3
Are Web Components better for Cybersecurity?
(programming.dev)
A community for discussion amongst professional software developers.
Posts should be relevant to those well into their careers.
For those looking to break into the industry, are hustling for their first job, or have just started their career and are looking for advice, check out:
The actual question I'm reading from this is "are components that I build myself more secure than those provided by a third party library?"
You should correct me if that's not what your asking.
The short answer is "probably not." You can and will introduce bugs and vulnerabilities into your own software.
The main downsides of third party libraries are that they can have dependencies that you may not know about and vulnerabilities in third party libraries mean that a given vulnerability is just as widespread as a the library that it exists in.
Most "bad actors" are opportunists so a specific vulnerability being wide spread tends to work in their favor by increasing opportunities.
That said, I wouldn't waste your time rewriting functionality that already exists in other libraries unless you have a very compelling reason for it.
thanks for your thoughts.
thats not quite what im asking. im wondering if there are nuanced benefits to using webcomponents over something like react. with the key difference being the native support.
i hope with the webcomponent approach it could be "furture-proof" as it seems to be the rhetoric i hear around. im sure i wont have a great implementation any time soon, but id like to try out a few ideas to see if it holds-up. hopefully to lead to a "secure javascript ui framework" (which itself could be a whole discussion). i hope that by having it open source, i can point to an example to discuss and improve it.
it seem for the messaging app refactor, i'll be fine to use react on it. which is great because i already have a working-ish demo.