Same guy as last time. Not the best presenter, but here we are.
Afternoon Session 2 - 'Real World' ASP.NET MVC in 75 Minutes!
Gus Emery
Custom Routing
Customization to urls
Keeps site secure (no exposure of real url)
MVC is type smart
Easily addable to global.asax. Miguel told us not to do that...
Default controller: {controller}/{action}/{index}
Never a good sign when he warns us to bear with him with all the issues he's expecting. Or it shows he's learning from last session.
Can also create partial views as ascx.
Form Validation
Use AddModelError to add an error to the model, then check ModelState.IsValid(). Note, requires a roundtrip to check, but 2.0 apparently has a better way (using jQuery I think).
Provides easy way to display errors (HtmlValidationSummary) and uses standard validators on fields.
Custom Filters
Allows custom functionality (logging, tracing)
Very flexible
Actually filtering on actions to let you log them.
Didn't really work (at all) in his demo, so not really sure....
Caching
Less DB hits
Faster
Basically tag any method with a cache. Things go faster. Can do a varyByParam to specify individual parameters that should be used to specify how to index your cache.
Monday, October 5, 2009
Afternoon Session 1: Intro to ASP.NET MVC
Alright, been way too wordy. This session I think is going to go a lot into a generic intro of ASP.NET MVC. I figured that out all by myself JUST from looking at the title. Seriously. So I'm not going to post much about the specifics here. All part of my fewer-words initiative. Go!
Afternoon Session 1: Intro to ASP.NET MVC
Gus Emery
MVC was originally called "Thing-Model-View-Editor." Awesome. That's better than the Entity table.
Claims it's not for every project, but also says he hasn't ever seen an app for which MVC is not a good fit.
2.0 Updates:
Addition of jQuery validation lib
Areas - multiple projects
Model Validation Providers
Metadata Providers
Exteded Editable flags
URL rewriting more secure since users can't see what your physical pages are.
My biggest problem -- and Al and I have talked about this -- is that it's very developer friendly, but we have the unique goal of exposing the view layer to Marketing. There's a lot of code in the View, and it's not easy (for a non-developer) to just add a view -- you have to build the corresponding controller, etc. With a standard web form, on the other hand...very possible.
Integrated security = nice. I can see using this for backend stuff for sure.
Cookie based authentication - with cookies that last a LOOOOONG time.
Not my favorite presentation of the day. This guy is going a bit fast and seems a bit disorganized (crashes on examples, things like that), which makes some of his examples a bit tough to follow. Wish it wasn't done in VB, too. Stupid no semicolons.
Afternoon Session 1: Intro to ASP.NET MVC
Gus Emery
MVC was originally called "Thing-Model-View-Editor." Awesome. That's better than the Entity table.
Claims it's not for every project, but also says he hasn't ever seen an app for which MVC is not a good fit.
2.0 Updates:
Addition of jQuery validation lib
Areas - multiple projects
Model Validation Providers
Metadata Providers
Exteded Editable flags
URL rewriting more secure since users can't see what your physical pages are.
My biggest problem -- and Al and I have talked about this -- is that it's very developer friendly, but we have the unique goal of exposing the view layer to Marketing. There's a lot of code in the View, and it's not easy (for a non-developer) to just add a view -- you have to build the corresponding controller, etc. With a standard web form, on the other hand...very possible.
Integrated security = nice. I can see using this for backend stuff for sure.
Cookie based authentication - with cookies that last a LOOOOONG time.
Not my favorite presentation of the day. This guy is going a bit fast and seems a bit disorganized (crashes on examples, things like that), which makes some of his examples a bit tough to follow. Wish it wasn't done in VB, too. Stupid no semicolons.
Morning Session 2: Advanced Web Forms Practices – Part II
OK, so this actually started a bit last session, but want to keep everything together, so here we go with Part 2! May try to make this stuff less wordy, but it's a good session.
Morning Session 2: Advanced Web Forms Practices – Part II
Miguel Castro
Solutions Architect
2. Swappable State Storage
Can store data in Session, Application, Cache, Cookies, etc. So what if you want to swap storage of a var from one to the other? Have to find all instances and change them -- a bit tedious.
ASP.NET Provider Model has a solution.
Separation of concerns! Woohoo!
