Sunday, December 18, 2011

Security in ASP.NET MVC

Security is a major concern when developing web applications. 
Here we'll talk about security in ASP.NET MVC

Some of the main concepts to understand when dealing with security are,
  • Authentication
  • Authorization
  • XSS
  • CSRF (Cross site request forgery)

Authentication

In ASP.NET there are two main authentication mechanisms. 
  • Windows Authentication Provider
  • Forms Authentication Provider

Authorization 

Basically you can apply AuthorizeAttribute filter to actions and controllers to achieve authorization in MVC. See how to create Custom AuthroizeAttribute.

Role based security #

This is useful when you need to enforce policies where you have multiple users with different privileges. .NET framework role-based security supports authorization by making information about the Principal, which is constructed from an associated Identity.

What is a principal object?

A principal object represents the security context of the user. It includes the user's identity and the roles to which they belong. In .NET, IPrincipal defines the basic functionality of a principal object.

Resources

Principal and Identity objects (MSDN)
Key security concepts (MSDN)
Custom IIdentity or IPrincipal (SO)
http://nipunasilva.blogspot.com/2012/07/filters-in-aspnet-mvc.html
http://www.codeproject.com/Articles/654846/Security-In-ASP-NET-MVC 

Wednesday, December 14, 2011

Memory Basics : Stack and Heap

Stack and heap are closely related with memory. Actually both are stored in computers RAM. Let's firstly look at what they are.

The Stack

Is a special region of the computer memory which holds temporary variables created by each function. This is managed and optimized by the CPU itself therefore you don't have to worry about allocating memory or anything as such. 

When you enter a function the variables defined inside the function will be pushed into the stack and when you exit the function the variables will be cleared from the stack. 

The stack is always reserved in LIFO (last in first out order). The stack is set aside for a thread. Each thread gets a stack.

 
Understanding stack in  JavaScript (blog article)

In JavaScript sometimes you'll encounter Maximum call stack exceeded in JavaScript error. This happens when you exceed the  call stack size in JavaScript. You can replicate this with a simple code like below



The Heap

Is the memory set aside for dynamic allocation. Unlike stack there is no pattern for allocation or deallocation of blocks from the heap. You must manually destroy variables on the heap. 

Heap can have fragmentation when there are lot of allocations and deallocations happening. Heap is usually responsible for memory leaks as well. 

In .NET unless you're building a compiler, knowing how stack and heap works is not needed much. (Stack vs. Heap in .NET - Stackoverflow).

Resources

Wednesday, December 7, 2011

Interesting Findings - JavaScript

Design

Design considerations for JavaScript API (Smashing Magazine)
  • Fluent interfaces
    • Referred to as method chaining
  • Treating undefined as an expected value
  • Named arguments (Python has this but currently not possible in JavaScript)
  • Argument maps.
    • visual representation of the structure of an argument
  • Module Pattern Explained

Other

How JavaScript timers works
Controlling Robots

Testing

Exception Handling 

Here are some reference articles for Exception handling in JavaScript
- http://eloquentjavascript.net/1st_edition/chapter5.html

Catch JavaScript errors on server side. This way you can find more details about how your system performs in production environment. See articles.

Debugging

http://amasad.me/2014/03/09/lesser-known-javascript-debugging-techniques/

Monday, November 28, 2011

Events in JavaScript

Events are the core of JavaScript. You use events to make the interaction between the DOM and the JavaScript. 

Event capturing and Event bubbling

Following diagram extracted from guistuff shows what is event capturing and bubbling are.



Example1 - Using pure JavaScript - return false and event.stopPropogation

        var outer = document.getElementById('outer'), //Outer element
            inner = document.getElementById('inner'); //Inner element

        outer.addEventListener('click', function (event) {
            console.log('outer');
        });

        inner.addEventListener('click', function () {
            console.log('inner');

            //Without anything outer will get fired

            //event.stopPropagation(); //outer won't get fired

            //return false; //Doesn't do anything.
        });

- When you use return false, it won't stop event from bubbling up.
- See this google search,  this, this or this for more information.

