Be Careful with GIDs in Rails
blog.julik.nl
Be Careful with GIDs in Rails
1–10 of 22 posts
Re: Be Careful with GIDs in Rails
#2Re: Be Careful with GIDs in Rails
#3Re: Be Careful with GIDs in Rails
#4If there’s a gotcha it’s that _signed_ global ids are only signed, not encrypted, and very few people seem to know about the optimised method (globalid::Locator.locate_many) for loading a batch of global ids
Re: Be Careful with GIDs in Rails
#5Any popular Rails apps that use to_global_id?
Re: Be Careful with GIDs in Rails
#6Re: Be Careful with GIDs in Rails
#7GID's are great - i think the issue is with how they leveraged rubyLLM for something they should inherently not be using LLMs for.
> Remember that GIDs were made for facilitating ActiveJob serialization - they are a system-level facility, not a product-level facility.
I think this is somewhat obvious given the signature like gid://awesome-app/Post/32; there is no scoping to the user or account so it should be treated like a global lookup. If you need scoping to a user/account you can build that.
Honestly I think this is a matter of the author using poor design decisions and over leveraging LLMs. But this is not the fault of Rails, it is working as expected.
Be careful with LLMs!
Re: Be Careful with GIDs in Rails
#8Then the problem with this post boils down to applying the authorization layer in any tool call, just like you do in controllers. Seems obvious?
Re: Be Careful with GIDs in Rails
#9This title is odd, given the actual identified problem seems to be LLMs writing code.
Re: Be Careful with GIDs in Rails
#10Any popular Rails apps that use to_global_id?