HNHacker News
TopNewBestAskShowJobs

thdxr

808 karma · joined August 25, 2017

[ my public key: https://keybase.io/thdxr; my proof: https://keybase.io/thdxr/sigs/l4kb7Hf_jl35s_WMc0geyu0H9nOfFY-mv3wLQG9xqVU ]

ZB7NfzWsA6

submissionscomments
thdxr··on Annoying and alarming things about OpenCode
not too much actionable here. most of the more glaring issues are already fixed in our upcoming v2 if you'd like to try beta: https://x.com/thdxr/status/2075636594640376165

some things mention are outdated - particularly the tool call pruning feature. this has been disabled by default for a while specifically because of complaints like this

when we looked through our data it's not so clear cut that it's net negative https://x.com/thdxr/status/2048268697790300343

also i'm pretty excited about our new system prompt approach - can define each component in a way that avoids busting the cache when they change. eg that midnight issue: https://x.com/thdxr/status/2070721003924103651

providers (anthropic is the first) are supporting this as a native concept

thdxr··on Rift: Better Alternative to Git Worktrees
this is a 1 day old vibe coded experiment where i'm exploring some ideas
thdxr··on OpenCode – Open source AI coding agent
API support was never removed
thdxr··on OpenCode – Open source AI coding agent
this isn't true

it will use whatever small model there is in your provider

we had a fallback where we provided free small models if your provider did not have one (gpt nano)

some configs fell back to this unexpectedly which upset people so we removed it

thdxr··on Anthropic tries to hide Claude's AI actions. Devs hate it
we are going to implement this
thdxr··on Unauthenticated remote code execution in OpenCode
the email they found was from a different repo and not monitored. this is ultimately our fault for not having a proper SECURITY.md on our main repository

the issue that was reported was fixed as soon as we heard about it - going through the process of learning about the CVE process, etc now and setting everything up correctly. we get 100s of issues reported to us daily across various mediums and we're figuring out how to manage this

i can't really say much beyond this is my own inexperience showing

thdxr··on Unauthenticated remote code execution in OpenCode
hey maintainer here

we've done a poor job handling these security reports, usage has grown rapidly and we're overwhelmed with issues

we're meeting with some people this week to advise us on how to handle this better, get a bug bounty program funded and have some audits done

thdxr··on Crush: Glamourous AI coding agent for your favourite terminal
docs for that are here: https://opencode.ai/docs/models/#local
thdxr··on Opencode: AI coding agent, built for the terminal
curious why /clear instead of making a new session?

and nothing expires out from the session until you get near the context window max - at which point we do a compaction process

thdxr··on Opencode: AI coding agent, built for the terminal
we actually do heavily use prompt caching now
thdxr··on Opencode: AI coding agent, built for the terminal
it's implemented in the backend, will expose in frontend soon
thdxr··on Opencode: AI coding agent, built for the terminal
hey one of the authors here

we're a little over a month into development and have a lot on our roadmap

the cli is client/server model - the TUI is our initial focus but the goal is to build alternative frontends, mobile, web, desktop, etc

we think of our task as building a very good code review tool - you'll see more of that side in the following weeks

can answer any questions here

thdxr··on Opencode: AI coding agent, built for the terminal
author here - right now it's all the same prompts as claude code

but we're going to make all this very configurable next week

thdxr··on Opencode: AI coding agent, built for the terminal
author here

we're very focused on UX and less so on LLM performance. we use all the same system prompts/config as claude code

that said people do observe better performance because of out of the box LSP support - edit tools return errors and the LLM immediately fixes them

thdxr··on Next.js 15.1 is unusable outside of Vercel
what did i do to you!?
thdxr··on Remix Breaks Up with React
this isn't official and is missing context flagged it
thdxr··on Why is AI so popular when nobody wants it?
i think the idea that no one wants it is off

even if the models do not get better there is so much demand even just b2b

we have all these problems we can fix but we are totally limited by availability

cloud providers are overwhelmed by the demand - you can see this in how stingy they are with rate limits and how they don't even talk to you unless you've already spent a lot with them

thdxr··on Ask HN: How do you make a living contributing to and/or creating OSS projects?
build something popular then build a second thing that's as popular that's paid

it's pretty hard but that's what we did

thdxr··on OpenAUTH: Universal, standards-based auth provider
yes this was the intent
thdxr··on OpenAUTH: Universal, standards-based auth provider
thanks for writing this up! i have been looking at switching to PASETO instead of jwt

one thing though - the reason we use asymmetric encryption is to allow other clients to validate tokens without calling a central server

eg if you use AWS API Gateway they specifically have jwt authorization support where you can point them to a jwks url and it will validate requests

i need to look into the algorithm again - another constraint was trying to work across everywhere JS runs and i need to check if a better algorithm can be used that still works everywhere

thdxr··on OpenAUTH: Universal, standards-based auth provider
we will add SAML adapters as well

but the flow between your apps and openauth will always be oauth

thdxr··on OpenAUTH: Universal, standards-based auth provider
all of the data in there will be exposed via an API and also directly queryable since it's in your infra

but the idea here is openauth does not handle things like user storage - it just gives you callbacks to store the data in whatever database you're using

precisely because of what you're talking about - eventually you need access to it

thdxr··on OpenAUTH: Universal, standards-based auth provider
yeah this is a naming mistake a realized but thankfully in beta so can rework it

it used to be called authenticator! mixed it up unintentionally

thdxr··on Ask HN: Those making $500/month on side projects in 2024 – Show and tell
we sell coffee from the terminal

ssh terminal.shop

will do 6 figures in revenue the first year - not bad for a side thing!

thdxr··on Show HN: Self-Host Next.js in Production
llrt is extremely experimental and early - probably not the right fit

the latter is being worked on and there is a cloudflare adapter in that github org

thdxr··on SST: Container Support
when it comes to marketing the only thing that'll work is finding your true voice

i made this video because it reflects my sense of humor and is the kind of content i'd appreciate

anything outside business as usual will draw polarizing reactions

but in a noisy world that's the only thing that'll work

https://x.com/thdxr/status/1848794269848637510?s=46

thdxr··on SST: Container Support
we'll get there! we want to do everything we just go in order of demand
thdxr··on SST: Container Support
that's creating the raw ecs cluster

these components have

1. adding services that can auto scale

2. specifying load balancing config

3. automatic service discovery registration

4. network tunnel to access vpc resources from your machine

5. typesafe resource linking to access your resources in your application code

6. dev mode which brings up your system locally in a single multiplexed terminal UI

not pitching - just listing out why we bother doing anything. pulumi is great and if you want a more low level experience you should use it

thdxr··on SST: Container Support
can you share more about what DX is missing?

v3 i think has parity with v2 minus wide support for non-js runtimes

thdxr··on Terminal.shop codebase is open source
we sell coffee entirely over ssh - lot of people asked about the codebase when this was originally posted back in april and we've officially open sourced it
Page 1 of 6Next →