by

How to setup Sharepoint sites for HTTPS

Hi guys, I want to share with you a discussion that I’ve participated recently.
Consider this: you are a a host provider and your company will offer Sharepoint support to the public so they can pay you a monthly fee and then they setup a Sharepoint site with you.
You go for a simplistic and cheap design. You have IIS, Sharepoint installed, and you create a web application on the port 80. Within this web app you create multiple site collections. They are the sites your clients will have control for their own setups.
And how do you host multiple websites on the port 80 with a single IP address? Easy. I will use host headers – you say.
a
b
And you think: I should be fine. I will setup in away so each client will have their own separate database, they will redirect to the given URL I will provide them and according to the hosting plan I enable disk quotas for each case. For instance, if my client pays me some little money and he is a ’silver client’ I offer them 10MB; if they are ‘platinum client’ and pay me some more I give them 50MB.
All goes fine and well. You see everybody joining your company, the clients keep coming and your setup is totally independent.
so, what’s the problem here?
1

You are unable to offer HTTPS in that setup. If one of your clients wants to add a shopping cart area and want it to be secure, you can’t help them with that model.
The thing is, IIS can not resolve an incoming HTTPS request like that. ISS will hold the request and it is going to ask himself: ok, to which website should I give this request? Unfortunately IIS as of now can not address this question following that setup. Everybody is under the same IP.
To fix that one of the recommended approaches is to follow the diagram below:

2

On your IIS you will create multiple web applications, then for each web application you will want to give separate IPs and then host sites on these IPs, and then these web applications are the ones you will offer to your clients.
That’s a little bit more elaborated solution, a little bit more expensive but the gains in scalability will overcome the headaches you might have in the future with an atomic structure that at some point needs to be flexible.
And on that model IIS can finally then fix the SSL dilemma. Because then you will assign the applications to independent IP addresses on the ISS Manager.
Sometimes it takes more than a quick and simplistic approach to design a solution if you only know partially the products involved. Once you have the proposed design please be aware of the issues that are basic in the parts involved. In our case, a knowledge of IIS would have avoided a big trouble in the beginning.
See you later.

By

by

Filling the SOA gaps

Hi guys,
Let's talk architecture again, reference architecture, more
specifically SOA, and how can we map the available products and resources available from Microsoft given a SOA project?
Before I start, let me make a statement here: I will talk this from the Microsoft's point of view, since this is a blog about Microsoft technologies.
In any case, it doesn't matter what's your preferred provider as long as you are able to correctly do the mapping of functionalities to better fit your business' plans, budget and SLA. And just to revisit: SOA is an architecture where the functionalities of existing business applications are exposed and published as services.
And what would be a service? Services are software components that expose application functionalities in a given SOA architecture and they are:
- self-manageable;
- message-based oriented;
- can handle and support many protocols;
- can be published on a myriad of hosts;
- implement operational contracts, interfaces and message types;
Of course you can design some service that doesn't follow these rules, but let me tell you: Rules are made with a purpose and in our case the purpose is to design a solution where clients and services are highly decoupled, thus paving the way for the reuse of functionalities. One of the goals is to maximize the resource utilization in our project.
I won't talk here about governance, granularity, message routing, service level control etc. I won't go there for it is a much larger topic, so this post is about the technical view. Now, let's make our first diagram given what we've seen so far:
1
As we can see, we have here the common services of a SOA architecture such as the presentation services, collaboration, systems integration, orchestration services etc.
Looking at this diagram we can identify the aspects that we really want to map in our solution to be successful. Note that in some scenarios sometimes the security is critical, sometimes the orchestration is paramount, sometimes the platform integration is more important.
Now, visualize this filling the gaps with the products that Microsoft has to offer.
2
An interesting conclusion we can take at first sight is that some products can cross domain frontiers and can handle various capacities at once, such as the Windows Workflow Foundation, which can be used for interoperability services and orchestration at the same time with BizTalk Server.
What's the best option to choose? Well, to be able to see this big picture and to choose the best piece in the puzzle is your job as architect. Unfortunately many architects fall in the problem to overkill the solution.
Also important is to choose not to overkill the solution. Sometimes a simple custom application can fill the gap enough to not require a bigger solution like Windows Workflow Foundation, for example. Otherwise the whole project just becomes harder to handle and to maintain...thus increasing the ROI overtime...and the developers patience.
The message to keep in mind: any good architecture is composed by many capacities. To identify these capacities and which one of them are important for our solution is as critical as choosing the technology provider.
See you later.

