Class files and performance

Collapse
This topic is closed.
X
X
 
  • Time
  • Show
Clear All
new posts
  • Chris

    #1

    Class files and performance

    Are there any performance/general issues with putting classes in the .vb
    files in the app_code folder rather than compiling them into assemblies


  • Juan T. Llibre

    #2
    Re: Class files and performance

    Only the first time any page in the app is run.
    From that point on, all the files in App_Code will have been compiled, too.

    I view this, not from a performace viewpoint but, from a security viewpoint.

    I compile all my helper classes and upload the assembly/assemblies to the /bin directory.
    That way, my precious code is safe in my development computer.




    Juan T. Llibre, asp.net MVP
    asp.net faq : http://asp.net.do/faq/
    foros de asp.net, en español : http://asp.net.do/foros/
    =============== =============== =====
    "Chris" <nospam@nospam. comwrote in message news:OGtPtO6cHH A.5044@TK2MSFTN GP05.phx.gbl...
    Are there any performance/general issues with putting classes in the .vb files in the app_code
    folder rather than compiling them into assemblies

    Comment

    • =?Utf-8?B?UGV0ZXIgQnJvbWJlcmcgW0MjIE1WUF0=?=

      #3
      Re: Class files and performance

      Right, but neither files from the APP_CODE folder nor assemblies from the
      /bin folder are ever served anyway. The only security issue might be from a
      rogue developer who has access to the files. And even in that case, if your
      source files aren't available but your assemblies are, they can just
      decompile them.
      Yes? No?
      :-)
      --
      Site: http://www.eggheadcafe.com
      UnBlog: http://petesbloggerama.blogspot.com
      Short urls & more: http://ittyurl.net




      "Juan T. Llibre" wrote:
      Only the first time any page in the app is run.
      From that point on, all the files in App_Code will have been compiled, too.
      >
      I view this, not from a performace viewpoint but, from a security viewpoint.
      >
      I compile all my helper classes and upload the assembly/assemblies to the /bin directory.
      That way, my precious code is safe in my development computer.
      >
      >
      >
      >
      Juan T. Llibre, asp.net MVP
      asp.net faq : http://asp.net.do/faq/
      foros de asp.net, en español : http://asp.net.do/foros/
      =============== =============== =====
      "Chris" <nospam@nospam. comwrote in message news:OGtPtO6cHH A.5044@TK2MSFTN GP05.phx.gbl...
      Are there any performance/general issues with putting classes in the .vb files in the app_code
      folder rather than compiling them into assemblies
      >
      >
      >

      Comment

      • Juan T. Llibre

        #4
        Re: Class files and performance

        re:
        !The only security issue might be from a
        !rogue developer who has access to the files.

        That's enough of a risk to be concerned about.
        There's also other security risks, like unauthorized access.

        re:
        !And even in that case, if your source files aren't available
        !but your assemblies are, they can just decompile them.
        !Yes? No?
        !:-)

        Decompilation isn't all that it's whooped up to be.
        Yes? No?

        :-)

        Are you advocating that source code in the app_code directory is
        less a security risk than compiled assemblies in the /bin directory ?

        To me, that'd be surprising, Peter.



        Juan T. Llibre, asp.net MVP
        asp.net faq : http://asp.net.do/faq/
        foros de asp.net, en español : http://asp.net.do/foros/
        =============== =============== =====
        "Peter Bromberg [C# MVP]" <pbromberg@yaho o.yabbadabbadoo .comwrote in message
        news:DEDD33CA-B5D3-4C88-A7E1-73D51ABCF667@mi crosoft.com...
        Right, but neither files from the APP_CODE folder nor assemblies from the
        /bin folder are ever served anyway. The only security issue might be from a
        rogue developer who has access to the files. And even in that case, if your
        source files aren't available but your assemblies are, they can just
        decompile them.
        Yes? No?
        :-)
        "Juan T. Llibre" wrote:
        >
        >Only the first time any page in the app is run.
        >From that point on, all the files in App_Code will have been compiled, too.
        >>
        >I view this, not from a performace viewpoint but, from a security viewpoint.
        >>
        >I compile all my helper classes and upload the assembly/assemblies to the /bin directory.
        >That way, my precious code is safe in my development computer.
        >>
        >>
        >>
        >>
        >Juan T. Llibre, asp.net MVP
        >asp.net faq : http://asp.net.do/faq/
        >foros de asp.net, en español : http://asp.net.do/foros/
        >============== =============== ======
        >"Chris" <nospam@nospam. comwrote in message news:OGtPtO6cHH A.5044@TK2MSFTN GP05.phx.gbl...
        Are there any performance/general issues with putting classes in the .vb files in the app_code
        folder rather than compiling them into assemblies
        >>
        >>
        >>

