But seriously, you're just as screwed if they inject HTML that changes the form submit URL for your password to an attacker-controlled site. The real answer to this problem is HTTPS, everywhere.
1,616 karma · joined June 20, 2009
But seriously, you're just as screwed if they inject HTML that changes the form submit URL for your password to an attacker-controlled site. The real answer to this problem is HTTPS, everywhere.
[Disclaimer: I work at Google, but not on any area related to this]
What? When did that get discredited?
Javascript excels at evented programming. Use the right tool for the job.
If you want to give your javascript some type-checking, try running it through the closure compiler. This is what we do, and we annotate our methods with type signatures like this
/**
* Queries a Baz for items.
* @param {number} groupNum Subgroup id to query.
* @param {string|number|null} term An itemName,
* or itemId, or null to search everything.
*/
goog.Baz.prototype.query = function(groupNum, term) {
...
};
And then the Closure Compiler tells us if we've broken some type contracts.Yeah, that's exactly what you do. Just because your new dev doesn't know how to refactor (and it's hardly even refactoring, it's like a two-line diff) doesn't mean we all shouldn't use IDs.
IDs have an extra bit of self-documentation when you use them - when I see #promoCol, I know instantly that there's just one promocol, and I don't have to worry about breaking the look of another promocol while I'm fiddling with the CSS in there. If there's a class, you don't know how many things it applies to until you've done a grep over your project.
I find changes in listening habits correlate well with big life changes.
_(people).max(function(person) {
return person.firstName.length + person.lastName.length;
}); var a = function(x) { if (x == 0) return 'done'; return a(x-1); };
a(100000);
RangeError: Maximum call stack size exceeded
http://code.google.com/p/v8/issues/detail?id=457I profiled it once, and most of the time was spent shelling out to python to do the syntax highlighting.
They declare the encoding in the HTTP Response.
Content-Type:text/html; charset=utf-8
That's totally proper. If you specify it again inside the HTML, are you gaining anything?It doesn't matter what the target language is if you want to do static typing or type inference. For example, Haskell compiles down to assembly, but still has an extremely robust type system with inference and all.
>> severely restrict the target platforms and future growth
Are you serious? JavaScript is supported on every platform and is experiencing crazy growth.
I'm very happy with my .nz domain, but it's lame that I have to have my home address in a publicly accessible database.