By

by

New home

www.superedge.net

by

File Upload and Canonical Issues

Never trust the user input. The incoming data can be the source of many devils and a security flaw can be there just waiting for the right moment and the right person to break your application.
After finishing with the upload control I finally did the integration with the website. Now the users can select the files and send it to the website to be processed.
1
What are the security risks here? Something that can be called 'canonicalization issue'.
For a start all data can be seen on its canonical form. A canonical form is the most simple and most stardard form that any data can be represented, thus canonicalization is the process of converting the data to its canonical form.
Proficient JavaScript programmers are very aware of what I am talking about, and as a matter of fact in our system the user can search for a name using wildcards. So you can ask him: "Retrieve me a list of all the instances where its canonical form includes Bill as mandatory prefix" The user will probably say: "Retrieve what???" but if you ask them: "Give me a list of all the users where their names start with Bill" they will type in the system 'bill*'. The user normally does not know that but he is doing is performing a 'type of canonical query'.
Now, back to our file upload issue. A file name is a very common canonical type. You can call the same file as:
  • thairecipes.doc
  • c:\recipes\thairecipes.doc
  • c:\\recipes\\thairecipes.doc
  • c:\   recipes\thairecipes.doc
  • c:%3A%5Crecipes%5Cthairecipes.doc
As you probably figured the last one is the issue. Your Windows operating system will recognize the symbols %5C and %3A.
You see now because we are giving to the user the option to save in our system just about any file name he wants to at the same time we are also opening a door for a sort of canonical attack. Remember : Never trust the user. And by user I am not only talking about a person. In our context an user is any entity who uses a given resource or service, and for that matter an user indeed can be another system or another application.
A hacker would think: "how can I break into this site? Does it allow any easy access to any of its resources?". In our case, yes our website must allow the user to upload files.
What to do now? How to handle a file upload to a web server?
Well, first as a general rule you must not design a website that accept just about any file names created by the user and save it like that. As a matter of fact, any input must be validated and sanitized  if possible, not only in client-side but on the server-side as well.
A better design: Do not allow the user to save the file in the web server with the filename that he wants to use. Accept the file, keep the original filename somewhere and let the application rename that file with another name and then save it. I would suggest you to use a GUID string for that matter. That way you are not only closing the doors for a possible canonical attack but also you do not give a chance to a malicious user to try to find out the filenames you might have in your server. For example, If a hacker knows that there is a file called http:\\mywebsite\mydocs\clientid1\file1.doc he will try something like http:\\mywebsite\mydocs\clientid1\file2.doc, and then http:\\mywebsite\mydocs\clientid1\file3.doc and so on. By using an internal name rule creation you minimize his surface.
2
Another thing to observe: You don't have to fight against and defeat a malicious user, probably there can be hundreds of hackers trying to break your code and you are just one guy against them ( and you don't want to have any sleepless nights during weekends, do you? ) They always find a way to break your code. The best option is to minimize their attack surface. Chances are they are going to move on and concentrate their efforts to break a "weaker website" if your site if strong enough for the first rounds of attack.

These would be some instinctive considerations and additionally I would suggest to take a look at implementing File I/O guidelines as well. At the end of the day, it all depends about how secure you want to be, how much time you have available to implement it and how rigid the specifications were given.
See you later.

