Community
Chat Logs
Sunday, March 1, 2026
- phaleththere's gonna be a police lurking and banning startups for life in the cyberspace https://freebsdfoundation.org/blog/getting-ready-for-the-cyber-resilience-act/
- blueheh
- bluethe biggest security risk for freebsd is probably having been infiltrated by woke activists
- bluebtw phaleth
- bluehttps://nevet.repopack.app/features
- blueI got it working
- phalethcool, it responds with a json, no clue what the data is about
- phalethfreebsd foundation is just posting about that on their blog
- phaleththe message is that companies will be required to make their SBOM public, but still, might wanna read that blogpost anyway
- blueyeah
- blueisn't publishing SBOM good though?
- bluelike, it shows you're up to date on your supply chain
- phalethnot sure, possibly it could required also for websites
- blueis that bad?
- blueanyway I always try to use as few deps as possible, I doubt that's gonna affect us greatly
- blueit's only gonna affect the deps-narcos :P
- phalethme too, but the thing is that software still decays
- bluetrue
- phalethmaybe a good time to start thinking about SSG for primate? at least for Svelte so that primate website can be processed
- phalethand markdown and the other few deps
- bluewhat's your understanding of SSG? producing only HTML at build time, instead of a .js bundle?
- blueit's probably better from a security POV...
- phalethproducing a jamstack site, where html, css and js are separate
- phalethjs should still leverage the dynamic import trickery client side and also fetch APIs and all the other relevant browser APIs
- blueyeah but what's the advantage of that versus the default monothilic build target?
- bluemonolithic*
- phaleththe advantage is that everything happens client side and all responses from APIs and other resources are merely static and always predictable, there is no database, no session, no anything on a remote place
- phalethand so there is no possibility to compromise the remote site
- phalethcause you know the remote site has dependencies to do all of it's dynamic processing
- bluebut the current primate website doesn't have any session/database anyway
- phalethand those can decay and so become compromised
- bluehm, fair
- phalethwell, but it still requires a server side runtime for dynamic processing
- blueyeah, I agree, the only thing here is that the server side runtime is basically almost an nginx replacement at this stage
- bluethere's almost no dynamism happening
- phalethif the website was static and ran only on say caddy then there are two deps, caddy and golang
- bluemhm, true
- blueso you want a --target=static for primate that generates an HTML file for every route?
- bluethese HTML files all embed the same JS and CSS
- phalethdon't remember how the primate cli works, but yeah
- bluethe only real question is how fetch-browsing then works. currently when you click a link in primate, it'll get you JSON for the next page
- phalethhtml should not embed anything if possible, it's a waste of cache opportunites for browsers
- bluewhat if we generated *one* html file, but that would contain embedded json?
- bluehm, still wouldn't work for search engines
- phalethsince the json is static it's fine and json should not be cached anyway, but js and css and images are different story and should be separate
- blueso what about this
- bluewe generate many html files, one per page. they contain all the HTML needed to show the page + js (for example, for switching between light/dark scheme)
- phalethbut consider adding content hashes to json filenames as well and then it makes sense to cache those
- bluebut in addition, we generate a content.json containing all the content, again
- blueso that when you click, it can replace it
- phalethcontent-1489g47sdf8.json
- blueonly problem is that json file would be huge
- bluesince we don't have svelte anymore in this scenario, we have no way of saying "this is the dynamic part"
- phalethwell, I'd say smaller than html
- phalethby about 30%
- bluehow? it would contain the HTML for every page
- phalethah, I thought it'd only have the data, but that's fine too
- phaleththen it's equal to the size of current html
- blueso my question is how do you do fetch browsing in this scenario. or well in this case client-based browsing, no additional requests after the first one
- phalethhmm, nope
- phalethjamstack is about making aditional request for anything via say fetch API, but only as long as that anything is not dynamically processed
- phalethit can be a static pre-rendered json file
- phalethwith response headers so the browser can aggresively cache it: content-4gf59d4sg8.json
- blueyeah but how do you see this working. I access primate.run/docs, I get the full HTML. then I click on /docs/quickstart, what happens?
