!meta
@slrpnk.netYou can read the official release annoucements here.
This is mainly a security release, but it fixes some important flaws in the frontend code. Thus while there are not many changes from a user perspective, it is still a quite significant improvement š
Search isn't showing me anything for the obvious terms.
I'd like a climbing-specific sublemmy(?), ideally, but I appreciate that's a bit niche! Just somewhere for chatting about general fitness would be cool. I'd start one myself, but it doesn't seem very solar-punky.
As you might have heard several Lemmy instances have been attacked via a security vulnerability in the browser frontend related to custom emoji.
While SLRPNK was vulnerable to it, we seem to have not been actively targeted and I took the instance down as a precaution as soon as I learned about it.
I have applied all the currently known mitigations, which means that everyone got logged out of their account and needs to log back in manually.
As of writing this the API is working again and can be used with apps like Jerboa safely.
I am still contemplating if I want to re-enable the web frontend now or wait for a release that fixes the issues found.
Edit: the main issue was fixed and I restarted the web ui with it.
cross-posted from: https://sh.itjust.works/post/923025
lemmy.world is a victim of an XSS attack right now and the hacker simply injected a JavaScript redirection into the sidebar.
It appears the Lemmy backend does not escape HTML in the main sidebar. Not sure if this is also true for community sidebars.
I updated to Lemmy version 0.18.1 yesterday which seems to have resolved quite a few issues in the UI and also made the site overall quite a bit more responsive. Very nice team work of all the people involved in bug fixing and performance optimisation of Lemmy š„°
Edit: it might be necessary to force-reload your browser (Press CTRL+F5) to get the new Javascript files properly.
I also added the Hanubeki themes and enabled the mint
version as the default. This is not meant as the final theme here, but just a quick change to have something other than the somewhat boring Lemmy default. But maybe people like it anyway.
I also played around with the new custom emojis a bit and they seem to mostly work.
For exampe:
So I guess we could start collecting some nice ones to be added for everyone to use.
Last but not least I pre-emtively blocked threads.net (the new Facebook service) as discussed here.
I just saw that lemmy.ml has pre-emptively defederated from threads. Are there any plans to do that here? I personally want nothing to do with Meta/Facebook, and I'm sure that's not an unpopular opinion around here.
edit: y'all, please pay attention to where you are when coming from all.
edit again: kbin really ought to make a post's home instance more clear.
Is it possible to use this instance in a dark mode when browsing from desktop?
I've been having issues today with the front page not loading content. Refreshing works sometimes, but not always. I've also had some posts show a loading icon indefinitely. When I leave and come back, they usually load. I'm not sure why, but I figure sharing this will help with troubleshooting.
Is there any bug submission process I should follow aside from posting in !meta?
https://slrpnk.net/c/15minutecity
Discussion about the path towards 15 minute cities. Post examples and discuss about how to make this a reality! Checkout these other communities with similar themes: - !urbanism@slrpnk.net [/c/urbanism@slrpnk.net] [https://slrpnk.net/c/urbanism]
when Iām logged in, a lot of communities are empty - but i can see loads of posts when logged out. does anyone know what the issue is?