By

by

Uploading files and bubbling events

This week while I was awaiting for a new project confirmation I saw myself doing some code fixing for another project, that's something quite common and I really don't mind that. One of my tasks was to develop a little page to upload images to a server. That's not a problem, so I decided to try something new. Yes, I was very keen to use Silverlight for the task, but I used some good old javascript and a very cool concept similar to the called bubbling events, which is basically to raise an event from a determined and let it propagate up in the chain until it is captured.
My first idea was : I will create a web user control that can be easily added to a common web page and this guy will pass the list like a bubbled event.
1
This control will implement an interface to select and hold a list of files and will be able to send that list to the page and notify the page the list is ready to upload. Let's call it MyUpload control.
2
being a user control any programmer can then drag and drop this guy to any page and it must be atomic enough to not be too attached to the parent. So it inherits from usercontrol, and will have, at least for now, 2 methods called upload and a click. Here the things are getting cool. This click event is an event raiser.
3
When a programmer use this control, by calling the click method it will pass the selected file collection to the page. How? sending the list as arguments of the call.
The upload method must then be responsible populate the list and send this list to the caller.
4
Once the event is triggered in the webpage this page will loop through the items in the received file list and for each instance I will 'save file as...' and provide the path in the web server directory. This will move the file to the desired location as specified in the document request.
5
Could I save the files in the database? Yes, I could but all the specs for the task are done and that was the mission. So I won't discuss any matters of  a better solution for this given scenario.
My upload control will have two buttons add and remove files which will be responsible for maintaining the list of files I want to upload. Why is that? because we want to upload a list of files in one shot and not one by one. Indeed, I'll spend more hours implementing this solution but at the end this will be a reusable control and as I said, any other programmers will then just drag and drop it should they need to implement a similar solution.
How do implement the code for add and remove files? That's the most difficult part and requires a good amount of javascript knowledge. Just this javascript routine can be subject of a post by itself. For now let's say the control has a private method called buildjavascript which renders in the page all the javascript methods necessary to maintain this object list.
6
Returning to our code behind, this list will be a collection and the best way to keep it and pass it by posting is to make it inherit from a very cool and useful class for this situation: the HttpFileCollection.
7
The upload button in the control will call the upload method which does nothing but raise the event to the page. The page who has the control implements already the method expected to parse the list as an HttpFileCollection object. Now, we only have to save the object as new name, being in a new location.
8
My initial design is done and I am doing the javascript side of things. This week was hectic but once things come back to normality and some time is left for me, I will share my code here somewhere.
See you later.

By

by

Stored procedure takes longer run SQL2005 than 2000

Here there is something interesting that I would like to share with you guys.

Even thou Microsoft SQL Server 2005 is out for quite some time, it is still common to see people working in projects using Microsoft SQL Server 2000 and often in mixed environments.

That's the case I want to talk about: The mixed environment, and I am working in a project where some applications have that hybrid configuration.

So someone told me that my report developed in .NET 2.0 was running slower than the similar one done in the old fashioned ASP. Of course I denied, just to see later the proof I was wrong.

Yes, the same stored procedure executed from the same page from, in the same machine was running faster in the old environment while it was slower in the new (and supposedly improved) environment. How's that possible? I traced the execution, used the SQL profiler but nothing gave me a good clue. Than I found this in the Microsoft website.

In SQL Server 2000, the execution plan for the query uses an Index Seek operator. In SQL Server 2005, the execution plan for the query uses an Index Scan operator. The optimizer produces an index spool for the Index Scan operation. When you use the FORWARD_ONLY cursor, SQL Server scans the index for every FETCH statement. Each fetch takes a long time. Therefore, the query takes a long time to execute.

See that example below:

50 declare @p1 int

51 set @p1=0

52 declare @p3 int

53 set @p3=16388

54 declare @p4 int

55 set @p4=8194

56 declare @p5 int

57 set @p5=0

58 exec sp_cursoropen @p1 output, <Transact-SQL statement> ,@p3 output,@p4 output,@p5 output

This code will run faster if you are NOT using the .NET 2005 SQL Connectors or running in a SQL Server 2000. Here we are using the sp_cursoropen to open a cursor, then specifying the forward-only option in the parameter list.

This is a bug you can only experience if you are using a lot of cursor-based stored procedures from a SQL 2000 to a SQL 2005 environment, and here we have a VERY HIGH cursor usage. (not that I like them neither I defend its usage, it is just a fact from the environment here)

How to fix this?
If you do not want to download and apply the patch and want to fix this in the code itself use "OPTION (FAST 1)" in the stored procedure call. That will make it run faster in the SQL 2005 machine. Otherwise download here and here the patches.

See ya later

By

by

TeamSystem and TFS add-on to Count Lines of Code and Predict Errors

Here another cool thing. From the Microsoft download website you can find this:

"Microsoft IT partnered with Microsoft Research to create a VSTS 2005 extension that counts lines of code and predicts system defects. In the software development environment, insight into the volume of code being produced, and the changes applied to that code, provide measurements of productivity and quality. The Line of Code (LOC) counter provides a flexible and extensible framework for automating the LOC counting process."