- phalethhtml loads js file in the header and js fetches json
- phalethin the header to avoid layout shifting
- blueso the js fetches content-quickstart-somehash.json?
- blueand what does that contain?
- phalethyup, only when on that page
- phalethcould be html
- phalethmight as well ditch svelte and use htmx at this point
- blueindeed
- blueif you're getting the whole HTML, you'll lose things like scrolling state on the left bar
- blueI'm not sure SSGs have thought this through properly
- blueif you collapse the svelte world into a dumb html world, you can't replace custom nodes anymore
- bluewell you could, but you'd again need some js logic for that
- phalethcan manage the state client side using other means than just js if needed
- blueso you're building a UI again
- phalethI think htmx has that figured out too
- bluehm, I have a different proposition. we keep svelte, but it's running only on the client
- phalethbut anyway, it's not a problem of svelte, cause originally svelte was a client side only framework
- phalethyeah, svelte is fine
- blueand instead of fetching JSON for every click, it fetches a combined all-data.json on the first request. after that there is no subsequent request to the server, at all
- phalethmight as well ditch it and use poly again, cause of svelte 5's server side stuff
- bluethis combined json contains per data for the list of components and their data
- blueper page*
- phalethyeah, but that's a lot of data and you'll see SEO penalties
- bluewhy? the SEO doesn't need the JSON file
- bluethe SEO sees the html, the json can be loaded lazily
- blueand primate.run can work completely offline, too
- phaleththose tricks you describe used to work in the past, but not anymore, bots are way more clever nowadays
- blueyou just need the original request, then you're done
- phalethand of course any documentation site should work completely online and be servable using: python -m http.server
- phalethoriginal request?
- blueyes
- blueI do GET /docs, I get the HTML for docs, and also the /data.json which contains all component data I need for every other page
- blueso the website can work completely offline after the first request
- phalethyeah, but again that data.json combined is huge
- phalethah, you mean if the server goes down
- phaleththat scenario is not possible
- blueI mean if I'm offline
- blueI can also literally save the HTML file and it works
- phalethwell then get better interwebz and do not browser primate.run when going through the tunnel or something
- blueheh
- phalethalso if you go offline
- blueI wonder how big that data.json would get: you know, it only references a list of components and their data. it just contains the inner HTML for docs, and the data for the navbar
- bluemaybe 1-2 MB?
- phalethand the site is properly split as I described above, and you have visited the page you navigate previously, you will get a cache hit
- phalethso the page should load for you
- blueyes, that would work under the scenario I'm proposing jsut the same
- phalethand if you are in doubt you can always employ what some jamstack sites do, that is a service worker
- blueyes
- phaleththe bigger the site grows the bigger the data will get
- bluelet me ask chatccp
- phalethclanker will tell you to use hugo
- blueI'm not using hugo, hugo is dumb
- blueall SSGs are total garbage. there's no way to edit posts in an editor in the browser and they all expect you to have nvim
- bluethat's why I'm building priss, so I can edit primate blog posts in the browser and get direct feedback on how it looks
- bluethose SSGs aren't able to separate mentally the build phase from the run phase
- bluewhat I want is wordpress comfort during/before build phase, and SSGs comfort during run phase
- bluesomehow nobody had that idea until now
- phalethheh, yeah, hugo is just re-doing everything and depends on many things so it has to be run from within docker build
- phalethI think only the zig SSG framework checks if a page is already rendered using some sort of hashing tricks, but prolly not
- phalethbut I don't remember it's name
- phalethzine
- blueso the idea of priss is, you have dev mode. like `npx primate`. during that, you can access an in-browser editor that allows you to create content (pages/posts). you also get immediate feedback when editing their markdown (splitscreen).
- blueduring build though, this whole /admin area doesn't exist, like at all. we just generate those HTML pages. so unlike wordpress it's not possible to edit pages while the site is running
- phalethyou mean edit the page from devtools of the web browser?
