539 karma · joined November 30, 2011
anthonybishopric.com
Given the following literal:
<script type="text/javascript"> <div><%= something %></div> </script>
Go 1.8 will escape the EJS delimiter, breaking the template. I.e.:
<script type="text/javascript"> <div><%= something %></div> </script>
I selected EJS specifically because I wanted a templating library that didn't conflict with html/template's handlebars syntax. If you're in the same boat you'll want to find a template engine with non-html entity delimiters.
It's in a business's best interest, and exceedingly common practice, to "land and expand" with something clear and compelling, and following that add features to compete with alternative solutions. I don't think there's anything inherently altruistic about CoreOS that would keep Rocket lean in the long-run, especially as they begin migrating their various tools away from Docker containers.
Phpdoc may not seem ideal, and it's not, but it has afforded some significant flexibility
$2M/30years => $66k/y.
There are many other ways to make PHP beautiful. In fact, you can make object models that are almost as flexible, DRY and elegant as they would be in any other language.
Call me a conspiracy theorist but one thing the future holds for us is more of this. Except it will take place in scientific literature, respected publications, maybe in our own homes and (purposefully or not) by the people we know and trust. We'll need a factcheck.org for regular news.
"Sponsor post" is probably as good as we will ever get from The Atlantic.
Also, how often is it useful to define a class at test time that is initialized by production code (from the section I Still Have Serious Dependency Issues!). This seems like an unlikely use case.
Maybe it'll turn out that there's a huge need for some intermediate between IFTTT and vanilla API use, but I'm having a hard time seeing when.
This very much reminds me of the Worse Is Better line of thinking.
"Of course, we can get very slow algorithms by adding spurious loops before the first test of X against the Ai . However, such easy solutions are unacceptable because any fool can see that the algorithm is just wasting time. Therefore, we must look for an algorithm that does indeed progress steadily towards its stated goal even though it may have very little enthusiasm for (or even a manifest aversion to) actually getting there."
Zeno would be pleased.
For one, my heart wasn't in it. It was like I had spent months crafting an idea that I thought an audience of customers would receive happily - only to realize I wouldn't use it or care about it myself. It also had become a business proposition I couldn't succeed at myself. I needed more help than ever.
So I packed up my stuff and killed it. It was painful, but I am glad I had the ability to see the truth before getting so bad as to be like the scene painted in this post. That said, it's not always obvious like it was in my case; I have tremendous respect for folks that go through this and fight to the bitter end.
Actual tools: Evernote (on all my devices, plus the email address that I send them to), the iPhone reminder app, Google Tasks.
It's the first query, the metadata one, that applies the passed arguments in a raw form directly to the query. The exploit takes place inside of a 'show' operation. It's totally unprotected and lets you run pretty much any select you're interested in.
It also goes beyond prepared statements - the metadata query in question is totally separate from the one specified by any parameterized query you'd pass using something like ('id = ?', params[:id]). So essentially, as a developer, you can't do anything better. This is kind of on the framework side alone :/