Isn't that amazing ? Finally a cool software metric add-on for Team System, and if you wanted another reason to stop using SourceSafe and start using Team Foundation System guess what: It also works with TFS.

If you use Team System or TFS, get it here.


See you later.

By

by

How to Make Productive Project Meetings


Project Meetings can be very productives but also can be a real waste of time and money.
Recently while working on a client where I was responsible to have a project development meeting as meeting coordinator. The group of participants were an heterogeneous group and despite the fact that I did not know some of the atendees, the meeting was a big success.
During a conversation on our coffee break I was asked about meetings strategies and how to conduct them.
So I am going to share with you guys here what I told them, and what I effectivly did during that particular meeting:
  • Every meeting MUST have 3 elements: purpose, agenda and maximum duration. If any of these items is missing, the meeting is meaningless and should not happen.

  • Make sure you are able to define a purpose for the meeting in a maximum of 2 sentences, for instance:"This meeting is to plan the new developments for the project X". This way, everyone will know why they are there, what needs to be done and how to proceed in order to well-succeed.

  • Define a clear agenda in advance. Make a list of all the items to be discussed, revised, analysed, displayed etc. When I conduct meetings, my personal strategy is to allocate a time limit for each item in the agenda and to assign the responsability to lead the discussion to someone in the group. Works as a charm.

  • Define a duration for the meeting, how many minutes/hours it should last. From the start make crystal clear to everyone what time the meeting will start and, sometimes more importantly, when it will end. It is amazing the number of managers who have absolutely no control of their meetings and do not know how to enforce the finishing rule. If you think you have this habit...CHANGE THIS !!!

  • Do not wait for the delayed people. Meetings must start on the agreeded time. Do not wait about late arrivals. Do not wait for those who need to be called for the meeting. You just make sure everyone gets notified, then when someone arrives after the meeting have started, DO NOT STOP TO REVIEW WHAT WAS SAID. Do this as a proof of respect to those who arrived on time.

  • If the meeting's organizer is late, Consider the meeting cancelled, and get back to work. How long is considered late? Depends on the company, but I would not wait more than 5 minutes.

  • Document your meeting. What I do is to put someone in charge of writing down the notes. What to put in the meeting notes? Basically the name of the attendants, the discussed subject, the agreed points, the next developments and/or actions with dates and their respective responsibles.

  • When the meeting is over - do not wait more than 24 hours - the meeting notes must be sent to: All the participants, to those who could not make it to the meeting and to those who might be influenced by upcoming decisions.

  • Keep the focus. Every meeting must have a regulator to notify the others when someone is discussing any subject outside the scope of the current topic. Ask one of the presents to volunteer for this task when the meeting is about to start. His/her task is to interrupt the meeting at any given time when the focus is lost and bring back the main subject. This new outside topic can maybe then be noted and even can be discussed in future meetings. In case of doubt regarding a specific topic being in or outside the scope, the meeting organizer has the final word.
I hope these notes can be of any help in your next meetings. If you have any comments or other meetings ideas, please feel free to leave them here and share as well.
See ya later.

By

by

A safer code

During my professional career up to now, I had the chance to work with all sorts of developers. From the reasonable to the excellent ones; and talking with some colleagues this week about that fact I have to say, it does not matter how bad or good they were I must say in every case I learnt something good with them. And one thing specially was common in all the cases: how to write a more secure code.

Which brings me to another point of discussion: how do you measure yourself as a code-writer? do you think you are a good coder? What makes you such a good developer? How do you approach a problem before you start coding?

And when I stop to think about the last sentence I remember an article I read about making your code safer and a concept I've learned reading the book "Decline and fall of the American programmer" from Edward Yourdon : The silver bullet. Basically the silver bullet is the only thing that can kill a werewolf, portrayed as a software bug or a business problem, and unfortunately just like this mythical creature there is no silver bullet for the real life issues we face everyday. There is no 'exact and single' solution for our problems.

So, to make you code safer is literally up to you. Nobody else, therefore excluding the programming language you use. Just because you are using C# it does not means it will be a better product than if you were using Visual Basic 6. OK, it will save you development and release time but just the language won't make your product better or your code safer. Again, only the developer can predict and treat the vulnerabilities.

