Sign in

Forbes Lindesay

@forbeslindesay.co.uk
133 followers 153 following 101 posts

Founder @rollingversions.com

PostsRepliesMedia
Forbes Lindesay @forbeslindesay.co.uk · 29/09/2026
It’s frustrating how companies have the opposite view. I could easily get approval to spend loads of money on some AI tool that may or may not actually save time, but it would be virtually impossible to get the same budget to hire someone to help me be more productive.
010
Forbes Lindesay @forbeslindesay.co.uk · 22/08/2026
I recently got: if the attacker controls the input object, they can run arbitrary code by passing in `{ get optionName() { …malicious code here… } }` and waiting for you to read the optionName prop.🤦‍♂️
051
Forbes Lindesay @forbeslindesay.co.uk · 05/08/2026
This stuff frustrates me so much. The React team seem convinced they’re personally friends with everyone who might be smart enough to build a framework, so there’s no point documenting this stuff publicly.
000
Reposted by Forbes Lindesay
Roman @rman.dev · 09/06/2026
dependents.dev
dependents.dev
dependents.dev
dependents.dev - Analyze package dependents, downloads, and traffic across the ecosystem.
4267
Reposted by Forbes Lindesay
Ky @ky.fyi · 24/04/2026
I wrote about why I quit my job, and how weird and tiring tech feels these days.
ky.fyi
Do I belong in tech anymore?
On quitting, the spread of AI, and the loss of an ideal.
1281791544
Forbes Lindesay @forbeslindesay.co.uk · 13/04/2026
I only thought you weren’t escaping properly due to how you’d structured the LIKE part of the query.
010
Forbes Lindesay @forbeslindesay.co.uk · 13/04/2026
We also have a small check to catch when people accidentally wrap values in quotes: github.com/ForbesLindes... e.g. this errors for `SELECT * FROM users WHERE name="${name}"` as that would not produce valid SQL.
github.com
100
Forbes Lindesay @forbeslindesay.co.uk · 13/04/2026
This also lets you build up complex queries from fragments of SQL because we can tell the difference between an SQLQuery value and a raw string/object.
100
Forbes Lindesay @forbeslindesay.co.uk · 13/04/2026
That’s awesome. It’s the same approach (broadly speaking) that I take in www.atdatabases.org/docs/sql - by using a class of SQLQuery for the result of the tagged templates, I can ensure both with TypeScript and at runtime that you don’t accidentally pass raw strings as db queries.
atdatabases.org
Building SQL Queries
All SQL Databases in @databases use the same approach for building SQL Queries. Using tagged template literals gives you a powerful and flexible way of creating queries without opening yourself to SQL...
120
Forbes Lindesay @forbeslindesay.co.uk · 08/04/2026
If it is escaping parameters correctly, it should be `SELECT * FROM users WHERE name LIKE ${`%${name}%`}` instead of `SELECT * FROM users WHERE name LIKE '%${name}%'` since it’s the entire string after the LIKE keyword that is a parameter, not just the “name”
100
Forbes Lindesay @forbeslindesay.co.uk · 07/04/2026
This example looks like it has an SQL injection security vulnerability. Unless I’m missing something?
110
Forbes Lindesay @forbeslindesay.co.uk · 04/04/2026
If you need to ask about someone’s disability, talk directly to the disabled person. It really sucks to stand there while someone asks my partner if I’ll be able to cope with an activity. I can speak for myself.
010
Forbes Lindesay @forbeslindesay.co.uk · 04/04/2026
It feels like a huge part of the problem is real zoom links having technical looking domains like us02web.zoom.us instead of something clean and simple like us.zoom.com it makes it so much easier for malicious actors to make plausible looking fake zoom links.
010
Forbes Lindesay @forbeslindesay.co.uk · 01/04/2026
For what it’s worth, I do think the choice of keyword (I.e. `void`) is fine, but the semantics of it can be a bit weird/confusing as currently implemented.
000
Forbes Lindesay @forbeslindesay.co.uk · 01/04/2026
Ok, but what it actually means in JS is “evaluate this expression then resolve to the value, undefined”. Nothing to do with fn calls.
100
Forbes Lindesay @forbeslindesay.co.uk · 01/04/2026
Yes, the void keyword is totally unrelated: it really does evaluate to undefined and has nothing to do with fn returns.
100
Forbes Lindesay @forbeslindesay.co.uk · 31/03/2026
Using it for arguments and variables really should just be an error. What would be really great would be if `void` could mean “unknown except not a Promise” as currently I have to rely on lint rules to catch the floating promises instead.
110
Forbes Lindesay @forbeslindesay.co.uk · 31/03/2026
It would probably have made more sense for void to be equivalent to the “unknown” type, since if I accept a callback with a return type of void, I _probably_ don’t care if your fn actually returns something. There are currently loads of edge cases though.
210
Forbes Lindesay @forbeslindesay.co.uk · 17/03/2026
I get reports every few weeks that are of the form: > if you already have RCE, your library can be made to call arbitrary functions.
021
Forbes Lindesay @forbeslindesay.co.uk · 26/01/2026
I was playing around with ways to use this in markdown 12 years or so ago: github.com/ForbesLindes... I remember having a lot of fun with it.
github.com
GitHub - ForbesLindesay/ascii-math: node.js version of http://www1.chapman.edu/~jipsen/mathml/asciimath.html
node.js version of http://www1.chapman.edu/~jipsen/mathml/asciimath.html - ForbesLindesay/ascii-math
000
Forbes Lindesay @forbeslindesay.co.uk · 23/01/2026
Runtime validation for TypeScript: I’ve just launched a new documentation site for funtypes, along with version 6.0.0, which has a smaller bundle size, better type inference, and better error messages. funtypes.dev
funtypes.dev
Funtypes - Runtime validation for TypeScript
Funtypes validates and parses runtime data in TypeScript with complete type safety.
030
Forbes Lindesay @forbeslindesay.co.uk · 19/01/2026
Thank you for building this. Today I was able to use it to ship a new version of www.npmjs.com/package/funt... that's ESM only. I would otherwise have needed to keep supporting CommonJS for much longer. It removes so much mess.
npmjs.com
020
Reposted by Forbes Lindesay
Joyee Cheung @joyeecheung.bsky.social · 19/01/2026
First and likely the most anticipated, marking require(esm) as stable. I wrote a blog post about the journey of it going from experiment to stability: joyeecheung.github.io/blog/2025/12...
joyeecheung.github.io
require(esm) in Node.js: from experiment to stability
More than a year ago, I set out to revive require(esm) in Node.js and landed an experimental implementation. After a lot of iteration and battle-testing, require(esm) is now unflagged across all suppo
271
Forbes Lindesay @forbeslindesay.co.uk · 27/10/2025
It's one of my favourite TV shows. The pilot is way longer than any of the other episodes as it has to introduce everyone. The other episodes are much quicker to get into the action.
110
Reposted by Forbes Lindesay
Accessibility Awareness @a11yawareness.bsky.social · 11/10/2025
Automatically updating content can be extremely distracting, especially for users with vestibular disorders or attention difficulties. This could force users to scroll through page content to not see the animation, or to just look away. Allow animations to be paused or stopped.
04511
Forbes Lindesay @forbeslindesay.co.uk · 04/10/2025
That seems like it would make it a bad way to execute anything.
000
Forbes Lindesay @forbeslindesay.co.uk · 30/09/2025
In many games I'm happy for my character not to share my physical limitations, but it would be nice to occasionally have the option to put more of myself into my character.
040
Forbes Lindesay @forbeslindesay.co.uk · 30/09/2025
Most recently I've been playing Baldur's Gate 3, where my character carries a staff on their back, but I wish I could have them hold the staff in their hand as they walk. I assume it just didn't occur to the developers that anyone would want that, or maybe it was just too much extra work to animate.
120
Forbes Lindesay @forbeslindesay.co.uk · 30/09/2025
This seems every bit as relevant today as when it was written. I use a walking stick due to a physical disability, and it's disappointing how rarely that can be represented in video game characters.
120
Reposted by Forbes Lindesay
Dave Rupert @davatron5000.bsky.social · 23/09/2025
This post by @samwho.dev explaining Big-O notation in human terms with concise code samples and simple illustrative demos is a joy to read. samwho.dev/big-o/
samwho.dev
Big O
A visual introduction to big O notation.
24510
Forbes Lindesay @forbeslindesay.co.uk · 14/09/2025
The vite plugin (www.npmjs.com/package/@vit...) also looks like it may be a useful reference point. I imagine the article would guide you through building something like that, but the most basic possible version with the minimal features to make RSC work.
npmjs.com
@vitejs/plugin-rsc
React Server Components (RSC) support for Vite.. Latest version: 0.4.29, last published: 5 days ago. Start using @vitejs/plugin-rsc in your project by running `npm i @vitejs/plugin-rsc`. There are 4 o...
120
Forbes Lindesay @forbeslindesay.co.uk · 14/09/2025
This would be awesome, and I wouldn’t mind helping out. overreacted.io/why-does-rsc... and devongovett.me/blog/parcel-... do get you a lot of the way there, but a minimal implementation of react-server-dom-yourbundler is missing, and would be extremely difficult to build on public APIs.
overreacted.io
Why Does RSC Integrate with a Bundler? — overreacted
One does not simply serialize a module.
