HNHacker News
TopNewBestAskShowJobs

qooleot

112 karma · joined September 10, 2013

IVC, Inc. www.ivc.com
submissionscomments
qooleot··on Better SQL strings in io.js
Hey you do you a middleware you use for this? I'd be interested in trying it out for cases where I have large, semi-static queries and want the entire file to be sql-language and not mixed with node code.

Also, how do you handle queries that are not pre-defined? I have a lot of screens where the user can select 'categories' (a collect of join-statements basically) and pick their own columns (including creating formulas so I can't just select *), sort, group-by clauses, and "pivot" (using CTEs or the crosstab feature) dynamically.

qooleot··on Better SQL strings in io.js
That is invalid in javascript, just like this is invalid:

var foo = "string "with quotes" done."

You can escape the inner backquotes \` but then its just a backquote character in the string. It doesn't do anything special like call the template string again.

qooleot··on Better SQL strings in io.js
An example of extending your reserved list would be the world "lateral" (new type of join in 9.4). I'll do a PR if I get that far:}

RE: comments, yes it would be quoted and that would cause an error.

select/comment/ 1; ?column? ---------- 1 (1 row)

# "select/comment/" 1; ERROR: syntax error at or near ""select/comment/"" LINE 1: "select/comment/" 1;

That's probably a silly example, and I was just trying to think through 'what could go wrong with this?' before implementing. Thinking about it further, thats probably not something you want the library to be responsible for handling. I'd want to try out newline chars too since thats more common.

qooleot··on Better SQL strings in io.js
I really like knex, and have projects that use it too!

Sometimes, and especially on an intranet/admin tool thats not meant for widespread consumption, I start with a sql query (or an analyst hands me one) and it just needs to be a report/chart on a web page and isn't mean to be part of a product's API and flexible. Converting it to knex, and especially if the analyst changes their mind and gives me a brand new sql query, isn't really worth the effort (opportunity cost of working on that code vs something more fruitful).

qooleot··on Better SQL strings in io.js
Hey yes, sorry if not clear, but I definitely output a prepared statement and do not homebrew any escaping! I'll take a look at adding a "TL;DR" section at the top to point that out before the second page where I actually go through how it works:

http://ivc.com/blog/better-sql-strings-in-io-js-nodejs-part-...

qooleot··on Better SQL strings in io.js
Hey nice I actually looked at this library when I started. I really like the sql identifier escaping, where most just do literals.

I'd thought about:

"select * from %I${my_table} where ..."

I think I'd probably feel more comfortable having a whitelist of allowed words rather than just a blacklist, as there are probably ways around it. Either new syntaxes in future Postgres versions, or mid-sql comments. Take this for example:

Edit: sorry the * before the word "comment" below is being escaped by hacker news. There is probably some hackernews-injection to get around this:}

select/comment/ * from foo;

if "select/comment/" was the identifier, that's valid sql, but:

function isReserved(value) { if (reservedMap[value.toUpperCase()]) {

does a comparison on an exact match, not contains.

https://github.com/datalanche/node-pg-format/blob/master/lib...

qooleot··on Modern SQL in PostgreSQL
If you're just trying to get JSON out (for a simple query to REST api, or in a node.js environment), have you considered converting the record/recordset to json in the subquery?

The json functions in 9.3+ are pretty handy for that sort of thing. Andrew (core developer who wrote most of that functionality) and I decided to keep the api pretty lightweight, as its easy to also add your own functions to suit your needs.

qooleot··on Modern SQL in PostgreSQL
I work on several Django apps, and also write advanced SQL in Postgres (CTEs, plv8 functions, materialized views, etc.). One thing the ORM allows though is writing a custom sql query and its pretty easy to 'cast' the sql results into a Django model.