Event.preventDefault vs return false
You can use either of above return statements to prevent other event handlers from executing after a certain event. 

http://stackoverflow.com/questions/1357118/event-preventdefault-vs-return-false

document ready functions
window.load vs document.ready


Sources
http://stackoverflow.com/questions/4616694/what-is-event-bubbling-and-capturing
http://www.quirksmode.org/js/events_order.html
http://www.quirksmode.org/js/support.html
http://stackoverflow.com/questions/tagged/javascript-events

Saturday, August 27, 2011

Transactions in Databases

Transaction is databases is executing set of database instructions in a sequence which should be accomplished together. Transactions have following properties which are known as ACID (wiki).
  • Atomicity : Ensure all operations are completed successfully or in a failure, all operations are rolled back to its previous state
  • Consistency : Ensure database properly changes state upon a successful transaction completion
  • Isolation : Ensure transactions are operate independently 
  • Durability : Ensure result or effect of a committed  transaction persist in a case of a system failure

Transactions in Entity Framework

Whenever you execute SaveChanges(), the framework will wrap that operation in a transaction. Starting with EF6, Database.ExecuteSqlCommand() by default wrap the command in a transaction if one was not already present. Entity framework does not wrap queries in a transaction.

Read below articles for more information Working with Transactions (Data Developer Center)
Managing connections in Entity Framework (Visual Studio)
Using Transactions or SaveChanges (SO)


Transactions in SQL Server

Implicit Transaction 
http://dba.stackexchange.com/questions/43254/is-it-a-bad-practice-to-always-create-a-transaction
http://www.codeproject.com/Articles/4451/SQL-Server-Transactions-and-Error-Handling
http://stackoverflow.com/questions/10153648/correct-use-of-transactions-in-sql-server-2008
http://www.tutorialspoint.com/sql/sql-transactions.htm
http://www.dotnet-tricks.com/Tutorial/sqlserver/c2XF120412-SQL-Server-Transactions-Management.html


SAP
https://help.sap.com/saphelp_gateway20sp08/helpdata/en/41/7af4bca79e11d1950f0000e82de14a/frameset.htm

Friday, August 19, 2011

The most seamless tool set to develop applications


Are you looking for the seamless set of tools to develop your applications? You have great languages like Java, C#. But what is the best tool set? Well, when it comes to that the obvious choice of yours would be Microsoft products. These MS products have such a nice compatibility with each other.

Expression Blend, Visual Studio, Silverlight and .NET provide the most compelling and seamless design and development workflow on the market today. You will amazed by how easily they can be handled.

Wednesday, August 10, 2011

Introduction to Cloud Computing

What is cloud computing?
Large group of remote servers networked to allow centralize data storage and online access to computer services or resources. (Wikipedia). Cloud computing can be classified as private, public and hybrid.

Fundamental models 

Infrastructure as a service (IaaS)
Provides Virtual Machines, Servers, Storage, Load balancer's etc.

Platform as a service (PaaS)
Typically provides execution runtime, database, web server

Software as a service (SaaS)
Provided access to software and databases. Cloud provider manages the infrastructure. Also known as On demand software. Usually priced pay per use. 



Deployment models

Private cloud
Typically used for a single organization 


Public cloud
Open for public use. Technically there may not be any difference between between private and public clouds however security considerations are different. 

Web Server, Garden and Farm

Web Garden scales across multiple processes
Web Farm scales across multiple servers

Hybrid Cloud




Some of the enterprise software companies include
Hewlett Packed Enterprise - https://www.hpe.com/





Wednesday, July 20, 2011

Serialization in C#

Serialization is used to convert an object into a byte stream. This is usually done to store the object in the memory, database or a file and retrieve the state of the object later. This reverse process is called de-serialization.

To make a type serialize, you need to apply SerializeAttribute to it. If you haven't specify the attribute and when you try to serialize it, it'll through SerializationException. If you want to make some fields in your class not serialized, you can decorate it with NonSerializedAttribute. 

You cannot serialize iterator types such as IEnumerable etc. See SO

Binary Serialization 

Uses binary encoding to produce compact serialization. In Binary, all members are serialized. 