        Comment

        • Mark Rae

          #5
          Re: Class files and performance

          "Juan T. Llibre" <nomailreplies@ nowhere.comwrot e in message
          news:OyEs$$$cHH A.1244@TK2MSFTN GP04.phx.gbl...
          Are you advocating that source code in the app_code directory is
          less a security risk than compiled assemblies in the /bin directory ?
          >
          To me, that'd be surprising, Peter.
          Me too, FWIW...


          Comment

          • =?Utf-8?B?UGV0ZXIgQnJvbWJlcmcgW0MjIE1WUF0=?=

            #6
            Re: Class files and performance

            I'm not advocating anything here, just pointing out what seems to be
            self-evident. I personally do not have an APP_CODE folder in any of my
            production work.

            However, my point, which you may have missed, is that somebody who wants
            your code would need access to the IIS deployment folder in either case. If
            that's a security issue, you could certainly make the case that leaving
            source code there is less of a risk than your compiled assemblies, but the
            fact of the matter is that I am on your box and I AM going to get your
            "stuff" one way or the other - MWAHAHAHAH!

            :-) Peter
            --
            Site: http://www.eggheadcafe.com
            UnBlog: http://petesbloggerama.blogspot.com
            Short urls & more: http://ittyurl.net




            "Juan T. Llibre" wrote:
            re:
            !The only security issue might be from a
            !rogue developer who has access to the files.
            >
            That's enough of a risk to be concerned about.
            There's also other security risks, like unauthorized access.
            >
            re:
            !And even in that case, if your source files aren't available
            !but your assemblies are, they can just decompile them.
            !Yes? No?
            !:-)
            >
            Decompilation isn't all that it's whooped up to be.
            Yes? No?
            >
            :-)
            >
            Are you advocating that source code in the app_code directory is
            less a security risk than compiled assemblies in the /bin directory ?
            >
            To me, that'd be surprising, Peter.
            >
            >
            >
            Juan T. Llibre, asp.net MVP
            asp.net faq : http://asp.net.do/faq/
            foros de asp.net, en español : http://asp.net.do/foros/
            =============== =============== =====
            "Peter Bromberg [C# MVP]" <pbromberg@yaho o.yabbadabbadoo .comwrote in message
            news:DEDD33CA-B5D3-4C88-A7E1-73D51ABCF667@mi crosoft.com...
            Right, but neither files from the APP_CODE folder nor assemblies from the
            /bin folder are ever served anyway. The only security issue might be from a
            rogue developer who has access to the files. And even in that case, if your
            source files aren't available but your assemblies are, they can just
            decompile them.
            Yes? No?
            :-)
            >
            "Juan T. Llibre" wrote:
            Only the first time any page in the app is run.
            From that point on, all the files in App_Code will have been compiled, too.
            >
            I view this, not from a performace viewpoint but, from a security viewpoint.
            >
            I compile all my helper classes and upload the assembly/assemblies to the /bin directory.
            That way, my precious code is safe in my development computer.
            >
            >
            >
            >
            Juan T. Llibre, asp.net MVP
            asp.net faq : http://asp.net.do/faq/
            foros de asp.net, en español : http://asp.net.do/foros/
            =============== =============== =====
            "Chris" <nospam@nospam. comwrote in message news:OGtPtO6cHH A.5044@TK2MSFTN GP05.phx.gbl...
            Are there any performance/general issues with putting classes in the .vb files in the app_code
            folder rather than compiling them into assemblies
            >
            >
            >
            >
            >
            >

            Comment

            • Juan T. Llibre

              #7
              Re: Class files and performance

              <chuckle>

              Among two evils, I'd certainly choose the smaller one, though.