Static factory class for entry point to all storage methods
Provider base class defines public interface
One provider implementation class for each type of storage
Configuration section listing available and default provider.
Side note: He was doing an example and just manually added a namespace. I Heart Resharper.
Goal is to be able to do something like this:
StateStorage.Store("MyKey", "Hello World");
-- Is it using Session? Application? Cookies? Who cares?
So define a config section that defines several state storage providers, defining a class for each one. One of the providers is flagged as the default provider. Have to write configuration classes of course very similar to the last SSL example. ASP actually provides a class (ProviderSettingsCollection) for defining a basic provider using only a provider and type.
Single static factory class (StateStorage above) will read all the config information and get all the providers and assign a default provider.
Each provider extends a single base class that provides the Store method -- storing however you want. (Note .NET provides a ProviderBase class that your base class should extend) Also has abstract methods for things like Store that you want your provider to support. Individual providers extend that base class and implement the abstract methods as needed. Note can use the providers to uniquify the keys used for storage, or even uniquify a key in the application state for a single user. Don't know why you would do the second one - storing user specific data in application instead of session. But whatever.
And can target a specific provider in code by creating a physical provider from the list of providers in the StateStorage class.
I like it, but not as much as the SSL stuff. Lot of code to solve a not-that-hard problem. More cool code than useful code, but the concept of using the ASP provider model is a good one.
3. Nav Flow
Wizard-like scenario for multiple pages.
Includes nav buttons
Prevents step-skipping
Ability to manage pages and their order
Minimal code from page
Leverages Swappable State Storage above.
Even includes a custom control for dropping nav onto any page in process.
Define a configuration section with a group of pages. He likes his config files. I'm still a little out on how much I love the idea of doing so much stuff in config files.
Allows for defining which state storage provider (from above) to use for storing things like where you are in the process (for validating and preventing skipping).
Static NavigationManager has methods for:
1. Marking current step
2. Navigating forward and backward.
3. Validate if current page is a valid place to be.
Big warning about the Back Button here. May screw around with the validation. He says in eCommerce you should just threaten to double charge people if they use the back button. Haha.
My thoughts: Nice in that it's easy to insert pages or reorder them. Not sure how often that stuff changes drastically, but still a much easier way to handle this than doing all of this info right in the page itself. Could probably also do something like create a couple alternate NavFlows to A/B test some different alternatives (i.e. does fewer steps in the checkout increase conversion?) or provide a different navigation for an express checkout.
Could definitely see using this or something like it for checkout, although I'm (like I said) still not sure if it's maybe better to put the "configuration" inside of code instead. Little more work and requires a compile, but you gain some valuable things like better debugging.
4. Mobile Page Routing
Really quick section on routing mobile users to a mobile version of the site...and potentially vice versa.
Good design allows for forcing normal version even from mobile browser (i.e. full internet on iPhone) and keeps user there via a cookie or something.
More config settings to define the default mobile page. State storage provider again to store cookie (or whatever) for forcing full version browsing.
Another HttpModule that checks if mobile browser is accessing site.
Provides a class called BrowserInfo that has IsMobile property (see cd).
This section was very rushed, but worth checking out later. This has potential to be a key initiative going forward.
Great couple of sessions. Lots of really good and really useful info.
Morning Session 2: Advanced Web Forms Practices – Part II
Miguel Castro
Solutions Architect
2. Swappable State Storage
Can store data in Session, Application, Cache, Cookies, etc. So what if you want to swap storage of a var from one to the other? Have to find all instances and change them -- a bit tedious.
ASP.NET Provider Model has a solution.
Separation of concerns! Woohoo!
Static factory class for entry point to all storage methods
Provider base class defines public interface
One provider implementation class for each type of storage
Configuration section listing available and default provider.
Side note: He was doing an example and just manually added a namespace. I Heart Resharper.
Goal is to be able to do something like this:
StateStorage.Store
-- Is it using Session? Application? Cookies? Who cares?
So define a config section that defines several state storage providers, defining a class for each one. One of the providers is flagged as the default provider. Have to write configuration classes of course very similar to the last SSL example. ASP actually provides a class (ProviderSettingsCollection) for defining a basic provider using only a provider and type.
