Quantcast
Channel: javascript – Gea-Suan Lin's BLOG
Browsing index pages (219 articles)
↧

example.com 的改版

看到「IANA's email about why example.com changed (via)」這篇還蠻有趣的,有人注意到 example.com 改版了,所以就寫信去問,結果意外的收到 Kim Davies (IANA 的 VP) 親自回信說明,裡面就提到因為流量問題所以這樣設計: As it tends to be heavily trafficked, the overall...

View Article


Image may be NSFW.
Clik here to view.

Iterator 多了 includes() 可以用了

在「BCD Universal Implementations Report Mon Sep 14 2026」這邊看到 Iterator 多了 includes() 可以用了: 從支援的 method 可以看出來 Iterator 常常缺東缺西的,這次總算是補了 includes() 進來了,不然常常都是用 ... 硬轉成 list 再來處理,但就喪失了 Iterator 的優點...

View Article


連三角函數的值都可以拿來 fingerprint 了...

看到「Your Browser Does Math Differently on Every OS, and Anti-Bot Systems Read the Bits (via)」這篇,重點很容易懂: Math.tanh(0.8) // 0.6640367702678491 genuine Linux Chrome (glibc) // 0.664036770267849 genuine...

View Article

querySelector* 的錨點

前幾天看到「Bookmark: querySelector immediate children with :scope」(應該是 Lobsters?),裡面引用了「querySelector immediate children with :scope」這篇。 在 browser 裡面沒辦法直接 element.querySelectorAll('> *') 這樣使用,需要透過...

View Article

npm v12 要預設關掉 post install script 了

npm 的 post install script 一直都是許多資安事件的破洞,其他各家 package manager 因為包袱比較少,都已經關的差不多了,像是 pnpm 的「Mitigating supply chain attacks」,或是 Bun 的「Add a trusted dependency」。 現在 npm 本家也進一步要處理這個問題了,npm v12 預設要關掉 post...

View Article


VoidZero 加入 Cloudflare

這幾天的消息,VoidZero 被 Cloudflare 買下來:「VoidZero is joining Cloudflare (via)」。 開頭就說明了 VoidZero 的產品,算是 JavaScript ecosystem 很有名的公司: VoidZero, the company behind Vite, Vitest, Rolldown, Oxc, and Vite+, is...

View Article

不使用前端 JavaScript 架構架設網頁的方式

前幾天 JavaScript broke the web (and called it progress) (via) 這篇在 Hacker News 上有一些討論。 作者在抱怨現在的前端 JavaScript 框架最主要的目的是 DX (Developer experience),而且會發現代價是犧牲了 UX (User experience),以及帶給 Architecture 與 DevOps...

View Article

Meta 與 Yandex 在 Android 上的違法追蹤

上個禮拜科技圈蠻熱的新聞,Meta 與 Yandex 在 Android 上利用「後門」的方式追蹤使用者,這邊抓個新聞連結:「Meta and Yandex are de-anonymizing Android users’ web browsing identifiers」,研究團隊發表的頁面則是在這邊:「Disclosure: Covert Web-to-App Tracking via...

View Article


暴力法取得 Google 使用者的手機號碼的安全漏洞

Hacker News 上翻到「Bruteforcing the phone number of any Google user」(via) 這個,作者意外爆破了取得手機號碼的安全漏洞。 主要是發現在測試 Google 服務在頁面沒有 JavaScript 的時候是否能用,意外發現登入頁可以用,而且因為沒有 JavaScript,所以很多現代服務的偵測 bot 技巧都無法使用,這包括了...

View Article


Image may be NSFW.
Clik here to view.

TAWPA (台灣公益揭弊暨吹哨者保護協會) 網站被植入木馬

新聞的部分應該蠻好搜的,這邊抓個中央社的:「揭弊者協會網站疑有惡意程式 黃國昌:沒有資安外洩」。 網站現在已經離線了,但 Internet Archive 上的資訊已經足夠判斷,看起來至少首頁就被植了? 從 https://web.archive.org/web/*/https://www.tawpa.org/ 可以看到首頁上最近的兩筆是這兩個 archive (以寫這篇的當下):...

View Article

Image may be NSFW.
Clik here to view.