XML Serialization

Serializes public fields and properties of an object, or parameters and return values of a method. This serializes object into a XML stream. This provides more readable code.

SOAP Serialization

Serialize objects into XML streams which conforms to SOAP specification (which is a protocol based on XML).

Serialization in JavaScript
Convert form data to JSON using JQuery

Sources

Wednesday, February 16, 2011

Windows Communication Foundation


WCF is a runtime and set of APIs in .NET framework for building connected, service-oriented applicatons.

Difference with Web Services

Some of  the differences between WCF and Web service is that Web service only supports HTTP protocol. But WCF supports other protocols like TCP, HTTP, HTTPS, Named Pipes and MSMQ. Another major difference is that Web Services use XmlSerializer while WCF uses DataContractSerializer which is better in performance than XmlSerializer. Serialization in WCF.

ABC of WCF (msdn)

 

A - Address :  Where is the service
B - Binding : How do I talk to the service
C - Contract : What can the service do for me

 

Authentication and Authorization in WCF (MSDN)


You can also look in to this article series on MSDN about learning WCF.


Exception Handling in WCF

Handling exceptions in WCF is different than usual exceptions in .NET. Because WCF client may or may not base on .NET. Therefore we should have a generic way to pass exceptions to all types of clients. For this we have SOAP faults. 

SOAP faults are a way to propagate exceptions from service to the client application.  .NET framework has FaultException which can raise SoapFault exception. Here Service should throw FaultException<T> instead of usual CLR Exception object. T can be any type which can be serialized. 

WCF - Exception Handling

Resources

SO - Is there any official WCF Logo 
http://stackoverflow.com/questions/50114/wcf-wtf-does-wcf-raise-the-bar-or-just-the-complexity-level
http://www.codeproject.com/Articles/139787/What-s-the-Difference-between-WCF-and-Web-Services

Monday, February 7, 2011

What you need to know about JavaScript functions

As in any other language, functions are one of the building blocks of JavaScript. You can define functions and call them in different ways. In this article we'll see some basic but important things you need to know about JavaScript functions. 

Function declaration

The basic syntax for creating function declaration is like this. declarations loads to execution context before any code is executed. Below I'll show you function declaration example and 5 ways you can call the function.


Function expression

Functions can be created like expressions as well. Function expression gets load only when interpreter gets to the line of code. Also you can give a name to a function in a function expression they are called named function expression. If you do not give a name to a function expression it'll be called anonymous function expression.

The difference between function expression and declaration is how browser loads them to execution context. With functions comes a important concept called hoisting. Usually in JavaScript variable declarations are hoisted on top of a function. Read this for more info on hoisting. 

function themselves are objects of type Function. It has methods like apply, call etc.. Every functions by default accepts arguments object. You can find all arguments passed from the caller from argument object. Closures are related with functions. Read this article written by me about closures. JavaScript has predefined functions such as eval, isNaN, parseInt etc. If no return value is defined, functions will return undefined.

You can pass different parameters to functions. If you pass primitive type (primitive types in JavaScript) they get passed by value. But if you pass object (such as Array) the change will be reflected outside the function. That is you're passing an reference to an object by value. There is no pass by reference in JavaScript. 


Constructor functions vs Factory functions
Constructor function uses the new keyword to create a new object, set this within the function of that object and return it.





Factory function also uses to create new objects but it does not use new keyword. In fact factory creates the object for you and returns it. You can return different types of objects from a factory. 



With factories you get better encapsulation and data hiding. 

When you create an object from constructor function the prototype will be included in that object. When you create a n object through a factory since it just returns an object, the prototype won't be available.

Some Useful Stuff

Exclamation mark in front of a function (SO1 , SO2)


Resources

Tuesday, January 25, 2011

Data types in JavaScript

As in any other programming language, JavaScript also has Primitive data types and non-primitive data types. In case you didn't know primitive data types are predefined data types which comes with the language. Non-primitive are data types which are defined by the programmer.

