Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

julian

@julian@community.nodebb.org
nodebb 4.16.0
  • Open on community.nodebb.org

Co-Founder (NodeBB) | Husband 🤷‍♂️ and Dad 🙉 to three | Rock Climber 🧗‍♂️ | Foodie 🥙 | Conductor 🎵 | Saxophonist 🎷

✅ Small teams craft better code.
🇨🇦 Made in Canada
🗨️ Federating NodeBB with funding from NLNet ♥️🇪🇺

1119 Followers
454 Following
22 Posts
Joined June 17, 2013
Website:
https://nodebb.org
Location:
Toronto, Ontario
Preferred Editor:
Visual Studio Code
Open post
julian @julian@community.nodebb.org
· 22mo ago
Replying to
@hongminhee@fosstodon.org not many, and you're likely aware of the reason why: Mastodon strips almost all html out of non-notes, and delivers a sub-par reading experience for any implementor that doesn't send as:Note I detailed it all here: https://community.nodebb.org/post/101006 This is an area the ForumWG is actively working on, so it is my hope that we'll have something positive to report on that front sometime in 2025 😅
community.nodebb.org
1
1
2
0
Open post
julian @julian@community.nodebb.org
· 29mo ago
Replying to
@polotek@social.polotek.net for what it's worth I'm pretty bad at estimating. It drives @jay-moonah up the wall
0
0
0
0
Open post
julian @julian@community.nodebb.org
· 7mo ago

It is possible for NodeBBs to talk with each other. In fact, not only can two NodeBB forums see and share conversations, you can also connect with other websites that can federate.

This article is part of the NodeBB Answers category, where you can learn more about setting up, maintaining, and using your NodeBB forum. [...]


How does it work?

Under the hood, NodeBB uses a protocol called ActivityPub to exchange messages and activities between different websites and apps. Each user, category, topic, and post is able to be retrieved via this protocol, and users can follow each other in order to start seeing updates from another website.

How do I find other users and categories?

You can search for them in the search bar and search pages. Users and categories are identified by their username or handle, which looks something like @handle@website.com.

For example, I (@julian) can be found by searching for @julian@community.nodebb.org, and this category (@answers) can be found by searching for @answers@community.nodebb.org.

From there, you can follow users (or watch/track categories) to start the flow of new content to you. It's like subscribing to a newsletter. You'll start getting the new stuff, but you won't be able to see the old stuff unless you already know about it.

Okay, I started following some people, where do I see their posts?

Content from outside of the forum is all found inside the "World" page, accessible via /world. As new content comes in, it'll be shown in the feed-style timeline. Any remote categories you've started following will also show up in the sidebar for easy access.

How do I post to remote categories?

Once you've found some categories from outside of the forum (aka "remote categories"), you can browse back to them from the /world page. If you've watched/tracked the category, you can access them from the sidebar. Otherwise you'll have to search for them from the remote category search bar within this page.

Once you're in a remote category, you can start a new topic via the "New Topic" button just like a regular category on your forum, and your topic will be sent to the remote category for syndication.

Remember to follow the rules of other communities, as they may not match rules on your forum.

Answers
NodeBB Community

Answers

A community to talk about development and ask questions about NodeBB modern forum software

0
0
0
0
Open post
julian @julian@community.nodebb.org
· 7mo ago

Up until today, when you queried a NodeBB user or category's outbox, you would receive an empty OrderedCollection. This was done because the property's inclusion in the actor object was required, but it was not immediately apparent in 2024 how many people utilised this property. Thus it was easier to just send the empty outbox and pursue more urgent functionality.

While sending that empty outbox has not broken any implementations, but it has come to my attention that a few (read: more than 1) other implementors already do, or plans to, read from an actor outbox for backfill purposes.

The upcoming NodeBB v4.10.0 will contain an outbox populated by the contributions by that user or category.

Here's how that works...[...]

For both users and categories, a standard OrderedCollection is returned, with first, last, prev, and next properties for navigation.

For users:

  • A combined set of the user's activity is returned in the form of activities (Create, Like, etc.) — these activities include the user's posts, votes (both up and down), and shares.
  • Unlike other collections, this one uses a cursor. You can pass ?before= or ?after= values in the query string to retrieve items 20 at a time.

For categories:

  • A set of posts curated by this category is shown. It can contain both posts local to the instance, and remote posts from outside of the instance.
  • All posts are wrapped in the Announce activity. If the post is local, it is an Announce(Create(Note/Article)), if it is a remote post, then it is just an Announce(Object) by reference.
  • This collection is paged like other collections served by NodeBB.