Single static factory class (StateStorage above) will read all the config information and get all the providers and assign a default provider.
Each provider extends a single base class that provides the Store method -- storing however you want. (Note .NET provides a ProviderBase class that your base class should extend) Also has abstract methods for things like Store
And can target a specific provider in code by creating a physical provider from the list of providers in the StateStorage class.
I like it, but not as much as the SSL stuff. Lot of code to solve a not-that-hard problem. More cool code than useful code, but the concept of using the ASP provider model is a good one.
3. Nav Flow
Wizard-like scenario for multiple pages.
Includes nav buttons
Prevents step-skipping
Ability to manage pages and their order
Minimal code from page
Leverages Swappable State Storage above.
Even includes a custom control for dropping nav onto any page in process.
Define a configuration section with a group of pages. He likes his config files. I'm still a little out on how much I love the idea of doing so much stuff in config files.
Allows for defining which state storage provider (from above) to use for storing things like where you are in the process (for validating and preventing skipping).
Static NavigationManager has methods for:
1. Marking current step
2. Navigating forward and backward.
3. Validate if current page is a valid place to be.
Big warning about the Back Button here. May screw around with the validation. He says in eCommerce you should just threaten to double charge people if they use the back button. Haha.
My thoughts: Nice in that it's easy to insert pages or reorder them. Not sure how often that stuff changes drastically, but still a much easier way to handle this than doing all of this info right in the page itself. Could probably also do something like create a couple alternate NavFlows to A/B test some different alternatives (i.e. does fewer steps in the checkout increase conversion?) or provide a different navigation for an express checkout.
Could definitely see using this or something like it for checkout, although I'm (like I said) still not sure if it's maybe better to put the "configuration" inside of code instead. Little more work and requires a compile, but you gain some valuable things like better debugging.
4. Mobile Page Routing
Really quick section on routing mobile users to a mobile version of the site...and potentially vice versa.
Good design allows for forcing normal version even from mobile browser (i.e. full internet on iPhone) and keeps user there via a cookie or something.
More config settings to define the default mobile page. State storage provider again to store cookie (or whatever) for forcing full version browsing.
Another HttpModule that checks if mobile browser is accessing site.
Provides a class called BrowserInfo that has IsMobile property (see cd).
This section was very rushed, but worth checking out later. This has potential to be a key initiative going forward.
Great couple of sessions. Lots of really good and really useful info.
Morning Session 1: Advanced Web Forms Practices – Part I
A bit of a long one here heavy on technical details. There's a cd we got that has solutions rolling in all of this stuff, so let me know and I can share all that when I get back.
Morning Session 1: Advanced Web Forms Practices – Part I
Miguel Castro
Solutions Architect
Excited about this one. Billed as a session for the seasoned .NET developer interested in out-of-the-box problem solving.
Interesting – he asked for MVC junkies to raise their hands. Out of about 200 people, one hand went up.
1. Handling SSL Pages
Should not be used for all pages (performance hit, etc)
Should be able to easily mark a page for SSL use – including the ability to switch them back and forth easily and even the ability potentially to do it without a recompile. I like it.
Technique 1: Class Interception
One base class for SSL pages and another for Non-SSL
Hard coded into code-behind, secure against change. Good because it’s more secure, but bad because you have to recompile.
So create two different classes that extend System.Web.Ui.Page - PageBase and SecurePageBase. (Note: We're doing something similar in FrontEnd using a class called GCCPage. Very useful for overriding anything in Page for every single page, as well as providing convenience methods across all pages. The only thing we have not done is branch into the SSL and Non-SSL versions of the page)
SecurePageBase just extends the regular page base - with the only difference being that a member variable (RequireSSL) is set to true instead of false.
From there - simple. Just provide a simple method called in On_Init to check to see if you (1) require SSL (using member var) and (2) are not already in a secure connection, and do a Response.Redirect to the SSL version if needed!
if(!RequireSSL and !IsSecure())
{
Response.Redirect(...)
}
Also a nice approach since you can add a check for localhost and NOT do SSL. Now you don't need to config a cert locally.
Technique 2: Custom Module to check config info
Put SSL pages into config file.
Good approach because no recompile is required. But the downside is that anyone with access to web.config can do a little more damage now. Security not THAT big of a deal since web.config is not publicly accessible.
