560 blogs tracked4,950 posts indexed

#java

24 posts · 10 companies · newest first

Curated view of this subject:Topic: Java54
1

Security Baked Into the JVM: no single party controls the outcome (opens on the source site)

A URL is a name, and names get reused. Replace the bytes behind https://repo.example.org/order-processor.jar and every permission granted to that URL still applies, now to code nobody audited. So far in this series, Part 1 declared constraints on a remote call, Part 2 vetted code before a client loaded it, Part 3 established who is calling, and Part 4 carried that chain of identities across the wire.

javajvmexcerpt only · body stays at the source
From the web
2

Leave the Class Path in the Rearview Mirror (opens on the source site)

Introducing composable, module system native and agent friendly command line tools for modern Java developmentBy Danny Thomas, JVM Ecosystem TeamRecent work on the Java language to pave the on-ramp has made it easier than ever to start a Java program and evolve it using the full language and platform. At the end of that on-ramp lies Java’s mature build and dependency management ecosystem, capable of carrying software to enormous scale and complexity.That ecosystem reached its maturity by developing strong models for projects, dependencies, and builds. When the Java Module System arrived,…

software-engineeringjvmexcerpt only · body stays at the source 11 comment on HN (opens the discussion)
From the web
3

Security Baked Into the JVM: sixteen Subjects on the wire (opens on the source site)

Alice calls the order service. The order service calls the ledger on her behalf. At the second hop, the ledger has to decide whose authority the debit is being made under. Most stacks answer badly. Forward Alice’s bearer token verbatim, and the ledger cannot tell her from the service that relayed it. Drop the token and the ledger sees a machine, with no record that a human started the chain. Neither option lets the ledger authorize the combination.

javajvmexcerpt only · body stays at the source
From the web
5

Security Baked Into the JVM: two Subjects, one call (opens on the source site)

The constraint system stops a bad call before it leaves the JVM. The Safe Codebase Audit Pipeline stops bad code before a client ever loads it. What remains is identity: who is calling, and can you verify it? Most frameworks answer with a token check at the door. A filter validates a bearer token, sets a thread-local variable, and hopes that nothing downstream forgets to look at it. DirtyChai answers differently.

javajvmexcerpt only · body stays at the source
From the web
6

Security Baked Into the JVM: the Safe Codebase Audit Pipeline (opens on the source site)

In Part 1, the minimal deployment showed constraints traveling with the proxy: authentication, encryption, hardened deserialization, all declared in configuration and enforced at the call boundary. The proxy is a JAR. That JAR was downloaded and unmarshalled before any constraint ran. That step is the earlier problem. Distributed Java systems that load remote code are vulnerable to supply chain compromise: an attacker can replace a legitimate JAR with one containing malicious bytecode.

javajvmexcerpt only · body stays at the source
From the web
7

Making ServiceLoader usable: a provider factory (opens on the source site)

I keep coming back to java.util.ServiceLoader. I have used it to put a JSON layer behind a contract, so the core code carries no direct dependency on any particular JSON library, and I can swap the implementation without touching callers. The same shape works for JWT handling, where the concrete library might be jose4j or another JOSE implementation, and you can easily find other decoupling use-cases.

javaserviceloaderexcerpt only · body stays at the source
From the web
8

Security Baked Into the JVM: why fork Apache River and OpenJDK? (opens on the source site)

The more distributed a system, the harder it is to secure. Code crosses JVM boundaries. Objects are serialized across trust boundaries. Third-party proxies run inside your process. The usual answer is a network firewall. It helps, but it operates at the wrong level. Java 17 deprecated the SecurityManager, Java 24 put the final nail in its coffin. Most developers didn’t notice.

javajvmexcerpt only · body stays at the source
From the web
9

On programming languages, targets, and platforms (opens on the source site)

I started as a Java developer, but for some time now, I have broadened my horizons. Recently, I thought about how early languages were dedicated to a single target and platform, and now they are broadening their focus. In this post, I want to write down my thoughts in the hope that it may be useful to others, probably to my future self. Definitions You may have been wondering about the title terms.

javakotlinexcerpt only · body stays at the source
From the web
10

double, BigDecimal, or Fixed-Point? (opens on the source site)

There is an evergreen debate in the Java world: should you always use BigDecimal for money? The short answer is no. The real answer is: it depends on your computational context: the precision you need, the rounding rules you must follow, and the performance budget you have. The problem is that this conversation is often driven by dogma rather than engineering.

javabigdecimalexcerpt only · body stays at the source
From the web
11

Book Review – Troubleshooting Java (opens on the source site)

Introduction My friend, Laurentiu Spilca, has been working on the second edition of his Troubleshooting Java book, and when I was asked to review it, I was more than happy to do it since the book features a lot of topics that I’m also very interested in, such as performance tuning and query optimization. Audience This book is useful for any Java developer because it teaches you how to get the best out of your IDE debugger, as well as showing you how to profile Java applications and fix very complex issues,... Read More The post Book Review – Troubleshooting Java appeared first on Vlad…

bookbook-reviewexcerpt only · body stays at the source
From the web
12

Consider using JSON arrays instead of JSON objects for serialisation (opens on the source site)

When implementing the awesome MULTISET operator in jOOQ, its implementation mostly relied on SQL/JSON support of various RDBMS. In short, while standard SQL supports nested collections via ARRAY or MULTISET operators like this: This is poorly supported in most RDBMS, so jOOQ emulates it using SQL/JSON as follows (or similar): Wait a second. A JSON … Continue reading Consider using JSON arrays instead of JSON objects for serialisation →

javacompressionexcerpt only · body stays at the source
From the web
13

Foundations of AI and Machine Learning for Java Developers Course Review (opens on the source site)

Introduction In this article, I’m going to review the Foundations of AI and Machine Learning for Java Developers video course from my fellow Java Champion, Frank Greco. If you are new to AI and ML and want to get a great introduction to these topics, then you should definitely join watch the video lessons created by Frank Greco. And, thanks to LinkedIn Learning’s generosity, until June 20, you can enroll in this video course for free. Video Course Agenda The course provides one hour and thirty-five minutes of video lessons that are... Read More The post Foundations of AI and Machine Learning…

aicourseexcerpt only · body stays at the source
From the web
15

A Hidden Benefit of Implicit Joins: Join Elimination (opens on the source site)

One of jOOQ’s key features so far has always been to render pretty much exactly the SQL that users expect, without any surprises – unless some emulation is required to make a query work, of course. This means that while join elimination is a powerful feature of many RDBMS, it isn’t part of jOOQ’s feature … Continue reading A Hidden Benefit of Implicit Joins: Join Elimination →

jooq-in-useimplicit-joinsexcerpt only · body stays at the source
From the web
16

jOOQ 3.19’s new Explicit and Implicit to-many path joins (opens on the source site)

jOOQ 3.19 finally delivers on a set of features that will greatly simplify your queries further, after jOOQ 3.11 introduced implicit to-one joins: What are these features? Many ORMs (e.g. JPA, Doctrine, jOOQ 3.11 and others) support “path joins” (they may have different names for this concept). A path join is a join derived from … Continue reading jOOQ 3.19’s new Explicit and Implicit to-many path joins →

jooq-developmentcorrelated-subqueriesexcerpt only · body stays at the source
From the web
17

Maven Coordinates of the most popular JDBC Drivers (opens on the source site)

Do you need to add a JDBC driver to your application, and don’t know its Maven coordinates? This blog post lists the most popular drivers from the jOOQ integration tests. Look up the latest versions directly on https://central.sonatype.com/ with parameters g:groupId a:artifactId, for example, the H2 database and driver: https://central.sonatype.com/search?q=g%3Acom.h2database+a%3Ah2 The list only includes drivers … Continue reading Maven Coordinates of the most popular JDBC Drivers →

javasqlexcerpt only · body stays at the source
From the web
19

How to Pass a Table Valued Parameter to a T-SQL Function with jOOQ (opens on the source site)

Microsoft T-SQL supports a language feature called table-valued parameter (TVP), which is a parameter of a table type that can be passed to a stored procedure or function. For example, you may write: This function takes a table-valued parameter (TVP), and produces a result set containing the cross product of the parameter table with itself. … Continue reading How to Pass a Table Valued Parameter to a T-SQL Function with jOOQ →

jooq-in-usecode-generationexcerpt only · body stays at the source
From the web
20

How to Turn a List of Flat Elements into a Hierarchy in Java, SQL, or jOOQ (opens on the source site)

Occasionally, you want to write a SQL query and fetch a hierarchy of data, whose flat representation may look like this: The result might be: |id |parent_id|label | |---|---------|-------------------| |1 | |C: | |2 |1 |eclipse | |3 |2 |configuration | |4 |2 |dropins | |5 |2 |features | |7 |2 |plugins | |8 |2 … Continue reading How to Turn a List of Flat Elements into a Hierarchy in Java, SQL, or jOOQ →

javajooq-developmentexcerpt only · body stays at the source
From the web
21

Mechanically Deriving Binary Tree Iterators with Continuation Defunctionalization (opens on the source site)

Binary tree is the simplest of tree data structures. It is a tree in which each node has at most two children. A tree traversal is a process of visiting each node in the tree, exactly once. There are multiple ways of traversing a binary tree in depth-first fashion with each traversal resulting in a different enumeration of the tree elements. These tree traversals are defined as simple recursive functions. But what if we want to write Java-style iterators for them? Is there a way to mechanically derive these iterators from the traversal functions? Let’s find out.

algorithmscontinuationsexcerpt only · body stays at the source
From the web
22

Further experiments, writing a Serverless Telegram Chat Bot (opens on the source site)

In my last article I wrote about how I wrote Telegram Chat for tracking co-working spends. I wrote a chatbot using Java, hosted it on my Raspberry PI 3. Yes, it’s serving its needs, we fully rely on it. However, since this chatbot was written as an experiment, I wanted to proceed with research and investigate how real chatbots are written.

javachat-botsexcerpt only · body stays at the source
From the web
24 shown

Privacy choices

Reading never requires analytics. These choices last 90 days on this browser.

Essential sign-in and security storage always stays on. Read the privacy notice.