And because of this we go to another layer of the development cycle: The design. A better and safer design can do much more for the final product than the language used to develop it. Safer products are a result from safer designs and good code practices.

It does not matter how good the product is. Once it is released, it can be attacked. No, that's not a sad destiny. As a matter of fact, as a good developer you must find this absolutely normal and expected. I write code with this in mind. Everyday. And even thou the clients tell me: "this is only going to be used within our department", I still do not change my mind. It can lead to a little bit longer development time, yes, but the gains in security and stability in the application are far greater.

So, I do not worry about the securities holes the application might have in a future because the application will run in a new platform and I should have done "this" instead of "that". Again: I accept the fact the application one day will be attacked. My biggest concern here is: How my code will behave when it gets attacked?

So, spend the time you want in improving your code. We should be proud of our coding skills just like a father is proud of his offspring.

And we know sometimes the parents can be blind about their sons skills and abilities. To avoid this pitfall with your code, ask someone senior to review your code. Meet someone who really knows what's he is talking about and ask him to review your work.

If this person is really good, I have two words of advice for you: Be humble and prepare yourself. Asking someone to review your work can be an amazing learning experience about yourself and the way you see the problems.

Remember what I mentioned: you always can learn something new, from the good and from the not so good. This is a big lesson from life to those who have an open mind to learn.

By

by

Fix Visual Studio 2005 Slow Start

Microsoft Visual Studio 2005

If you are, like me, a heavy user of Microsoft Visual Studio 2005, chances are that you have experienced at some point a very slow application start. Once my visual studio 2005 was taking about 30 seconds just to load the interface.

After some good research, I could find a very interesting point: my visual studio was referencing a solution that I haven't worked in the last 8 months. Going deep on this, I saw this registry key:
HKEY_CURRENT_USER\Software\Microsoft\VisualStudio\8.0\ProjectMRUList (MRU stands for "Most Recently Used")
If you have never touched this key via any regedit application, chances are that it is holding the last 20 projects you worked using VS 2005, and it does not matter how many are listed in your MRU list in your "File menu".

Why does Visual Studio 2005 saves the last 20 projects even thou I choose to save only the last 5 ones is still a a mistery.

So, happens that some of the solutions in my list were pointing to remote drives that I do not access anymore, thus creating this delay when loading Visual Studio.

To fix that I simply deleted the values for this key and it is all good now.

By

by

What is Marketing ?

iPod marketing share

Dear friends, today Apple released to the market the brand new iPod. Speaking of business, the iPod is such a extraordinary creation that no one could see it coming a few year ago and reaching the levels they are today and its relevance in the world market. The iPod created a brand new market for itself, and its market share is just amazing. To have an iPod today is to have status. Apple really did it, again.

But not always was like that. So let me tell you a story.


---- --- -- -
The year was 1997. Steve Jobs, who was previously fired from the company he created with a friend, was called back to Apple with a mission to rescue the company from the certain death. Once he got there, one of the first things he did, he fired the company who used to produce Apple's marketing campaigns and immediately put up Apple's marketing account up for grabs.


Mr. Jon Steel, owner of one of the agencies crazy to get such a big client, remember the exact moment when he met Jobs. According to his words, it was something like that:


"Me and my partner were almost 2 hours inside this huge meeting room with 2 others Apple's executives. Then Jobs came in. He literally broke the amazingly boring presentation we were watching. Those 2 guys were doing a presentation about Apple's history, profile, the "win-win" ideology, the key factors for success inside the company, Apple's vast portfolio, investment plans, yada yada yada.

Jobs briefly greeted us and then came straight away, without even turning his head towards the actual Apple's executives. He said:
- I am 100% sure this beautiful talk that you guys just heard from the "dynamic duo" here is all crap. So, here is the deal: The Apple is about to break. We are going for bankruptcy! but I believe that if we can make 2 or 3 things very well done, things with world class appeal, we will manage our way out of this. During the last days I rejected 11 projects that were presented to me, only 2 were left: called G4 and iMac. For me, they are the ONLY projects capable to represent what we want this company to become: Technologically superb, visually fantastic. And I will bet Apple's future on them.


