Hacker Newsnew | past | comments | ask | show | jobs | submit | fgkramer's commentslogin

But has this been thoroughly documented and are there solid libraries to achieve this?

My understanding is that this is not part of the spec and that the only way to achieve this is to sign/hash documents on clients and server to check for correctness


Well, it seems that the Apollo way of doing it now, via their paid GraphOS, is backwards of what I learned 8 years ago (there is always more than one way to do things in CS).

At build time, the server generates a random string resolver names that map onto queries, 1-1, fixed, because we know exactly what we need when we are shipping to production.

Clients can only call those random strings with some parameters, the graph is now locked down and the production server only responds to the random string resolver names

Flexibility in dev, restricted in prod


I mean yeah, in that Persisted Queries are absolutely documented and expected in production on the Relay side, and you’re a hop skip and jump away from disallowing arbitrary queries at that point if you want to

Though you still don’t need to and shouldn’t. Better to use the well defined tools to gate max depth/complexity.


All these extra requirements are why GraphQL never really captured enough mindshare to be a commonly selected tool


> GraphQL never really captured enough mindshare to be a commonly selected tool

It has been, at the scale it matters and should be used at. Most companies don't operate at that scale though.


I feel this would go down pretty bad considering the recent attempts to break E2E encryption on messaging. Also a very tempting vector for hackers and governments to track user’s behaviour


Multiple reports will automatically drop it from the usual list, unless there’s manual intervention to keep it from brigading attempts


I don’t buy it. It’s like a simple if statement. If Israel || Gaza || Nyetawhaterver then canFlag = false.

It has happened so so so many times, it’s naive at this point to believe the mod has no influence

It’s ridiculous that the biggest story on tech this minute has only 130 comments after 24 hours.


Isn’t Vercel’s CEO an investor of Clerk? A direct competitor to all these FOSS auth libraries.


Yes, see: https://news.ycombinator.com/item?id=45393382

Now better-auth had raised $5M so they can't undercut Clerky by too much or they'll fail


You understand the complexities and risks involved in maintaining the setup you’ve described?

It’d be unreasonable for most folks who just want to sell regular products and deal with marketing and sales. Those become the biggest tasks once they start getting traction (ask any relatively successful indie hacker). Paying the processor’s fee is worth it for most


I agree, which is why most people just use Shopify and make all this their problem.


You travelled the Atlantic multiple times over the year? That must be costly!


It was extremely costly :( But given how dangerous my peanut allergy was I considered it money well spent - it will probably save my life.


I’m in my first month of meds and I’d do anything that’s necessary to keep taking them.

I get it’s a catch 22 sometimes, especially trying to get diagnosed as an adult, but the benefits in my life have been immense.

I’d encourage you to muster the willpower (that we feel we lack so often) and book it if you can afford it. It took me years to get to this point and I wish I had done it sooner. Life is short, allow yourself to live it fully!


It's been many years now, there's no fixing anymore. The upwards trajectory stopped of course, but two years or so I got were enough to get me through college, into an okay job and even help me find a girlfriend. It's not ideal, but I'll live.


What’s PEM?


PEM is post-exertional malaise, the hallmark symptom of mecfs and some portion of what we call long covid. It's brutal, trying to push through it can lead to permanent worsening of symptom severity.


I’m currently wearing a CGM from Lingo (https://www.hellolingo.com/) which is pretty much the easiest way I’ve found to get my hands on one without a prescription (as I’m not diabetic).

So far it’s shown me that the sluggishness after a carb-heavy meal its heavily correlated with the glucose spike and how good my organism copes with it.

Can’t wait for the day we have our own Fallout style Pip-Boys!


Astro - https://astro.build/

Is probably the fastest thing you can use with extremely sensible defaults and that you can use alongside most web frameworks.

I've been using React for 6 years but this has changed my view of what is possible. You can write React/Vue and have it compiled statically or keep the component's interactivity.

It's the tool I had been looking for for years.


>Leverage Astro's unique zero-JS frontend architecture to unlock higher conversion rates with better SEO.

I don't know Astro, and I'm sure other frameworks write similar stuff on their landing pages, but this state of web design just makes me puke.


Me too. It’s absurd


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: