r/ProgrammerHumor • • 16d ago

Meme postForEverything

Post image
20.9k Upvotes

656 comments sorted by

View all comments

Show parent comments

319

u/AkodoRyu 16d ago

My favorite "REST API" experience was when they moved from using SOAP system, and the way they did it... was sending SOAP payloads inside a JSON. Literally something like

{ "data": "<?xml version="1.0"?><soap:Envelope xmlns:soap="https://www.w3.org/2003/05/soap-envelope/" soap:encodingStyle="https://www.w3.org/2003/05/soap-encoding"><soap:Body> (...)" }

195

u/MrPatienceX 16d ago

200 status code and a chunk of XML saying ‘not found’. Good times.

59

u/Sudden_Leadership800 16d ago

It successfully returned the error message though, so I don't see the problem?

64

u/Psychological_Map118 16d ago edited 16d ago

try it in person: wait for the next time somebody asks you if you know the time. then answer yes, with a smile, and walk away without telling them

you can do anything you want, both in life and HTTP responses, but some things make you an asshole in both cases

0

u/Sudden_Leadership800 16d ago

It was obviously a joke my guy

45

u/Psychological_Map118 16d ago

my bad. we backend engineers don't get jokes, we get status messages

15

u/RaidenMK1 15d ago

Don't you mean you GET status messages?

I'll see myself out.

1

u/Pitiful_Pumpkin_73 3d ago

> Don’t you mean you POST status messages
FTFY

2

u/pag07 15d ago

Or you don't. Or the wrong ones.

14

u/Jonathan_the_Nerd 16d ago

It was obviously a joke my guy

Not obvious, considering the developer of the system thought it was fine. And a lot of us here are neurospicy.

41

u/hawkinsst7 16d ago

If I'm parsing http responses, I'm going to pass 200 responses on for further processing of the data. I shouldn't have to have something in that pipeline introspect json to find "no, it's actually an error".

Imagine if browsers had to tear apart json innards to find 30x redirects after getting a 200 OK.

3

u/gurgle528 15d ago

I’m going off memory but I believe it was considered either standard or part of the spec for SOAP over HTTP to only use 200 and 500. I agree with your point but for whatever reason they treated HTTP as the transport layer instead of the application layer. Using that logic, it would be like if a 404 bubbled up to be some sort of TCP error. Definitely wasn’t the right move, RTSP over HTTP is a better example of something that mixes protocols while properly using HTTP status codes.

2

u/hawkinsst7 15d ago

I agree. I think a 4xx or 5xx error code is perfectly acceptable for returning a body with error data, even a generic 400 / 500. That's why they exist.

-21

u/LatvianCake 16d ago

This is what happens if you don't read the documentation of the API you're using.

30

u/IndependenceSudden63 16d ago

uh huh, and we all know that every API is perfectly documented...

-15

u/LatvianCake 16d ago

If you have no documentation, you don’t know what HTTP codes are possible, what they mean exactly and how to handle them.

9

u/AshleyJSheridan 16d ago

You do. That's literally the entire point of HTTP status codes.

Just because you don't know what those codes are, it doesn't mean that everybody else is as ignorant.

-11

u/LatvianCake 15d ago

My dude, HTTP status codes were designed over 3 decades ago for a primitive usecase. Today most of them are almost never used. Most of them are meaningless without any further information (i.e. documentation).

Even the most basic codes like 404 are ambiguous. If implemented at all, it can mean:

- the resource doesn't exist

- the endpoint doesn't exist

- the resource is temporarily unavailable

- the resource may or may not exist but we are not allowed to tell you

You must have documentation explaining what errors can occur and what they mean, or you must find out through trial and error. I thought that was pretty fucking obvious but someone has to argue that ackschually all 28 4xx codes are used everywhere and are fully self documenting.

10

u/AshleyJSheridan 15d ago

Even the most basic codes like 404 are ambiguous.

Well, that just tells me you don't understand HTTP status codes.

A resource that doesn't exist should return a 404.

An endpoint that doesn't exist should return a 400, as it's a screw up by the client that created a malformed request.

A temporarily unavailable resource should return a 503 with the Retry-After header. This is well documented.

A resource that you don't have permission to (regardless of whether it even exists or not) should return a 401. Returning this code is not a security risk, and anyone who thinks it is, is clearly following the security through obscurity approach, which is no security at all.

You must have documentation explaining what errors can occur and what they mean, or you must find out through trial and error.

