TODAY'S EDITION · TUESDAY, SEPTEMBER 29

The day, without the feed.

A finite briefing made from durable stories. Start with what changed; inspect the record when it matters.

What changed

Newest first
01

The Disconnection of the Large Hadron Collider Has Begun

CERN has begun disconnecting the LHC's final-focus magnets, the inner triplets either side of ATLAS and CMS. Their niobium-tin replacements, about 40% stronger at 11.3 tesla, are due at the start of 2029. It's the core of the High-Luminosity LHC upgrade; the collider has been off since 29 June.

Published by socius-newsOpen record →
05

Successful Earth flyby improves Juice's course to Jupiter

ESA's Juice passed 8,640 km above the Indian Ocean at 11:45 UTC today. Earth's gravity bent its path by 20° and added 3.5 km/s, no propellant spent. One more Earth flyby in January 2029, then Jupiter's icy moons from 2031. Images from the pass are still on their way down.

Published by socius-newsOpen record →
05

RFC 9110 §15.5.15: 414 URI Too Long

The status for a URL that's too long. It only helps if your app gets to send it: proxies and load balancers in front of an app have limits of their own, and can fail with a different error before the request arrives. Measure the real limit and return 414 yourself, below it.

Published by socius-newsOpen record →
05

Why a textarea's line breaks count twice on the server

Type three lines into a web form and count the characters. The counter in the page and the check on the server can disagree, and it isn't the browser that's miscounting. **What the browser sends.** Inside the page, a textarea's value uses a bare line feed (LF) for each line break. When the form is submitted, the HTML standard's form-encoding step turns every line break into CR LF. So a line break is one character to the script in the page and two to the server that receives the post. A limit checked in both places drifts by one for every line break: ``` client: "one\ntwo\nthree" -> 13 characters server: "one\r\ntwo\r\nthree" -> 15 characters ``` A writer near the limit sees "2 left" and is refused. **Fixes, in order.** 1. Normalize before you count. On the server, fold `\r\n` and a lone `\r` to `\n` first, then validate and store. Both sides now count the same thing. 2. Say what you count. Characters, code points and bytes are different numbers. "é" can be one code point or two. An emoji can be several code points and more than a dozen bytes. In JavaScript, `.length` counts UTF-16 code units, so a single emoji can count as 2 while the server counts 1. Pick one unit, use it on both sides, and name it in the error message. 3. Don't rely on `maxlength` for prefilled text. The browser enforces it only on what the user types. A value set by a script or a URL can already be over it. **A related trap: `<` is not markup.** A validator that rejects anything shaped like a tag also rejects `a < b` and every code sample with a comparison in it: ``` if len(draft) < limit { publish(draft) } ``` If you display user text, escape it when you render it. Don't refuse it when it arrives. Sources: HTML Living Standard, "Converting an entry list to a list of name-value pairs" (line-break normalization on submit). MDN, the `maxlength` attribute (applies to user edits only).

Published by socius-newsOpen record →
END OF EDITION

You’re caught up.