Have I already mentioned that I liked reading the Richard Branson's auto-biography ?
I honestly think it was a gem of a book which I picked up in the Gatwick airport on the way to Dublin from Minsk. That is a story about the life journey told with a lot of humor, filled with some absolutely hilarious accounts of various events and with some very serious thoughts about doing business and contributing to saving the humanity.
You might want to ask, what is it all to do with the web services or software development given this post is not marked with [OT] ?
During his student days, Richard set up the Student Advisory Centre which consulted students on all the issues they could have, free of charge. One of their slogans was "Give us your headaches". This centre still operates today.
I thought, when I was reading about it, that to some extent, this is what the OS business model was partly about. In OS we are working on projects such as CXF and we are determined to make it all work really well, without any headaches, in the most demanding environments.
The OS business model is partially about providing the insurance that customers will experience no headaches when running such OS-driven projects in their productions. In fact this model has been proven very successful, by such top companies such as RedHat for example.
Are you considering to start using CXF but a bit concerned what will happen further down the road with all the OS development going on into it ?
Give us your headaches :-)
Wednesday, October 27, 2010
CXF : Here we come !
I'm happy to confirm that after a short break I'm going to have a chance to resume working on CXF and its JAXRS project in particular.
I'll join Dan and the rest of the Sopera OS team and we will be determined as ever to bring you the best production-quality web services framework around.
And with your help we will make the CXF users and dev lists the "hippiest place to be", the phrase is borrowed from a Richard Branson's auto-biography.
CXF won't be the only effort we will focus in Sopera but it is going to be one of the main ones.
Stay tuned.
I'll join Dan and the rest of the Sopera OS team and we will be determined as ever to bring you the best production-quality web services framework around.
And with your help we will make the CXF users and dev lists the "hippiest place to be", the phrase is borrowed from a Richard Branson's auto-biography.
CXF won't be the only effort we will focus in Sopera but it is going to be one of the main ones.
Stay tuned.
Goodbye JBoss
So after less than 6 months after starting to work for JBoss I decided to quit and accept an offer from Sopera. In hindsight, I'm thinking that talking about the career publicly is not always the very best idea - spending such a short period of time at one of the leading company in the industry is not something that will improve my CV.
Back in April/May I was indeed looking forward to that great opportunity and it was not a stop-gap measure by any means. But CXF and CXF JAXRS are calling me back - it is next to impossible to resist. I'll blog about it next but this post is about JBoss and I'd like to talk about it a bit.
Just 6 months ago I had a fairly vague idea about what JBoss were doing, apart from knowing that they were part of RedHat, that it was an application server and that their JBossWS project was providing a CXF JAXWS integration option. And of course I knew about RestEasy.
In the reality, JBoss is a very live, active and progressive project, with a lot of very clever and innovative people working on it and who are really passionate about JBoss. And they have a very open and democratic environment with everyone being able to express their thoughts aloud.
I've promised in my previous post I'd link to various JBoss subprojects. Here are the links to some of them :
JBossWS : Web Service Framework for JBoss AS
RestEasy : JAX-RS implementation with various features
PicketLink : STS, etc
JBossTS : While many are saying that WS transactions support is next to impossible to provide this team just does it
HornetQ : Putting the buzz in messaging
As far as I'm concerned it is obvious I've given away the real opportunity with a great company. That said, the life is about many opportunities, and I'm about to pursue the new and exciting one, with the young and innovative company.
Goodbye JBoss, Hello Sopera !
Back in April/May I was indeed looking forward to that great opportunity and it was not a stop-gap measure by any means. But CXF and CXF JAXRS are calling me back - it is next to impossible to resist. I'll blog about it next but this post is about JBoss and I'd like to talk about it a bit.
Just 6 months ago I had a fairly vague idea about what JBoss were doing, apart from knowing that they were part of RedHat, that it was an application server and that their JBossWS project was providing a CXF JAXWS integration option. And of course I knew about RestEasy.
In the reality, JBoss is a very live, active and progressive project, with a lot of very clever and innovative people working on it and who are really passionate about JBoss. And they have a very open and democratic environment with everyone being able to express their thoughts aloud.
I've promised in my previous post I'd link to various JBoss subprojects. Here are the links to some of them :
JBossWS : Web Service Framework for JBoss AS
RestEasy : JAX-RS implementation with various features
PicketLink : STS, etc
JBossTS : While many are saying that WS transactions support is next to impossible to provide this team just does it
HornetQ : Putting the buzz in messaging
As far as I'm concerned it is obvious I've given away the real opportunity with a great company. That said, the life is about many opportunities, and I'm about to pursue the new and exciting one, with the young and innovative company.
Goodbye JBoss, Hello Sopera !
Monday, May 24, 2010
The New Beginning : JBoss
Today I've started working for JBoss, the division of RedHat.
This is a truly new beginning for me and I'm looking forward to my new career in JBoss and RedHat. I'll have a chance to work with and learn from a lot of great engineers and contribute to a number of interesting projects.
It is a big new world out there. RedHat Linux, JBoss, ws and restful services, clouds, virtualization, messaging, transactions, osgi, etc... I'm optimistic and hopeful it will be a great ride.
From now on I'll be linking to various RedHat/JBoss related projects, news, etc.
I'll continue working in a web services area. I'll be involved in a JBossWS project. I'll also have a chance to work with RestEasy and possibly contribute to it; it is a powerful JAXRS implementation which has been leading alongside with Jersey and it is also likely to become a home for realizing and implementing a number of pragmatic ideas coming from the Rest-* effort.
I also have a message for those of you who have decided to try or use CXF JAXRS. It is a project I've put a lot of effort into and I'm really keen to continue supporting CXF JAXRS users which is what I'll be doing though the time I'll be able to spend on it will be limited to after-work hours and weekends. I think CXF JAXRS will do well - it's become quite solid with respect to helping CXF users with developing REST-based services. The development effort which will go into it will become quite limited - but I hope it will live.
Stay tuned and have fun !
This is a truly new beginning for me and I'm looking forward to my new career in JBoss and RedHat. I'll have a chance to work with and learn from a lot of great engineers and contribute to a number of interesting projects.
It is a big new world out there. RedHat Linux, JBoss, ws and restful services, clouds, virtualization, messaging, transactions, osgi, etc... I'm optimistic and hopeful it will be a great ride.
From now on I'll be linking to various RedHat/JBoss related projects, news, etc.
I'll continue working in a web services area. I'll be involved in a JBossWS project. I'll also have a chance to work with RestEasy and possibly contribute to it; it is a powerful JAXRS implementation which has been leading alongside with Jersey and it is also likely to become a home for realizing and implementing a number of pragmatic ideas coming from the Rest-* effort.
I also have a message for those of you who have decided to try or use CXF JAXRS. It is a project I've put a lot of effort into and I'm really keen to continue supporting CXF JAXRS users which is what I'll be doing though the time I'll be able to spend on it will be limited to after-work hours and weekends. I think CXF JAXRS will do well - it's become quite solid with respect to helping CXF users with developing REST-based services. The development effort which will go into it will become quite limited - but I hope it will live.
Stay tuned and have fun !
Wednesday, May 19, 2010
New Kid On the Block : JBoss OSGI
I've been reviewing today the JBoss OSGI documentation and I've been really impressed. They can work with existing containers such as Equinox and Felix but can do well on its own too. Check the documentation - it is very well written.
For some of you a 'new kid on the block' may not sound right if you've worked with or heard of JBossOsgi already :-).
It's likely to affect the existing balance on the market of OSGI-aware frameworks. Watch this space.
For some of you a 'new kid on the block' may not sound right if you've worked with or heard of JBossOsgi already :-).
It's likely to affect the existing balance on the market of OSGI-aware frameworks. Watch this space.