110
Forbes Lindesay @forbeslindesay.co.uk · 14/09/2025
I think you underestimate what the community can build when you don't actively exclude them. I'm not asking you to teach anyone how to build a bundler.
110
Forbes Lindesay @forbeslindesay.co.uk · 14/09/2025
It's a little disappointing that the advice seems to be "please don't try to understand this, it's too difficult for you". I think the reason people can't contribute is largely that github.com/facebook/rea... and github.com/facebook/rea... don't seem to be published to npm, and partly a lack of docs
github.com
react/packages/react-server at main · facebook/react
The library for web and native user interfaces. Contribute to facebook/react development by creating an account on GitHub.
200
Forbes Lindesay @forbeslindesay.co.uk · 14/09/2025
If I have time I'll try and pick apart the webpack example. It's tricky to even work out where it's calling react though as it's referencing packages like "react-client", which I'm guessing are bundled as part of preparing it for npm.
100
Forbes Lindesay @forbeslindesay.co.uk · 14/09/2025
Not sure what `npm install react-dom-<bundler>` is? That's not a valid package name.
100
Forbes Lindesay @forbeslindesay.co.uk · 14/09/2025
I wouldn't want to write a PR for these docs without first having docs for the APIs that the bundler is meant to generate calls to. i.e. bsky.app/profile/forb...
000
Forbes Lindesay @forbeslindesay.co.uk · 14/09/2025
It does repeatedly say things like "They are rendered before your application is bundled" though, which is either wrong, or using "bundled" to mean something different to how "bundled" is typically used in frontend development.
110
Forbes Lindesay @forbeslindesay.co.uk · 14/09/2025
I think it does mostly say most of this, that's how I've got to the point of understanding what I understand so far, which I'm not confident is fully correct.
100
Forbes Lindesay @forbeslindesay.co.uk · 14/09/2025
As I understand it, the only special thing the bundler has to do is to call a React API after the page loads to give React a reference to the client components it needs. I can't find any docs for that API though.
100
Forbes Lindesay @forbeslindesay.co.uk · 14/09/2025
It would help a lot to document the process of using them without a framework. i.e. for a toy example, what does the output of a bundler look like for a single RSC rendering a single "Client Component".
110
Forbes Lindesay @forbeslindesay.co.uk · 14/09/2025
I think it may take a page to explain what they are, but I think it's better to give people not enough information to form a full mental model, than give them info that forms an incorrect mental model.
100
Forbes Lindesay @forbeslindesay.co.uk · 14/09/2025
If you're willing to make more radical changes, I'd consider something like "'Server Components' are a new type of Component that renders in an environment that's separate from your existing 'Client Components' (whether those Client Components are rendered in the browser or using SSR)."
120
Forbes Lindesay @forbeslindesay.co.uk · 14/09/2025
As a starting point, I'd consider "Server Components are a new type of Component that renders in an environment separate from your client app or SSR." i.e. remove the parts of the existing sentence that are not true in many (most?) environments.
100
Forbes Lindesay @forbeslindesay.co.uk · 14/09/2025
If most devs don't understand bundling, the existing explanation is confusing because it includes bundling, which devs don't understand. If devs do understand bundling, the existing explanation is confusing because this explanation does not correctly map to how bundling works in most applications.
100
Forbes Lindesay @forbeslindesay.co.uk · 14/09/2025
Related to this, it's worth noting that SSR doesn't necessarily even run the bundles, it can be running the same code un-bundled in a node.js environment.
100
Forbes Lindesay @forbeslindesay.co.uk · 14/09/2025
I think it's really more of a trust boundary than a network boundary. "client" is the untrusted environment directly handling user input. RSC is the trusted environment with potentially direct database access.
110
Forbes Lindesay @forbeslindesay.co.uk · 14/09/2025
I think "Frontend"/"Backend" would be clearer, as at least those terms are not already given specific (conflicting) meanings in the React docs.
130
Forbes Lindesay @forbeslindesay.co.uk · 14/09/2025
It's also reusing the term "server", which is already used in "SSR", making the docs far more confusing than they need to be. There's also a network gap within "client" between SSR and rendering in the browser, and there's not guaranteed to be a network gap between SSR and RSC.
100
Forbes Lindesay @forbeslindesay.co.uk · 14/09/2025
Bundling has nothing to do with RSC, so it's not part of this explanation. As @danabra.mov points out, you could have a (very inefficient) bundler that generates a single bundle for your entire application.
200