- blueno, I mean edit the page inside your browser
- phaleththat'd be cool, just no idea how it'd work
- phalethok, but then you need some kind of editor like wordpress has
- phalethi forgot the name of that react thing
- bluesplit screen: textarea on your left, preview on your right
- blueyes that's no problem. this component is only used in the /admin area. the /admin area doesn't get bundled into the built website
- blueyou mean tinymce or whatever
- phalethsounds too complicated, someone like me would just use IDE to edit markdown and have esbuild to reload in the web browser
- phalethI think wordpress calls their editor gutenberg
- phalethbut it's a huge pile of react code
- blueyeah but someone like you isn't the target audience
- phaleth:)
- phalethI mean for starters it's fine to just use a code editor and have esbuild wrapper run in a console
- blueit's fine, but I wanna do more than that with priss
- bluebtw chatgpt said it's better to split the jsons
- blueyou win :(
- bluesomething something prefetching
- phalethyeah, well, jamstack is a super old concept that just works
- blue`You can keep “SPA feel” by prefetching the next page’s JSON on hover/viewport and caching in-memory (and/or Cache Storage).`
- phaletheven nowadays with all the nextjs or whatever bullshit rendering strategies
- phalethyup, browser already know what to do, just setup the HTTP server properly is the answer
- bluefor fully offline, it said it's better use a serviceworker and add --target=static:offline
- blue`Generate a service worker that precaches all HTML + page-data + assets (or a configurable subset)`
- phalethalso prefetching on hover is an old trick at this point
- blueyeah it sounds dumb to me though
- phalethand service workers also work well in all browsers
- phalethyeah, I'd not do prefetching on hover, thinking of mobile, anyway
- blueyeah that's dumb
- phalethusing on hover is dumb
- phalethexcept for changing colors slightly
- blueso I guess we'll do --target=static, and that generates docs/index.html, docs/start/index.html, and docs.json and docs-start.json
- bluesvelte becomes clientonly
- bluethe only thing I need to consider is if I move primate website to priss, what's the frontend of choice for priss
- blueideally should be chooseable
- phalethI'd recommend doing just svelte for now and bother with something else when somebody asks
- bluek
- bluephaleth: https://github.com/primate-run/primate/issues/253
- nevetProposal: `--target=static` (SSG output + client-only runtime) · Issue #253 · primate-run/primate
- blueI went over it and removed most of the ai slurp
- blueit had some interesting ideas like 4)
- bluethe proposal is mostly aligned with your suggestion, anyway
- phalethheh, nice
- phalethyeah, if json is embeded to html then there is no need to configure the HTTP server to add cache headers to json mimetype
- bluewell yeah, it's just the current page
- phalethright
- phalethwhat's weird that it suggest to use script tag for the json with type="applicaton/json", I'd recommend to use template tag https://developer.mozilla.org/en-US/docs/Web/HTML/Reference/Elements/template
- nevet<template>: The Content Template element - HTML | MDN
- bluebut template doesn't contain data, I think that's the difference
- phalethhmm? I mean the json could be inside template tag instead of the script tag
- phalethscript element will get evaluated by the browser
- bluehow does that help you? I thought <template> should be reused
- bluein combination with <slot>
- phalethhmm, nope, you can put template on the page as a data container for say JS to grab the data later
- phalethslot is a webcomponent tag I think
- phaleththe purpose of template tag is that it's not being rendered
- phalethand so browsers don't bother with it too much, except putting it to DOM
- blueah, that's cool
- bluecould you add a comment about that at the issue?
- phalethI can try logging into github, yeah
- bluecool
- blueawesome
- bluephaleth: I need to prioritise stuff for 0.37
- blueperhaps you can help
- phalethwell, that's easy, use primate for anything and whenever you run into a bug or something that you need then just update primate, rcompat or the rest
- phalethlike for example the thing we ran into yesterday that package.json is required at runtime for a prod app
- blueya