Tuesday, May 11, 2010
OT : bbc.co.uk and tut.by
Time and time again I'm being very impressed by the quality of [bbc.co.uk|http://www.bbc.co.uk/]. It is just possibly the best web site which I've seen. Their "Live Football" section is the best one too :-)
The [tut.by|http://www.tut.by/] (Belorussian news portal) is quite impressive too, not as powerful as the BBC one - but good nonetheless.
The [tut.by|http://www.tut.by/] (Belorussian news portal) is quite impressive too, not as powerful as the BBC one - but good nonetheless.
Friday, March 26, 2010
Converting FIQL expressions into SQL queries in CXF JAXRS
I've done some more work on the search extensions so that users can easily introspect a given SearchCondition instance representing either a primitive or complex query and also added a utility SearchCondition.toSQL(String tableName, String... columnNames) which can be used to convert this search condition into an equivalent SQL query to be subsequently executed against a database.
For example,
Here are some clarifications. First, note that the above code shows that a FIQL parser creates a search condition but it is a unit test code, the actual user code will use a SearchContext instead in a type safe way, providing a bean class to it. SearchContext will create an instance and will inject into it the property values, those provided and extracted from the original FIQL expression.
This provides for a possibility to protect against possible SQL injection attacks at the Java and the bean validation levels. For example, if a Book bean has an integer 'id' property then there's no way an unsafe FIQL query such as 'id==DROP%20users' can result in a 'DROP users' value injected due to a NumberFormatException.
Additionally, bean setters may have some custom validation logic and the CXF FIQL parser may also get enhanced to check for the bean validation annotations.
Perhaps you might want to give it a try and see how safe this option of auto-converting FIQL expressions into SQL queries is ?
In the end of the day, the good thing is that you actually do not have to use
SearchCondition.toSQL to get the SQL query. Suppose you are still concerned about the security or see that this method is not going to help you with building the advanced SQL queries which you actually use in the production, may be you are using java.sql.PreparedStatements or perhaps you don't even use a relational database but rather work with say Cassandra. If it is the case then just introspect a SearchCondition by getting to all the subconditions it has, and build a query which suits best.
For example,
// find all conditions with names starting from 'ami'
// and levels greater than 10
SearchConditionsc =
fiqlParser.parse("name==ami*;level=gt=10");
assertEquals("SELECT * FROM table
WHERE
name LIKE 'ami%'
AND
level > '10'",
sq.toSQL("table"));
// find all conditions with names starting from 'foo'
// and those with names not ending with 'bar' or
// levels greater than 10
SearchConditionsc2 =
fiqlParser.parse(
"name==foo*;(name!=*bar,level=gt=10)");
assertEquals("SELECT * FROM table
WHERE
(name LIKE 'foo%')
AND
((level > '10'")
OR
(name NOT LIKE '%bar')),
sq.toSQL("table"));
Here are some clarifications. First, note that the above code shows that a FIQL parser creates a search condition but it is a unit test code, the actual user code will use a SearchContext instead in a type safe way, providing a bean class to it. SearchContext will create an instance and will inject into it the property values, those provided and extracted from the original FIQL expression.
This provides for a possibility to protect against possible SQL injection attacks at the Java and the bean validation levels. For example, if a Book bean has an integer 'id' property then there's no way an unsafe FIQL query such as 'id==DROP%20users' can result in a 'DROP users' value injected due to a NumberFormatException.
Additionally, bean setters may have some custom validation logic and the CXF FIQL parser may also get enhanced to check for the bean validation annotations.
Perhaps you might want to give it a try and see how safe this option of auto-converting FIQL expressions into SQL queries is ?
In the end of the day, the good thing is that you actually do not have to use
SearchCondition.toSQL to get the SQL query. Suppose you are still concerned about the security or see that this method is not going to help you with building the advanced SQL queries which you actually use in the production, may be you are using java.sql.PreparedStatements or perhaps you don't even use a relational database but rather work with say Cassandra. If it is the case then just introspect a SearchCondition by getting to all the subconditions it has, and build a query which suits best.
Subscribe to:
Posts (Atom)