Data types in JavaScript
  • Primary data types
    • Number
    • String
    • Boolean
  • Composite data types
    • Object
    • Function
JavaScript consists of lot of objects in it. Following diagram shows some of them. (source)

Array
Array is a high-level, list like object. Array prototype includes methods to perform operation on it.

Array. forEach
Array.prototype.map()
Creates a new array after manipulating the array elements from the callback function which is passed to map.
There are lot of other methods available for use in Array.prototype. 
Resources

Tuesday, November 30, 2010

Algorithms every software developer must know

Basics in algorithms

What is Big O notation? (link Stackoverflow)
It is relative representation of the complexity of an algorithm

Sorting Algorithms

Sorting algorithms are often classified by
  • Computational complexity 
    • of elements in terms of the list size
    • of swaps
  •  Memory usage
  • Recursion
  • Stability
  • Adaptability

Popular sorting algorithms

Simple sorts : Insertion sort, Selection sort
Efficient sort: Merge sort, Heap sort, Quick sort
Bubble sort


Resources

http://stackoverflow.com/questions/33923/what-is-tail-recursion
http://stackoverflow.com/questions/tagged/algorithm

Tuesday, November 23, 2010

Modifiers in C#

Modifiers are used to modify declarations of types and type members. Following are the modifiers comes in C# (MSDN)

sealed #

  • In classes, sealed modifier prevents other classes from inheriting from it.
  • Can also use sealed modifier on a method or property that overrides a virtual method or property in a base class
    • Enables you to allow classes to derive from your class and prevent them overriding specific virtual methods or properties 
  • When applied to a method or property sealed must always used with override 
  • Structs are implicitly sealed, they cannot be inherited. This is because structs are value types 

virtual #



  • Virtual is used to modify methods, properties, indexers or event declarations and to be overriden in a derived class. 
  • virtual member can be changed in a derived class with override modifier. 
  • By default methods are non-virtual. Therefore you cannot override a non-virtual method. 
  • Virtual members are an implementation of type-based polymorphism. When you have a base class and a derived class, the derived class can re-implement the base class virtual method thus giving you dynamic entry point to the class type.
  • You cannot create private virtual members. You'll get virtual or private members cannot be private Exception.
  • virtual properties behave like abstract methods, with few differences.


http://www.dotnetperls.com/virtual

abstract #

  • indicates thing being modified has a missing or incomplete implementation
  • abstract method is implicitly virtual

default (SO)

  • For a reference type returns null
  • For a value type other than Nullable<T> returns 0 initialized value
  • For Nullable<T> returns empty value


const 

- Cannot change (compile time constants)

readonly

- Can change in the constructors. (runtime constants)


  • async
  • event
  • extern
  • new
  • override
  • partial
  • static
  • unsafe
  • volatile

Saturday, September 11, 2010

Principles in Software Development

When designing a software there are various principle you should follow 
to make the software better in different aspects. 
In this article we'll go through some of those principles.

Principle of least astonishment

Basically you should not astonish people when it comes to implementing something. For example if you have a method toString() which returns a string "not implemented", it is breaking of least astonishment principle. 

see wikipedia and Programmers - StackExchange 

Cargo cult programming
inclusion of a code or program which does not have any real purpose
wikipedia, Programmers SO 

GRASP

Consists of guidelines for assigning responsibility to classes and objects.  See this wikipedia article and this.

KISS (Keep it simple stupid)

States most systems works best if they are kept simple rather than complicating. Therefore simplicity should be a key goal in designing a system.

YAGNI (You aren't gonna need it)

It's a principle of Extreme Programming. It states that programmer should not add functionality unless deemed necessary. See wikipedia.


Other

Having a good software design is important to avoid bad design which will cause us very badly. According to Robert martin there a 3 things we must avoid when designing software.
  • Ridiglity : It's hard to change because changes affects too many other parts of the system
    • every change causes a cascade of subsequent changes in dependent modules. Can grow 2 day work to multiple weeks
  • Fragility : When you do a change, unexpected parts of the system breaks. Has a close connection with Ridiglity.
  • Immobility: It is hard to reuse component in another area of the application.
  • covariance and contravariance
Memoization 
In computing, memoization is an optimization technique used primarily to speed up computer programs by storing the results of expensive function calls and returning the cached result when the same inputs occur again.

source
Memoization in JavaScript


https://www.cs.utexas.edu/~scottm/cs307/handouts/deepCopying.htm

Tuesday, August 10, 2010

Introduction to Python

Python is an interpreted, high-level, general-purpose programming language. Instagram and Google uses Python in there backend. Over the years Python has grown its territory massively. 