So a config section called pageRouting and configuration element collection called securePages - with elements for all url's that need to be secured. Can also have attributes in config to do things like disable for local host or blanket disable ssl entirely -- all quickly and easily.
Note: I put some xml here - which blogspot does not let me display. Do a view source to see it I guess...
So have to create a few classes to define both the ConfigurationElementCollection and ConfigurationElement...and of course a class for the ConfigurationSection for "pageRouting." I'm looking at how easy it is to decorate classes and properties with Attributes using the .NET 2.0+ tags...and wondering why I don't do it more often.
Now it's easy to read the config section using the ConfigurationManager class and see what urls need to be SSL'd, redirecting if needed.
So he's getting into tapping the Http pipeline events (as opposed to page events) to do the redirects. He is talking about NOT using Global.asax (which, by the way, we do heavily) and instead using a class that implements IHttpModule. Lets you tap into the exact same events, but it's reusable! Gonna have to remember this.
Just implement a single event (Init(HttpApplication context)) and then you can wire into any event:
i.e. context.PostAcquireRequestState += context_PostAcquireRequestState;
Then register a new HttpModule using this class in web.config and your events get fired.
My thoughts - I like the approach for its flexibility, but I don't see the lack of a recompile as a massive advantage in our environment. It's good code and I like it better than the first approach. Longer to implement, but easy to do once it's set up. And the module created is completely reusable. More I think about it, more I'm convinced I'm totally stealing his code. I HAVE to remember this about moving stuff out of global.asax. Even if we don't use the rest, this at least is good stuff.
Morning Session 1: Advanced Web Forms Practices – Part I
Miguel Castro
Solutions Architect
Excited about this one. Billed as a session for the seasoned .NET developer interested in out-of-the-box problem solving.
Interesting – he asked for MVC junkies to raise their hands. Out of about 200 people, one hand went up.
1. Handling SSL Pages
Should not be used for all pages (performance hit, etc)
Should be able to easily mark a page for SSL use – including the ability to switch them back and forth easily and even the ability potentially to do it without a recompile. I like it.
Technique 1: Class Interception
One base class for SSL pages and another for Non-SSL
Hard coded into code-behind, secure against change. Good because it’s more secure, but bad because you have to recompile.
So create two different classes that extend System.Web.Ui.Page - PageBase and SecurePageBase. (Note: We're doing something similar in FrontEnd using a class called GCCPage. Very useful for overriding anything in Page for every single page, as well as providing convenience methods across all pages. The only thing we have not done is branch into the SSL and Non-SSL versions of the page)
SecurePageBase just extends the regular page base - with the only difference being that a member variable (RequireSSL) is set to true instead of false.
From there - simple. Just provide a simple method called in On_Init to check to see if you (1) require SSL (using member var) and (2) are not already in a secure connection, and do a Response.Redirect to the SSL version if needed!
if(!RequireSSL and !IsSecure())
{
Response.Redirect(...)
}
Also a nice approach since you can add a check for localhost and NOT do SSL. Now you don't need to config a cert locally.
Technique 2: Custom Module to check config info
Put SSL pages into config file.
Good approach because no recompile is required. But the downside is that anyone with access to web.config can do a little more damage now. Security not THAT big of a deal since web.config is not publicly accessible.
So a config section called pageRouting and configuration element collection called securePages - with elements for all url's that need to be secured. Can also have attributes in config to do things like disable for local host or blanket disable ssl entirely -- all quickly and easily.
Note: I put some xml here - which blogspot does not let me display. Do a view source to see it I guess...
So have to create a few classes to define both the ConfigurationElementCollection and ConfigurationElement...and of course a class for the ConfigurationSection for "pageRouting." I'm looking at how easy it is to decorate classes and properties with Attributes using the .NET 2.0+ tags...and wondering why I don't do it more often.
Now it's easy to read the config section using the ConfigurationManager class and see what urls need to be SSL'd, redirecting if needed.
So he's getting into tapping the Http pipeline events (as opposed to page events) to do the redirects. He is talking about NOT using Global.asax (which, by the way, we do heavily) and instead using a class that implements IHttpModule. Lets you tap into the exact same events, but it's reusable! Gonna have to remember this.
