ColdFusion was a great product for its time. My employer in the early 2000s had it as our default preferred language though if a client had a different language preference, we'd use that instead. Today most of my exposure to CF is through finding untouched old code still chugging along decades after it was first written. Unfortunately, injection vulnerabilities were pervasive in CF coding practices of the era and now it's very common to find old CF programs with thousands of vulnerabilities and no one to fix them. Any documentation on the business rules in them have long been forgotten. We have web application firewalls and other monitors in place to try to catch any vulnerable code being exploited and hope someday that the departments behind the programs decide they need a major overhaul that necessitates a greenfield rewrite. I did push for us to hire someone to either correct the vulnerable code or do a transliteration conversion to a contemporary tech stack but no one wants to allocate money for it, especially since the problem is spread around many different departments.
That the ColdFusion programs have been silently doing their thing for a long time without failing is a testament to the strength and durability of the platform. It also says something about what a sleepy, mundane employer I'm with now, but sometimes it's nice to not have to deal with everything around you being a moving part constantly changing its path.
That the ColdFusion programs have been silently doing their thing for a long time without failing is a testament to the strength and durability of the platform. It also says something about what a sleepy, mundane employer I'm with now, but sometimes it's nice to not have to deal with everything around you being a moving part constantly changing its path.