terribleplan

joined 1 year ago
MODERATOR OF
[–] terribleplan@lemmy.nrd.li 1 points 1 year ago (1 children)

Pretty sure it needs to be https://$user:$pat@github.com/username/repo.git#branch.

[–] terribleplan@lemmy.nrd.li 6 points 1 year ago (2 children)
  1. You host it yourself
  2. You can get a cool domain name
  3. It's pretty low maintenance
[–] terribleplan@lemmy.nrd.li 3 points 1 year ago* (last edited 1 year ago)

I would still go with one that isn't one of the biggest. My general advice is to find one that fits the vibe you're going for, communities you're interested in (e.g. some are focused on art or cybersecurity, etc), or is somehow tied to your locality. It shouldn't matter that much, though some servers will be a little more (or less) strict with things like federation, content warnings, alt text, etc. Usually the server will have some info telling you some of this, and their admin should be linked and likely has a post or two pinned to their profile explaining some of this as well.

I am partial to kind.social, though have opted to run my own instead of joining up anywhere.

[–] terribleplan@lemmy.nrd.li 4 points 1 year ago* (last edited 1 year ago)

It depends on what specific thing you want to add geoblocking to, but often something like the MaxMind GeoIP database, which then can feed into a firewall to pre-emptively geo-block at a connection level, or as part of e.g. nginx geolocating the IP a of the connecting IP then making the blocking decision at request time.

There's a project that works with Traefik's forward-auth middleware to do this, which is probably how I would go about it if I wanted it at an HTTP level.

[–] terribleplan@lemmy.nrd.li 2 points 1 year ago

No, these issues are pretty much by-design. In ActivityPub IDs are inherently tied to the domain on which they were created. Based on the nature of federation it is safe to assume someone somewhere will still go looking for that thing via the outdated URL.

[–] terribleplan@lemmy.nrd.li 3 points 1 year ago (3 children)

If you're taking that approach make sure you shut down the stack before you copy the data over so everything gets copied over consistently (e.g. the DB isn't in the middle of a write), and yes it should pretty much be that easy.

[–] terribleplan@lemmy.nrd.li 5 points 1 year ago* (last edited 1 year ago) (1 children)

Whoo, can't wait for this season of "Wait, I thought we made progress last episode/chapter!?"

I am a bit behind on the manga, but it has been really hard to be motivated to read it. It feels like any minuscule piece of progress is followed by immediate regression. I was very much in the mindset of "Fuck you, I'll see you next week" for a while, haha.

I'll comment my thoughts after I get around to watching the episode a bit later today.

[–] terribleplan@lemmy.nrd.li 4 points 1 year ago* (last edited 1 year ago)

Things don’t get backfilled, so until a new action happens on an old post/comment/etc they won’t show up on your instance. New things should make their way in eventually though.

Taking the link of a specific post/comment from the community instance and searching for it from your instance should populate it on your instance, just like you probably had to do to get this community to show up so you could subscribe/post at all.

There are backfill tools/scripts, but unless you really want old posts I wouldn't use them. It unnecessarily increases the load on already struggling popular/overloaded instances like lemmy.world.

[–] terribleplan@lemmy.nrd.li 2 points 1 year ago

If you find a decent alternative let me know. I have been looking for a while and not found anything that supports the full feature set I want (including Twilio).

[–] terribleplan@lemmy.nrd.li 4 points 1 year ago

Agreed, I recommended filtering to only http(s) links in the github issue, I just made this x-post. I don't see a strong reason to let people link to weird things like file: and data:, or deeplink to installed apps on your computer/phone. Filtering the scheme to just http(s) is how Nutomic seems to have fixed it in the backend from what I can tell (I am not a rust dev).

[–] terribleplan@lemmy.nrd.li 4 points 1 year ago

May the Lord have mercy on us all.

 

I tried what another user reported and it worked. I submitted a github issue as the security email seems to be unmonitored based on me trying to contact it (regarding a different issue) for over a week now.

Be careful about links you click in Lemmy, I guess.

cross-posted from: https://sh.itjust.works/post/774797

What is XSS?

Cross-site scripting (XSS) is an exploit where the attacker attaches code onto a legitimate website that will execute when the victim loads the website. That malicious code can be inserted in several ways. Most popularly, it is either added to the end of a url or posted directly onto a page that displays user-generated content. In more technical terms, cross-site scripting is a client-side code injection attack. https://www.cloudflare.com/learning/security/threats/cross-site-scripting/

Impact

One-click Lemmy account compromise by social engineering users to click your posts URL.

Reproduction

Lemmy does not properly sanitize URI's on posts leading to cross-site scripting. You can see this working in action by clicking the "link" attached to this post on the web client.

To recreate, simply create a new post with the URL field set to: javascript:alert(1)//

Patching

Adding filtering to block javascript: and data: URI's seems like the easiest approach.

[–] terribleplan@lemmy.nrd.li 3 points 1 year ago* (last edited 1 year ago)

The EFF is neither right nor left wing, they advocate for privacy and freedom. Free speech includes speech you may not like, and it certainly includes things I do not like. Luckily one of the freedoms generally included in "free speech" is the freedom to ignore, shun, call out, shame, etc. those who say things I don't like if I so choose (like what you are seemingly trying to do with this post, in fact).

 

Apparently someone on lemmy.ca feels the need to make clickbait out of a very short wikipedia article. And they didn't even answer their clickbait in the post body. smh.

For added fun archive.org seemingly breaks the Lemmy UI, indicating that the community lives @web.archive.org for some reason.

Created: 9th century

"This is the most exciting piece of excrement I've ever seen ... In its own way, it's as irreplaceable as the Crown Jewels"

 

The operator of the plant is confident it is safe, some say there are other risks that make not releasing the wastewater worse, most opposition is limited to saying hasn't been enough study, one scientist in particular says it is unsafe. We'll see what ends up happening later this month.

“a lack of adequate and accurate scientific data supporting Japan’s assertion of safety”.

“The risk of another earthquake or a typhoon causing a leak of a tank is higher, and they’re running out of space.”

“The concept of dilution as the solution to pollution has demonstrably been shown to be false, [...] [t]he very chemistry of dilution is undercut by the biology of the ocean.”

“I think it is important to evaluate the long-term environmental impact of these radionuclides,”

“We have confirmed that the tritium concentrations in the bodies of marine organisms reach equilibrium after a certain period of time and do not exceed the concentrations in the living environment,” [...] The tritium concentrations then decrease over time once the organism is returned to untreated seawater.

The IAEA [...] is expected to release a final report on the site and the plan for the wastewater release later in June.

 

For a defendant with no prior criminal convictions, an offense level of 37 yields 210 to 262 months (17 1/2 to almost 22 years). A defendant who accepted responsibility could reduce that range to 151 to 188 months if the prosecution agreed to deduct the third point.

 

KNOWER is currently one of my favorite bands. Anyone else dig their vibe?

5
LoadingReadyRun (lemmy.nrd.li)
submitted 1 year ago* (last edited 1 year ago) by terribleplan@lemmy.nrd.li to c/communitypromo@lemmy.ca
 

Starting up a fan community here on Lemmy for my favorite internet comedy troupe. Currently mostly just linking to new videos of theirs I particularly enjoy.

!loadingreadyrun@lemmy.nrd.li

view more: next ›