Just implement a single event (Init(HttpApplication context)) and then you can wire into any event:
i.e. context.PostAcquireRequestState += context_PostAcquireRequestState;
Then register a new HttpModule using this class in web.config and your events get fired.
My thoughts - I like the approach for its flexibility, but I don't see the lack of a recompile as a massive advantage in our environment. It's good code and I like it better than the first approach. Longer to implement, but easy to do once it's set up. And the module created is completely reusable. More I think about it, more I'm convinced I'm totally stealing his code. I HAVE to remember this about moving stuff out of global.asax. Even if we don't use the rest, this at least is good stuff.
Random conference thoughts
1. The store in this place is ridiculously expensive. Dinner last night: small tuna salad wrap, bag of chips, 20 oz Coke. Cost: $15.18. And the tuna salad was terrible.
2. This is a conference for developers. Laptops everywhere. In the main hall, I have counted a total of about 10 outlets. At least I got one of em.
2. This is a conference for developers. Laptops everywhere. In the main hall, I have counted a total of about 10 outlets. At least I got one of em.
Keynote: Visual Studio 2010 - Get Ready for the Next Wave
So the first session of VSLive Orlando. I'm going to post some stream of consciousness sort of thoughts on each of the sessions here. Enjoy!
Keynote: Visual Studio 2010 – Get Ready for the Next Wave
Matt Carter
State of dev – failure high!
68% of proj never make it to production
VS2010 around reducing failure
“Over 50% of projects will cost almost 200% of their original budget.” – Forrester. P&C was ok!
Focus on capacity planning and PM-ish features (in Team Foundation) – Does this integrate with Project?
SketchFlow in Expression Studio 3 for prototyping. Looks like an intereting tool worth considering.
Claim: “Regression errors are a thing of the past.” Big words, Matt. Big words.
They have a new light version of TFS coming out. Not sure if it will be cheaper or what. But promising.
Showed off some of the manual testing stuff in TFS. Nothing special, but integration is nice. Really turns VS into your hub for everything.
Performance of VS2010 pretty slow – promises better by release!
And the first crash occurs 34 minutes in while connecting to TFS. Mark it!
One cool part about manual testing – it automatically captures video of the steps.
I like that the testing/bug tracking/development are all integrated.
Ah, kinda cool. Automatically creates a test for the developer after bug is generated, and will walk through and replay the EXACT steps the QA tester used to generate the bug. Less sending the bug back?
Better Visual Studio Gallery integration…never used it, but maybe I will now.
Undock individual tabs – nice.
Trying to improve start page. Looks like ability to add widgets. He’s trying to show off some sort of Twitter feedback mechanism. Not really working and I don’t understand it. I’m gonna go out on a limb and say I can safely continue to ignore this stuff.
Keynote: Visual Studio 2010 – Get Ready for the Next Wave
Matt Carter
State of dev – failure high!
68% of proj never make it to production
VS2010 around reducing failure
“Over 50% of projects will cost almost 200% of their original budget.” – Forrester. P&C was ok!
Focus on capacity planning and PM-ish features (in Team Foundation) – Does this integrate with Project?
SketchFlow in Expression Studio 3 for prototyping. Looks like an intereting tool worth considering.
Claim: “Regression errors are a thing of the past.” Big words, Matt. Big words.
They have a new light version of TFS coming out. Not sure if it will be cheaper or what. But promising.
Showed off some of the manual testing stuff in TFS. Nothing special, but integration is nice. Really turns VS into your hub for everything.
Performance of VS2010 pretty slow – promises better by release!
And the first crash occurs 34 minutes in while connecting to TFS. Mark it!
One cool part about manual testing – it automatically captures video of the steps.
I like that the testing/bug tracking/development are all integrated.
Ah, kinda cool. Automatically creates a test for the developer after bug is generated, and will walk through and replay the EXACT steps the QA tester used to generate the bug. Less sending the bug back?
Better Visual Studio Gallery integration…never used it, but maybe I will now.
Undock individual tabs – nice.
Trying to improve start page. Looks like ability to add widgets. He’s trying to show off some sort of Twitter feedback mechanism. Not really working and I don’t understand it. I’m gonna go out on a limb and say I can safely continue to ignore this stuff.
Subscribe to:
Posts (Atom)