You can view the implementation status of the various features here: https://kangax.github.io/compat-table/es2016plus/#test-RegEx...

mathias··on ECMAScript regular expressions are getting better (2017)
I make sure to keep the article up-to-date. It correctly states the status for each of the features. They’re all part of ES2018 with the exception of String#matchAll which is currently at Stage 3.
mathias··on ECMAScript regular expressions are getting better (2017)
Hey, I’m the author of the article. Despite its age, it’s still accurate and up-to-date.

> these features aren't entirely new

Depends on what you mean by that. These features are still not universally supported by all modern browsers, for example, so I can imagine they’re still new to a lot of developers.

Chrome supports all these features (except for String#matchAll, which is currently at Stage 3). Other browsers don’t yet support the full set, but they’re all working on getting there.

mathias··on The Intl.RelativeTimeFormat API
That’s not very JavaScript-y. Where else in ECMAScript are constants used like this?
mathias··on Ten years of V8
That would be a Chromium feature. V8 only implements ECMAScript and WebAssembly.
mathias··on About rel=noopener (2016)
The article is two years old but still up-to-date. The links to the relevant browser bugs are in the document, and the Edge bug is still unresolved. https://wpdev.uservoice.com/forums/257854-microsoft-edge-dev...
mathias··on Chrome breaks the Web
> In older browsers, useCapture is NOT an optional parameter

Which browsers are those?

mathias··on Chrome breaks the Web
> Which means you can’t practically use the new form without feature detection.

That does not follow.

`{ capture: true }` works in both, since it’s an object, and thus truthy.

There’s no need for feature detection in the case you describe.

Sadly, that’s the whole premise of this article.

It’s only a problem if you want `capture: false` combined with other options — since you’d need to pass in an object, that would be truthy in the old implementations expecting a boolean instead. But then again, the additional options wouldn’t be supported in those old implementations either.

I’m confused — what’s the actual use case that’s breaking here?

mathias··on Promise.prototype.finally
That’s not equivalent though — in the article’s example, imagine `element` is `undefined`, for example. `then()` wouldn’t be called in that case.
mathias··on Promise.prototype.finally
Correct. By Stage 3, the proposal is supposed to be stable enough to start shipping it in stable browsers.
mathias··on Why does HTML think “chucknorris” is a color?
Wondering what a given legacy HTML color value (as seen in `bgcolor`, `text`, `link`, `vlink`, and `alink` attribute values) looks like? This tool (which I made for a presentation years ago) shows you: https://mothereff.in/bgcolor#mathiasbynens
mathias··on JavaScript async/await implemented in V8
Present tense: https://domenic.github.io/streams-demo/
mathias··on Remote code execution vulnerability in ImageMagick
Replace `test` with `example.com` et voila.
mathias··on Craig Steven Wright claims to be Satoshi Nakamoto
+1. Still, code screenshots in Notepad?!
mathias··on Craig Steven Wright claims to be Satoshi Nakamoto
Nowhere in the blog post does Wright say “this is the proof I’m Satoshi”. The entire write-up reads like he’s just giving an example. Why does everyone think it’s some kind of proof?
mathias··on Front-End Performance: The Dark Side
That’s true for client-side JavaScript (like I said in the presentation).

It’s a whole different story if you’re using server-side JavaScript (e.g. Node.js), though.

mathias··on Front-End Performance: The Dark Side
> It looks like this is possible because there is not an explicit 'access-control-allow-origin' header set on facebook

CORS has nothing to do with it, actually. This is where the strength of the attack lies.

mathias··on Breaking Same Origin Policy (for the alexa top 1m)
“If you are logged in to a site that does this, it's a huge danger. Your private account information can be slurped down by ajax on any other sites.”

This is false (unless `Access-Control-Allow-Credentials` is set). See CORS 101: https://annevankesteren.nl/2012/12/cors-101

mathias··on I � Unicode [pdf]
More details on the Unicode regex problems in JavaScript (slide 62) and how ES6 will solve most of these issues: https://mathiasbynens.be/notes/es6-unicode-regex
mathias··on Why Google is Hurrying the Web to Kill SHA-1
Luckily shaaaaaaaaaaaaa.com itself is fine: https://shaaaaaaaaaaaaa.com/check/shaaaaaaaaaaaaa.com
mathias··on Ignoring the amount customers confirm is no security bug according to PayPal
I spotted this earlier this week when ordering a t-shirt through TeeSpring using PayPal. I authorized a payment of 22.95 USD. Here’s a screenshot from the payment confirmation email I received: http://i.imgur.com/BGjKcsW.png The math doesn’t quite add up.
mathias··on The Elements of HTML
Please use http://meiert.com/en/indices/html-elements/ instead, as it’s based on the WHATWG HTML Living Standard rather than W3C’s versioned fork.
mathias··on Plain text wrapping in Gmail
The point of typing a message in a webmail UI and sending it is to deliver the exact message you entered to the recipient. Adding hard line breaks, effectively altering the original message, is not useful.

Making text fit on a 80-character fixed-width screen is not something the email sender should do; the recipient’s email client should do it based on their preferences.

Page 1 of 7Next →