Chat Logs

  1. NeXeNyeah, i got the plugin. it was weird, no syntax highlighting at all
  2. enoqam I the only one struggling with spring security? I find myself having to debug into running source code to figure out how to properly implement their primitives
  3. ParaYeah it can be a chor(tl)e. Use AI to get one working setup and forget it.
  4. deeboat least in spring boot it's quite easy, you just have to find the right extension points with minimal "custom code", we have a custom login + oauth + saml logins in the same app using the same authorities and it works nicely
  5. NeXeNenoq: is it difficult to think in filter chains ?
  6. NeXeNhonestly i like spring security. but the filter chains get confusing. and yeah deebo, customer filter, provider, or decoders are pretty coo
  7. deeboread the docs / use AI (and ask for references) to try to find the correct way, way too easy to do things in a way that works, but is still wrong and will cause issues some time in the future
  8. NeXeNi am not sure i'd use AI. security is kinda important
  9. deebolike i just noticed if you inject any webclient.Builder variant and build it, the default connection factory for httpcomponents5 creates a 5 per route capped connection pool at each built client
  10. NeXeNi asked an LLM to add javadoc comments to some code. i didn't pay attention, i figured easy thing. i don't vibe code so i didn't realize the dangers. but every one of the controllers it touched had it's cors policy set to allow anything/slut mode
  11. deebothat's why you verify and don't trust it blidnly, it can just churn through a lot of pointless experimenting and typing in minutes
  12. NeXeNyeah, you gotta customize connection pools. i guess back when they first designed it they set it very low on the pool size
  13. NeXeNyou can setup a web client config and return a pooling connection manager and you can set it's max connection per route and total
  14. NeXeNdeebo: that's kind of an interesting way to look at it. i guess maybe that's my best use, i'll ask to look at what a config file should look like or whatever, and get ideas
  15. deebothey offer no "proper" extension point for the http connection pool, which is the annoying part
  16. deeboyou have to create a custom connection factory that's shared and always provides the same factory using the same pool
  17. NeXeNPoolingHttpClientConnectionManager wow what a mouthful
  18. Parare: my complaint about all-the-patterns in hc4...
  19. deeboyeah have to see if there's something else to try with more sensible defaults etc, hc5 even does retries by default
  20. NeXeNi don't know it's internals and i just woke up haven't had coffee so the code still looks like squiggle marks to me. but using those patterns unlocks a way of doing things that you don't get without
  21. NeXeNcustom factories are actually really great when you think about it. years ago it was not so easy to get such a thing without a lot of work
  22. ParaJDK's SPI is somewhat underutilized mechanism but actually great.
  23. enoqNeXeN: filter chains isn't the problem, it's things like figuring out why your custom authentication filter does not save your session to redis, stepping through base classes, debugging which filter chains are active and what beans were injected into those
  24. enoqplus all the callbacks that you want/need to interact with to make use of built in features like throttling
  25. enoqmost of the stuff you find is just about very standard backend applications (form login, etc) which no one really writes anymore
  26. enoqit being different from normal spring also does not help (don't use @Service for filters for instance, do manual DI)
  27. enoqto me at least it feels like I can't use this stuff just from a quick glance over the APIs, I kinda need to read source code
  28. NeXeNi mean it's a problem with the pattern, yes, and para was pointing out the over-reliance on pattern conventions
  29. NeXeNyou can't glance at a complex pattern and grasp it quickly, you have to learn the pattern and then it becomes intuitive how to debug it. and i struggle with it, i know the pain
  30. NeXeNso i suppose their docs have fallen short and their design is non-intuitive to the man on a mission
  31. NeXeNi understand it well now, but there was a day when i was in hell. that's the problem with making something that stretches all the way from heaven to hell. you end up in both places, usually hell first. but once you get the hang of it, it's not too bad. and yeah i read the source too often times because it's easier for me
  32. NeXeNnot sure i've gotten to heaven yet, but when you think about all the things you had to do before to get the type of flexibility with pretty good performance, it's not a bad design it's just one with a grand scope which makes it hard to glance at and figure out what to do
  33. NeXeNoften times i only come across it when something is wrong and hard to fix, so i have to tell myself that i shouldn't let my point of view spoil what is really going on. i hated it for all the wrong reasons in the beginning