With that said, its still sometimes a struggle to justify if almost all the queries are highly custom, and the app doesn't require Django Admin. Certainly there are advantages, but the minimalism of Flask and focusing on the REST interface for integration and building micro services is more appealing in some cases.

qooleot··on Show HN: Jolie – The First Programming Language for Microservices
I think by "model logic" he is referring to MVC and things like data model relationships (and an ORM possibly), validation/casting, etc.

For example, in a single programming language and framework you could say:

payment.isPayPay()

from a payment out of a database wrapped into a model.

It has not been traditionally easy to share that business logic across languages (and by easy I mean not wrapping huge numbers of methods in http requests).

qooleot··on Review of the Model S 85
This. I'd played with all sorts of leap second adjustments, time zone switching, etc.

A really rolling road (Arizona has some of these) where the car might be one "roller" ahead of you but look a lot closer, then your car hits the brakes at the apex with a car tailing you.

qooleot··on Io.js 1.0.0
Lets hope they keep momentum, otherwise they'll be 'corkscrewing' the community!
qooleot··on Show HN: Cluckles, live theme editor for Bootstrap
Hey nice! One thing I might recommend is independently scrolling the main section from the property editor on the right (have that in a fixed position?). The idea is to be able to see the Navs example when you're changing the padding/colors for the Navs Components. That was much harder for me to play with than the buttons which are visible as I changed the background color since their scroll position was similar.
qooleot··on Ask HN: Who is hiring? (December 2014)
Hey yes, good catch:} You can email me at taras@ivc.com.
qooleot··on PostgreSQL 9.4 Released
No, it can be a gotcha because the json column type (which still exists and many may mistakenly use instead of the jsonb type) allows it:

select '{"foo": 1, "foo": 2}'::json; json ---------------------- {"foo": 1, "foo": 2} (1 row)

select '{"foo": 1, "foo": 2}'::jsonb; jsonb ------------ {"foo": 2} (1 row)

So technically, the gotcha is you have to remember to use jsonb instead of json, as well as json having a true "gotcha" and jsonb not having one.

qooleot··on PostgreSQL 9.4 Released
Since you're planning on doing some conceptual work with JSONB, just a heads upon one gotcha -

duplicate properties are not allowed. I.E.:

{ task: "do stuff", task: "do other stuff" }

which sometimes is useful when you have front-end data with an N-number of entries but its a form that serializes to an object instead of an array. There are other use cases too.

qooleot··on A Wave of P.R. Data
Sure, statistics in marketing has been around for hundreds of years. I think his key point was alluded to with "just so it would go viral online" as being the new and growing theme.

The trick is getting the public at large to spread the message, and the goal not being the message itself but rather a higher pagerank and traffic. Before, the statistic itself had to be meaningful, i.e. "users of our weight loss supplement lost 43 pounds in the first month". Now, the statistic just has to be "shocking" but not actually sell anything.

qooleot··on Ask HN: Who is hiring? (December 2014)
Cary, NC Software company of 25+ years is looking to fill a Dev Ops position.

Responsibilities would include: Setting up, monitoring, and deployment for Node.js, Python applications and databases such as Redis and Postgres.

Experience required: 1-3 year experience, this is a junior position.

We are looking for someone who wants to learn, who is motivated, passionate and a hard worker ready to grasp knowledge and grow with our company.

This is an awesome opportunity to expand your skill set, in this environment you will be mentored by senior engineers. The right person, will be ready to grasp the opportunity, learn quickly and produce. Willing to accept college co-ops or internship students.

qooleot··on Ask HN: Who is hiring? (December 2014)
Cary, NC Software company of 25+ years is looking to fill a Dev Ops position. Responsibilities would include: Setting up, monitoring, and deployment for Node.js, Python applications and databases such as Redis and Postgres. Experience required: 1-3 year experience, this is a junior position. We are looking for someone who wants to learn, who is motivated, passionate and a hard worker ready to grasp knowledge and grow with our company. This is an awesome opportunity to expand your skill set, in this environment you will be mentored by senior engineers. The right person, will be ready to grasp the opportunity, learn quickly and produce. Willing to accept college co-ops or internship students.
qooleot··on Node.js, a popular tool for building modern internet services, has split in two
By what, hacker news discussions? It seems here only "new" things are discussed, but not as much about platforms growing and stabilizing. Its almost like Rust and Golang have taken over the world if you measure by this community.
qooleot··on Announcing Docker Machine, Swarm, and Compose for Orchestrating Distributed Apps
Just a single data point, but I went to a Redhat talk and their demos had several failing bugs. They also clicked around a lot, and said things like 'well, you now created an ip block, then designated an ip from the pool, but to make that actually work you need to...'.