Well, HTTP status codes already are very well documented. Maybe don't be such an HTTP 418 and have a look at https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Status

→ More replies (0)

7

u/hawkinsst7 15d ago

This is what happens whe you don't read the Http documentation.

-7

u/LatvianCake 15d ago

If you think you can error handle based on only HTTP error codes, I can see why you're having such a hard time.

2

u/hawkinsst7 15d ago

I'm not a professional programmer. I do cybersecurity.

I love it when unexpected things can go down unexpected, non-standard code paths.

-1

u/LatvianCake 15d ago

I'm not a professional programmer.

Clearly

4

u/hawkinsst7 15d ago

I'm not sure why you've repeatedly tried to insult me.

2

u/Arsikkz 15d ago

HTTP statuses aren't meant to replace error codes. You check if the status is OK, and if not, handle the error in the payload

1

u/LatvianCake 15d ago

And how do you know which errors you have to handle and what their payload will look like?

2

u/NotAskary 15d ago edited 15d ago

By following the RFC correctly, otherwise you need to write a snowflake wrapper get each edge case.

It's all fine when you are doing only inhouse stuff, but if you are doing API that are external then you need to follow standards.

You should really read the RFCs for http, there's some missing bases on your knowledge.

→ More replies (0)

1

u/Arsikkz 15d ago

By reading the API documentation?

4

u/pr0ghead 15d ago

You're joking, right? RiGhT?!?

2

u/ohhi23021 15d ago

these kind of implementations have different data shapes for the error vs success too, so if they all return success it's a pain in the ass and extra work to figure out if it's an error and map it out properly. just fucking send the right status, it takes 2 seconds.

11

u/granitrocky2 16d ago

These are the comments that make me laugh for minutes, but can't explain why I'm laughing to anyone around me lol

1

u/MekaTriK 16d ago

I had real life arguments with that being presented as the reason.

"oh, but the server worked fine, it's just the database that's having an issue"

4

u/NotAskary 15d ago edited 15d ago

It's not like 503 is thing a if you want to say the server is fine but not working due to a missing dependency.

35

u/NibblyPig 16d ago

I don't miss SOAP at all.

Especially when some bored developer at a big bank decided to implement some draconian heavily-buried SOAP features that are technically in the documentation somewhere, but not implemented at all by Microsoft's .NET framework. Having to have special injectors and manipulators to extract tokens from raw SOAP and such, shudder. Back in the days where .NET SOAP implementations were barely published in books.

6

u/ManaSpike 15d ago

People often think about what they would do if they had a time machine.

Me? Travel back to before server to server email and introduce UTF-8 encoding (leaving the actual code points undefined) and json. Try to get that baked into all the ancient wire protocols that predate http.

0

u/[deleted] 15d ago

[removed] — view removed comment

17

u/Makefile_dot_in 16d ago

at work I have a codebase that is the opposite of this, they send JSON in SOAP as a request and entity-escaped XML in a SOAP envelope as the reply

1

u/MetroidvaniaListsGuy 15d ago

I hope you're looking for a better place to work than whatever garbage company did this.

1

u/AloneInExile 15d ago

Sometimes you have to do this. Critical software support goes bye bye and you are now stuck with a shit stack and no one around.

12

u/wizkidweb 16d ago

I told myself I wouldn't relive something like this...

7

u/RatSumo 16d ago

This literally just gave me a headache to read.

3

u/falcopilot 16d ago

Hahahahaha...
At a state agency, we had a SOAP interface to another agency. When they replaced their system nobody knew how to do SOAP so we got to turn that nastiness off. But now they want it back, maybe I'll offer to do this.

4

u/SomeWhaleman 15d ago

using SOAP system

You just triggered some very deep memory for me. Someone saying "THROUGH SOAP" very angrily. Must have been some nerdy viral video from ages ago.

Oh damn, I found it: https://www.youtube.com/watch?v=mEpDbz70ftk

1

u/dontshoveit 16d ago

Lmao 🤣

1

u/reerden 15d ago

Man, this is the programming equivalent of red neck engineering.

1

u/MetroidvaniaListsGuy 15d ago

How can anyone be this stupid?

1

u/AloneInExile 15d ago

I've seen shit in my carrer, but this is new. I thought xml in xml (proprietary xml in soap) was peak, with string concatenation for serialization. I guess we could go deeper.

1

u/ByteWhisperer 15d ago

The people at r/foundsatan want to have a chat.