TypeScript 的 tsc 用 Go 改寫的效果

剛剛微軟發表出來的稿子,TypeScript 的 tsc 改用 Go 寫之後編譯速度快很多:「A 10x Faster TypeScript」。 本來是用 node.js 跑的,現在改用 Go 可以預期會快很多。微軟初步測出來的 benchmark 是 10x 左右: 不過目前 feature 還沒全部在 Go 的版本實作完,只是抓個感覺: While we’re not yet...

View Article

Image may be NSFW.
Clik here to view.

JSON 與 JavaScript 再 Object 裡面元素順序的差異

標題要討論的是 { "a": 1, "b": 2 } 這樣的 object 再 JSON 與在 JavaScript 裡面有沒有定義 foreach 操作時 key 的順序。 剛剛遇到這個問題,印象中這邊有點 tricky... 找了對應的文件規範對了一下: JSON 定義成 unordered,所以不保證順序。 JavaScript 在 ES2020 後有定義一組特別的順序。 JSON...

View Article

Image may be NSFW.
Clik here to view.

CDN 造成的後端壓力問題 (Canva 的 outage)

Hacker News 上看到「The Canva outage: another tale of saturation and resilience (surfingcomplexity.blog)」這個,原文「The Canva outage: another tale of saturation and resilience」是去年十二月的時候在講 Canva 十一月時的 outage。...

View Article


Image may be NSFW.
Clik here to view.

Promise.try() 的支援度

在「BCD Universal Implementations Report Mon Nov 11 2024」這邊看到的,其中 Promise.try() 的部分,在 Safari 也實作後,所有主要的瀏覽器引擎都支援了,後面就是 release 的時間問題了: 原生的 Promise 物件功能不多,現在看起來陸陸續續加上去,寫起來會更方便一些...

View Article

uBlock Origin Lite (也就是 MV3 版本) 放棄在 Mozilla Add-ons 平台上繼續上架

整包故事大概都在「uBOL version updates missing in Firefox add-ons store #197」這邊了。 Raymond Hill (uBlock Origin 以及這次提到的 uBlock Origin Lite 的作者) 被 Mozilla 的 Add-ons Team 亂搞以後不爽,決定徹下 Mozilla Add-ons 平台上的 uBlock...

View Article


Node.js 實驗性支援 type 的語法 (但不會檢查)

在 Hacker News 上看到「Node.js adds experimental support for TypeScript (github.com/nodejs)」這個,標題有點誤導就是了,GitHub 上面的標題比較正確:「module: add --experimental-strip-types」。 從說明可以看到 --experimental-strip-types 參數只是接受...

View Article

axios 被植 malware

昨天的大新聞,這次的 supply chain attack 爆在 axios 上:「axios Compromised on npm - Malicious Versions Drop Remote Access Trojan (via)」,除非你的專案有刻意避開,儘量使用原生的 Fetch API 處理,不然幾乎都會用到,如果剛好在這段時間 npm update 的話就會中... 透過...

View Article


Image may be NSFW.
Clik here to view.

2025 年爬十億個頁面的成本

上禮拜看到的文章,作者在 AWS 上面只用 25.5 個小時就爬了 1B 個頁面,在 tune 過效能後的成本是 US$462:「Crawling a billion web pages in just over 24 hours, in 2025 (via)」。 作者在文章裡面有提到一篇 2012 年的「How to crawl a quarter billion webpages in 40...

View Article

Image may be NSFW.
Clik here to view.

直接用 uBlock Origin 做 Always Active Window 的效果

本來是用 Always active Window (Always Visible) 這個套件,但發現常常失效,結果在 review page 上看到有人用 uBlock Origin 做到: 這邊的 aeld 其實是出自 Resources Library 的功能 addEventListener-defuser.js: Prevents attaching event listeners....

View Article

Cloudflare 買 Astro

上個禮拜就看到 Cloudflare 買下 Astro 的消息了,雙方都有發新聞稿:「The Astro Technology Company joins Cloudflare」、「Cloudflare Acquires Astro to Accelerate the Future of High-Performance Web Development」。 目前官方的新聞稿上面是提到...

View Article
Browsing index pages (219 articles)


Latest Images