I'm not so sure Redhat will make things simple enough and "just work" for non-corporate clients.

qooleot··on Julia: A fresh approach to numerical computing
Julia's http library, and furthermore the extensive communities around tech stacks like node.js and ruby. Although Julia is focused on mathematical problems, its still often important to pull data from resources on the net (google weather just as a trivial example). Or outputting results to a website to share results dynamically. This is one area where Python shines - being both a strong web framework (Flask and Django)as well as with scipy and pandas library for computation.

As a bootstrap to letting us do things like stream audio from the Web Audio API, and use Julia inside of an existing web app was to build a Node.js and Julia bridge:

https://github.com/waTeim/node-julia

It worked out very conveniently that Node.js through node-gyp can use C libraries, and Julia can run inside a C context.

I think the strongest use cases are node streams, and also online-learning models such as a recommender system. I.e. pass to Julia what the user has been interested in, and simply get back a few suggested items of high correlation.

qooleot··on PgREST: Node.js in the Database, compatible with MongoLab and Firebase API
JSON will be getting binary representation. Its just a matter of organizing sponsorship of the project.
qooleot··on The Coach Who Never Punts
One glaring miss in the statistical-only approach is that the psychology of a defense on 4th down and how that can impact outcomes. If you just use average net yards-play to extrapolate expected results for 4th down, or 3rd downs as per the berkely paper, thats not going to work out. Defenses will most certainly strategy to take more risks (and decrease the median expected yards gained in return for a small risk in a huge play), crowd noise can increase, etc.

The berkeley paper completely writes this off without evidence or reason, even with his assumption that offenses will not become more conservative with play calling, and its obvious a defense and crowd would act differently on 3rd and 3 than 4th and 3:

"Since it seems unlikely that the defense has substantially more scope than the offense to affect the distribution of outcomes"

Primarily, the goal on defense is to get off the field, so other than special situations like goal-line or the edge of field goal range, its ok to give up 3 yards and even 4 is fine. You really just need one great play out of 3 - a blocked or missed pass, tackle for loss, etc. and they're 3-and-out.

The paper admits the entire basis and math would be wrong if his assumption was misplaced:

"Thus using third downs to gauge what would happen on fourth downs would lead to overestimates of the value of going for it."

On 4th down and 1-3 yards, everything changes. You try to play every play as hard as possible, but you bring something special when its 'us or them, right here, right now'. Thats partially why (the other reason is there is less room to pass) that you see teams march down the field and can't get the last yard 4 tries in a row. I know the offense also steps up, but in a short running play against relatively even teams, defensive players are usually shorter (leverage) and have an extra player (unless the offense does wildcat with a mobile quarterback).

The other missing piece is they didn't seem to look at time left in the half and timeouts left. Punting in the first quarter is not the same as punting with 37 seconds and the other team is out of timeouts.

qooleot··on Scaling with Queues
Very cool, and awesome on opensourcing the agentredrabbit code!

We had a somewhat simpler but related "tons of data coming in via RESTful services and don't want to flood directly to the db with massive parallel connections" issue and solved it with Redis likewise. Since we used postgres as the backend, we (http://www.ivc.com) actually sponsored a project create a Redis FDW:

https://github.com/pg-redis-fdw/redis_fdw

so we could batch up 1,000s of inserts into a single database insert, thus reducing IO to disk.

← PreviousPage 2 of 2