Python can be used for

  • server to create web applications. 
  • can be used alongside software to create workflows. 
  • can connect to database systems. It can also read and modify files. 
  • can be used to handle big data and perform complex mathematics. 
  • can be used for rapid prototyping, or for production-ready software development.

You can install Python from website.

Recommend tool to use python with Visual Studio Code. You can install Python extension for ease of use. 

References
https://stackoverflow.blog/2017/09/06/incredible-growth-python/

Saturday, August 7, 2010

Do not break these User Interface Design Principles


Keep the following as a checklist next time when you're designing an interfaces

  1. Keep things clear without confusing the user
  2. Make user know what is preferred action is. Especially for new users
  3. Keep user interface interaction controls close to relevant content
  4. Keep good set of default settings
  5. Guide user on what they must do. Next
  6. Give feedback for interactions
  7. Breakdown complex actions into set of simple step by step action set


Resources
Photo credit : msdn

Tuesday, May 11, 2010

Creational design patterns

Factory

Provides an interface to create objects. Rather than creating new objects using new keyword, we ask the factory to create and return them for us. 

Factory in JavaScript : method1 (addyosmani) and method2 (carldanley)





Builder

http://www.oodesign.com/builder-pattern.html

Lazy initialization

Creation is deferred until it is first used. Useful for complex objects. 

C# : http://msdn.microsoft.com/en-us/library/dd997286%28v=vs.110%29.aspx


Object pool

Useful when cost of initializing a class instance is very high.  Therefore when requester requires an instance, he can get one of already created instance.

Prototype




Singleton 

http://stackoverflow.com/questions/327955/does-functional-programming-replace-gof-design-patterns?rq=1

Saturday, May 1, 2010

Introduction to Testing


Testing is a mechanism we use to evaluate whether the software we are developing satisfies the specified requirements. Testing is a very broad subject. Here we'll just look in to some high level overview of what it is.


Types of testing

  • Manual testing
    • Takes the role of an end user and checks for unexpected behavior 
    • There are few levels like unit testing, integration testing, system testing and user acceptance testing
    • Uses test plan, test cases or test scenarios to test
  • Automation testing
    • Also known as Test Automation
    • Testers writes scripts and use other software to do testing
    • Rerun test scenarios quickly and repeatedly
    • Use tools like Selenium, VS Test Professional, IBM Rationale function tester

Testing methods

  • Black box 
    • Without having any knowledge of interior workings of the application (UI level)
  • White box
    • Detailed investigation of internal logic
  • Grey box
    • Testing with limited knowledg

Sunday, April 4, 2010

Behavioral Design Patterns

Observer

Object (subject) maintains list of its dependencies (observers). Subject will then notify observers whenever any state change occurs in it. 

Related patterns are Publish-Subscribe pattern, mediator and singleton 
http://weblogs.asp.net/fmarguerie/events-references-garbage-collecting-memory-leaks-and-weak-delegates


Iterator



Mediator

Defines an object which encapsulates how a set of objects interact. Mediator promotes loose coupling by keeping objects referring from each other explicitly.

http://www.dofactory.com/net/mediator-design-pattern  
Template method
http://www.oodesign.com/template-method-pattern.html
Null object

Strategy

Defines set of algorithms that can be used interchangeably. Basically you create an interface and derive implementations from that. Clients can couple themselves with the interface. 

http://robdodson.me/javascript-design-patterns-strategy/
http://sourcemaking.com/design_patterns/strategy

Command


Powered by Blogger.


Software Architect at Surge Global/ Certified Scrum Master

Experienced in Product Design, Software Engineering, Team management and Practicing Agile methodologies.

Search This Blog

Facebook