We left the meeting with all the ideas from Jobs himself. A few days later, we got the news that the "dynamic duo" had been fired later that same day.”
---- --- -- -
Well, my point is. What is marketing for you? Let's call this case the "Marketing 1.0". Until mid-90s, that was the kind of marketing that trashed companies around the world, with those companies mission statements, with empty messages, boring...but very well formatted. Nowadays, this marketing does not deserve any of our attention anymore.


Sometimes I think some "marketing people" are trying to make a "cartel", a "gang". This gang would be made of their cool-other-marketing-creative-friends-from-other-companies, they create large campaigns based on repetition-repetition-repetition-repetition of the same campaigns of the past, just because there is a saying in this niche: You have to publish 10 times the same campaign, so the client will pay attention to the message. Just like those crazy rug sellers on the TV screaming every 0.5 seconds the prices out loud, treating us at home as deaf or blind consumers.


I say, that's rubbish! We can do better than this! They MUST do better than this!

That's why the Marketing 2.0 is coming powerful in the Internet age. Now, you can see very funny, creative, innovative campaigns from the Internet itself. And guess who created them? teenagers, retired people, even people who never worked with marketing before. The media revolution gave them power so other can see and tell: Hey, those guys are really cool! And they never went to those marketing schools to learn those same-same marketing laws.

Right now, the main problem of the Marketing 2.0 is the ROI, or the lack of it. It still does not have metrics, it still does not give us better "leads" for new businesses, they still do not have a strategy to align the field vendors and the employees using several communication pipes online and offline.
And that's going to be just a matter of time, and then one day those guys and this new marketing era will be able to predict entire product forecasts and compose projects budgets with efficiency. And in a new way!

The marketing 1.0 will be dead then; and with it, those who were not able to pick up the pace.

If you are a marketeer, and you like your job, think about it. What would Jobs tell about you in your next PowerPoint presentation? Would he interrupt you ? Would he support you?

And then, comes the Demand 2.0.


We should concentrate our business efforts in the clients, but those with the highest chances to turn from formal proposals to real contracts. To real money. Use the marketing 2.0 to collect, Analise the market and then create customized approaches. Now, speak clearly what is the BEST reason why this client would want to make business with you or to buy your product. When talking to the bosses, be straight, be business-oriented, goal-oriented. Stop selling only for your regular buyer.

Discover what does the client wants, what other problems they have. Attack them! Now share those ideas with those who can help to find a solution. Which bring another point: surround yourself of good people. good soldiers. DON'T LET THEM GO to another company.


Transform your website in a portal that educates the visitor about how you can help them, what solutions do you have, what problems can you solve. Place there you most successful cases. Make a blog. Let others now that your company is a good one for work, in an open-shared environment where ideas flow.


Start selling your product before the client is ready to buy!

Yes, the end of the Marketing 1.0 is near and it is coming. Throw away the old myths, open space for the new. The Marketing 2.0 is right here, right now.


Let's share ideas. I can share mine with you as well. If you don't share, how would we exchange and grow? if not here, where? if not now, when?

Think about it. See you guys later.

By

by

The Risk

Last night I had a conversation with some new friends here in the Beautiful Australia and I would like to share something with you guys to reflect upon:

"Those people you see, on the National Geographic or Discovery Chanel, who try to reach the top of the Everest, are they crazy or what ?"

Now, picture this. For many decades, many men and women have tried... and there, they lost their lives. As a matter of fact, most of these people were not even able to return to their loved ones. Despite this tragic statistic, more and more people tried... risking... knowing that they probably will die during this journey, leaving family, children, wives behind.

So, why they still did/do this ? Because it was worth it doing it. In the very risk, a transformation happens in you, something is born inside you. No other experience can give you this. It only can be developed in the risk. That's the beauty of risk.

So, here we are, talking about the idea of "live your live to the most", no regrets, no looking back.

Then another question arise: "Can you remember when did you feel most alive?"

For some, it was when they managed to speak a second language for first time, for others was when they first did bungie-jumping in New Zealand or Switzerland, for others was when their first child was born.

Now, if you remember "your special moment", I bet a shiver will run through your spine and your heartbeat increase. If I ask you to describe this feeling, you will be talking about this moment, proud of yourself and about how cool was it.

