Elektrine lite

← Feed

Todd Sundsted

toddsundsted@epiktistes.com

Better dead than bored.

Posts

  • Release v3.8.0 of Ktistec

    There are two significant new additions in release v3.8.0 of ktistec. First, the actor cards on the followed/following pages show relevant actor status. On the followed page, it tells you how long it has been since that actor published an activity (create, announce, like, etc.) that was sent to your server. It's a proxy for how active they are (or are not). On the following page, it tells you how long it has been since you have been able to send to that server. It's a proxy for whether...

  • Release v3.4.1 of Ktistec

    This release fixes a small number of bugs found in recent releases. The full changelog: Fixed Prevent runaway recursion when handling filtered posts.Ensure profile header and header_static images are always present.Render the inline replies collection for local objects.Exclude blocked actors from object statistics and notifications. Changed Return 410 Gone instead of 404 Not Found for missing actors. Removed Tag counts on public pages. This release fixes a hard-to-exploit but potentially serve...

  • Release v3.3.9 of Ktistec

    Release v3.3.9 of Ktistec continues the security hardening work from recent releases, with further progress on the Mastodon-compatible API. Of note: all network connections now go through a new Ktistec::Network module. This allows Ktistec to limit the size of HTTP bodies it reads, on both inbound and outbound requests, and ensures it only opens connections to valid remote IP addresses. Here's the full changelog: Added New Mastodon-compatible APIs. Fixed Close DNS rebinding window for outb...

  • Post #2715973

    @reiver@mastodon.social i don't mind type but the leading hash always feels redundant

  • Post #2642737

    @mariusor@metalhead.club @silverpill@mitra.social a good question! one and the same thing for me. i'm just tired of having to go "somewhere else" to interact with events. fwiw, my personal bar is pretty low, but i increasingly think this is a major missing piece.

  • Post #2618112

    how widely adopted/supported/implemented is FEP-8a8e? is that a safe direction to converge for federated events?

  • Release v3.3.8 of Ktistec

    This release continues my focus on security instead of new features. As I wrote earlier this week, I rebuilt the template framework Ktistec uses with type safety as a central principle. What does that mean? Imagine that you have an instance of a String that holds federated data. Where can you safely render that in a browser, and what operations (sanitization, escaping, etc.) do you need to do first? The only way to answer that is to look carefully at the lineage of that data: where it came fro...

  • Post #1701333

    I’m working on handling OAuth token expiry as part of #ktistec Mastodon API support. Is my understanding that Mastodon issues OAuth tokens with no expiration correct?!?

  • Post #731592

    a glance is worth a thousand words #DogsOfMastodon #Saki