Notices by Hannes (hannes2peer@quitter.se), page 16
-
Hannes (hannes2peer@quitter.se)'s status on Wednesday, 07-Sep-2016 23:35:03 UTC Hannes @gargron what's wrong with the avatar shown here on quitter.se? -
Hannes (hannes2peer@quitter.se)'s status on Wednesday, 07-Sep-2016 16:44:13 UTC Hannes other !qvitter changes you can try/debug on quitter.se:
• disable keyboard shortcuts
• bookmarks from bookmarks plugin display better -
Hannes (hannes2peer@quitter.se)'s status on Wednesday, 07-Sep-2016 16:23:03 UTC Hannes !qvitter upload buttons should work in chrome 53+ now -
En kompis kompis (ekk@quitter.se)'s status on Wednesday, 07-Sep-2016 16:21:34 UTC En kompis kompis We're back! Sorry about the downtime. Hopefully all our commons work again, tell us if you see something strange. -
Hannes (hannes2peer@quitter.se)'s status on Tuesday, 06-Sep-2016 20:45:51 UTC Hannes @arvidos snyggt! självklart ok :) -
Basspistol Uncorporated (basspistol@quitter.se)'s status on Tuesday, 06-Sep-2016 08:07:18 UTC Basspistol Uncorporated "It would be so nice, if you could compute. Your freedom is not to dilute." !listening @sakrecoer https://archive.org/details/BPIST-V007 -
Hannes (hannes2peer@quitter.se)'s status on Sunday, 04-Sep-2016 16:16:39 UTC Hannes @translateuser merged and updated on quitter.se. thank you! and sorry about the delay. -
Hannes (hannes2peer@quitter.se)'s status on Saturday, 03-Sep-2016 09:46:47 UTC Hannes @inscius i thought it was a palindrome first, but it doesn't work: zibg ib sia kiz -
Hannes (hannes2peer@quitter.se)'s status on Thursday, 01-Sep-2016 22:28:08 UTC Hannes @zash if it's generated by gnusocial i would consider it safe enough https://git.gnu.io/gnu/gnu-social/blob/master/lib/apiaction.php#L344 -
Hannes (hannes2peer@quitter.se)'s status on Thursday, 01-Sep-2016 22:26:58 UTC Hannes @mmn Notice_source is only for known sources. unknown sources are served directly from the notice table -
Hannes (hannes2peer@quitter.se)'s status on Thursday, 01-Sep-2016 21:14:51 UTC Hannes @maiyannah ok. but the source field is not federated. -
Hannes (hannes2peer@quitter.se)'s status on Thursday, 01-Sep-2016 21:14:13 UTC Hannes @maiyannah @mmn e.g. i could do <script>alert("hello")</script> but not <script>console.log("hello")</script> -
Hannes (hannes2peer@quitter.se)'s status on Thursday, 01-Sep-2016 21:12:53 UTC Hannes @maiyannah @mmn although, it would be interesting to see if anyone could come up with a dangerous script with only 32 chars -
Hannes (hannes2peer@quitter.se)'s status on Thursday, 01-Sep-2016 21:02:35 UTC Hannes @maiyannah yes htmlpurifier should be enough, i guess? -
Hannes (hannes2peer@quitter.se)'s status on Thursday, 01-Sep-2016 21:00:39 UTC Hannes !qvitter admins should update https://git.gnu.io/h2p/Qvitter/commit/632d5f113627df4c158be973aefc1afc018764f4 -
Hannes (hannes2peer@quitter.se)'s status on Thursday, 01-Sep-2016 20:58:56 UTC Hannes @maiyannah this is what i did to !qvitter https://git.gnu.io/h2p/Qvitter/commit/632d5f113627df4c158be973aefc1afc018764f4 -
Hannes (hannes2peer@quitter.se)'s status on Thursday, 01-Sep-2016 20:44:05 UTC Hannes @maiyannah and now we'll have to assume it might have not, even if it's fixed in newer gnusocial -
Hannes (hannes2peer@quitter.se)'s status on Thursday, 01-Sep-2016 20:43:29 UTC Hannes @maiyannah apparently not -
Hannes (hannes2peer@quitter.se)'s status on Thursday, 01-Sep-2016 20:35:25 UTC Hannes @maiyannah the user (client) can send a any "source" when posting to api. imo it should be treated/sanitised by gs just like the notice text -
Hannes (hannes2peer@quitter.se)'s status on Thursday, 01-Sep-2016 20:31:41 UTC Hannes @maiyannah yes