I can almost tell a pattern where people will :

- Talk about a scenario in which the risk pushed themselves out of their comfort zone and;
- The outcome of the risk is not the main goal, instead the journey is what they remember most and;
- They finish the story with a big smile and sparkling eyes.


So, there it goes. Think again about that first question I mentioned. Now, my idea is that the beauty of the risk doesn't lie in the final result - it lies in who you become in the process. Confident. Engaged. Alive. I risk to say more: this is not something you do every summer
- it becomes a habit, and it can be contagious. It gives you a new approach to life. After doing it, your life is just not the same anymore, otherwise you will feel stagnant, bored.

So, just like that famous question:"when was the last time you did something for the first time?"

See you all later!

By

by

Start Slow: TFS and Team System

Lately I have been talking a lot with my colleagues about the TFS and the Visual Studio Team System.

Even thou these are very cool ground breaking technologies, I must say that they are no silver-bullets.

Companies who does not implement the right processes for software development life cycle, will get little gain from implementing them accross their teams.

I can say without doubt that if your company uses the Microsoft Solutions Framework (MSF) methodologies as a base, that's a very good indicator; if not, please before using TFS or TS, try to engage your team on this philosofy.

visual studio 2005 team system screenTeam System is a very expensive package, and it is not like Microsoft Office, that you just install and then let the people using it. If you plan to use Team System, one advice: Start small. Start by using TFS as a version-control and take advantage of work-item tracking. Now it is a good time to leave behind those cheap-file-system-based solutions like SourceSafe and CVS. They were good, at their moments, but now time times are different, we are talking of a world-class solution.


I have never heard of a full implementation of Team System in one shot . I can only imagine that if this happen, they would fire-fight the integration of so many variables and softwares and tools, and probably will learn that very simple truth: Team System is just too big. There is just too much to learn and execute at the same time. I even risk saying that at the end it will be a very big frustration... and waste of time...and of course, money.

So, by trying first the work-item tracking, everyone can see right away something called: traceability; also code metrics and better team communication. These are only baby steps, but at least in the right direction.

Once the work-item tracking is done, do this: implement unit testing. Start small, don't be affraid, start using basic unit testing, not the whole Test-Driven Development methodology. Remember, right now we only want to kick-off our environment, so no rush. Another point, is that TDD is a highly complex practice, not only a bunch of monkeys tryping crazy stuff to test and validade the cycle, so the learning curve can be very steep. Just by implementing Unit testing you will already improve the code quality in a matter of days.

The next step is to write unit tests to validade a requirement. Oh...Don't you have requirements? in this case, return to basics...MSF.

This is another benefit that you will have in a immediate way — you will for sure understand how to meet your requirements. Why? simple, because if you can't write an unit test for requirements, then the requirement isn't testable. The unit testing tools in Team Edition for Software Testers will quilify these are "poor quality items", and we do not want to deliver poor solutions, do we?

new microsoft visual studio 2008 codename Orcas screenshot

Now, just like you read email, or drink coffe, or do a little break at 3PM for a chat with colleagues, do this: perform unit testing. everyday. There is a method called continuous integration which is perform the tests against the code before it is checked in. If this is ask too much, at least make sure to check in a buildable version of your software. That's the minimum you can do for your colleagues, and for yourself. Guarentee that the latest version is not breaking.

The reason for that is called nightly builds. Every night, a build will be performed by Team System, and it will catch all the errors during this process. So play this game, try to catch the error before TS. Chances are you won't, but again you will improve your software testing culture. At the end of the day, is way cheaper catch bugs in development than after releases.

Another good thing about nightly builds is that, after each build you will have access to a report of build metrics. That's a very extensive report about your code. How many lines of code, method counts, how many unused variables, how many changesets per build. That's history data, and in a few months you can clearly identify what pieces of code are the most critical in your solution...chances are that you will be surprised to know that a small validating method in some business logic layer is just too overloaded with calls and responsability.

Even the nightly build is a big turn. So, try run the nightly builds per assembly, for a start...then add others with the time, if all goes well and you are getting used to the methodology.

Well, here they are: TFS, work-items, unit testing, nightly builds...And just for you to know, Microsoft Best Practices says to implement Team System new features every 3 months. So, again, no rush.
Good Luck!

By