              Juan T. Llibre, asp.net MVP
              asp.net faq : http://asp.net.do/faq/
              foros de asp.net, en español : http://asp.net.do/foros/
              =============== =============== =====
              "Peter Bromberg [C# MVP]" <pbromberg@yaho o.yabbadabbadoo .comwrote in message
              news:3E514133-EDC5-43A6-96FF-466DDE95F12D@mi crosoft.com...
              I'm not advocating anything here, just pointing out what seems to be
              self-evident. I personally do not have an APP_CODE folder in any of my
              production work.
              >
              However, my point, which you may have missed, is that somebody who wants
              your code would need access to the IIS deployment folder in either case. If
              that's a security issue, you could certainly make the case that leaving
              source code there is less of a risk than your compiled assemblies, but the
              fact of the matter is that I am on your box and I AM going to get your
              "stuff" one way or the other - MWAHAHAHAH!
              >
              :-) Peter
              --
              Site: http://www.eggheadcafe.com
              UnBlog: http://petesbloggerama.blogspot.com
              Short urls & more: http://ittyurl.net
              >
              >
              >
              >
              "Juan T. Llibre" wrote:
              >
              >re:
              >!The only security issue might be from a
              >!rogue developer who has access to the files.
              >>
              >That's enough of a risk to be concerned about.
              >There's also other security risks, like unauthorized access.
              >>
              >re:
              >!And even in that case, if your source files aren't available
              >!but your assemblies are, they can just decompile them.
              >!Yes? No?
              >!:-)
              >>
              >Decompilatio n isn't all that it's whooped up to be.
              >Yes? No?
              >>
              >:-)
              >>
              >Are you advocating that source code in the app_code directory is
              >less a security risk than compiled assemblies in the /bin directory ?
              >>
              >To me, that'd be surprising, Peter.
              >>
              >>
              >>
              >Juan T. Llibre, asp.net MVP
              >asp.net faq : http://asp.net.do/faq/
              >foros de asp.net, en español : http://asp.net.do/foros/
              >============== =============== ======
              >"Peter Bromberg [C# MVP]" <pbromberg@yaho o.yabbadabbadoo .comwrote in message
              >news:DEDD33C A-B5D3-4C88-A7E1-73D51ABCF667@mi crosoft.com...
              Right, but neither files from the APP_CODE folder nor assemblies from the
              /bin folder are ever served anyway. The only security issue might be from a
              rogue developer who has access to the files. And even in that case, if your
              source files aren't available but your assemblies are, they can just
              decompile them.
              Yes? No?
              :-)
              >>
              "Juan T. Llibre" wrote:
              >
              >Only the first time any page in the app is run.
              >From that point on, all the files in App_Code will have been compiled, too.
              >>
              >I view this, not from a performace viewpoint but, from a security viewpoint.
              >>
              >I compile all my helper classes and upload the assembly/assemblies to the /bin directory.
              >That way, my precious code is safe in my development computer.
              >>
              >>
              >>
              >>
              >Juan T. Llibre, asp.net MVP
              >asp.net faq : http://asp.net.do/faq/
              >foros de asp.net, en español : http://asp.net.do/foros/
              >============== =============== ======
              >"Chris" <nospam@nospam. comwrote in message news:OGtPtO6cHH A.5044@TK2MSFTN GP05.phx.gbl...
              Are there any performance/general issues with putting classes in the .vb files in the
              app_code
              folder rather than compiling them into assemblies
              >>
              >>
              >>
              >>
              >>
              >>

              Comment

              Working...