It is possible that this implementation serves data in an unexpected manner. If this is the case, please reply here to contact me directly so it can be fixed.

I used my best judgement for what to include in the outboxes, as well as using Piefed as a reference implementation. @rimu@piefed.social, I notice that Piefed's community outboxes serve up Announce(Create(Page)) even if the Page is not local to the instance. I was under the assumption that remote content couldn't (shouldn't?) be expanded in this manner because you cannot guarantee the integrity of the data, and so announcing the object by reference is preferred. Just wondering your thoughts on that.

0
3
0
0
Open post
julian @julian@community.nodebb.org
· 7mo ago

We are publishing a notice today to bring to attention an unintentional breaking change that could affect some users of NodeBB.

v4.5.0 contained an update to src/request.js that calls a DNS resolver to ensure that the destination address is not a reserved IP address (e.g. 192.168..., 127.0..)

This change was introduced in order to close off any potential for Server-Side Request Forgery for any calls made within the NodeBB codebase. [...]

In the vast majority of installations, this has no unintended effects. In some installations, custom plugins or themes may call URLs that resolve to an internal address on purpose (e.g. to query an internal database or similar.) In those situations, the call will now fail as of v4.5.0.

In those situations, you will need to update the plugin to add the domain to the allow list by calling the filter:request.init hook:

plugin.json

{
  ...
  "hooks": [
    ...
    { "hook": "filter:request.init", "method": "allowInternalHostname" },
    ...
  ]
  ...
}

library.js or similar

const plugin = module.exports;

plugin.allowInternalHostname = async ({ allowed }) => {
  allowed.add('example.org');
  return { allowed };
});
owasp.org
0
0
0
0
Open post
julian @julian@community.nodebb.org
· 6mo ago

Hi everybody,

With spring around the corner (it is currently a balmy 5°C here right now), it's time to get crackin' on a new release of NodeBB!

We focused on a lot of user experience updates this time around, along with tweaking the new /world page that was introduced in v4.9.0. In the backend, lots of optimizations were implemented, which make federation processing (and day-to-day maintenance) faster.

Here's what you can expect from v4.10.0...[...]

:globe_with_meridians: Updates to the /world page

The /world page got a makeover in v4.9.0, showcasing a more timeline-based feel. It more accurately represents the breadth of content available on the open social web, such as microblogging, in addition to long-form text (blogs), media-focused items, and everything in between.

We focused on UX updates to this page:

  • New sorts are available: You can now view just local content, as well as all known content.
  • The default sort continues to be "your followers", but also includes local content now as well, because you are also tracking those categories!
  • Guests were barred from /world in v4.9.0, but this is now opened up again. Their view of the /world page shows only local posts.
  • The /world page can now be set as a default home page.
  • Duplicate items were showing up when scrolling down /world (especially on very active timelines)
  • Uploaded images were showing up in the thumbnail/card headers, even if they were embedded in the post itself. The header is now restricted to topic thumbnails (and post attachments, which only occur with remote posts)
  • Posts are now height-restricted, so long posts don't take up an inordinate amount of space. A "show more" button is available to expand posts in-timeline.
  • The "quick create" editor at the top of this page now also lets you choose a category to post to. Administrators can update the default value as desired. It defaults to World/Uncategorized.
:speech_balloon: Alt Text now federating outward

Alt text was always supported in NodeBB, but this was not federated outward to remote instances. This is now supported for uploaded images and externally-linked images. Topic thumbnails do not support alt text at this time.

:arrow_upper_left: Soft redirects of remote content

Users unfamiliar with NodeBB were often surprised to see their content cached by NodeBB, despite this being how federation works. In order to reduce surprise, any guest navigating directly to a remote post or remote user will be soft-redirected out to the original source. This goes hand-in-hand with the topic-restriction feature in v4.9.0.

:computer: ActivityPub Outboxes published

For ActivityPub developers, we now publish outboxes as of this version.

:frame_with_picture: More profile pics!

@baris improved the avatar handling code so that NodeBB now remembers your last three used avatars, allowing you to toggle between them. You will no longer need to upload new pictures if you want to switch between previously-used avatars!

Follow counts better synchronized

@panos@catodon.rocks reported awhile back that follow counts in user pages were off. The logic was updated and should be back in sync with the real values once you follow/unfollow a user.

ActivityPub user and category outboxes coming soon
NodeBB Community

ActivityPub user and category outboxes coming soon

Up until today, when you queried a NodeBB user or category's outbox, you would receive an empty OrderedCollection. This was done because the property's inclu...

0
2
0
0
Open post
julian @julian@community.nodebb.org
· 7mo ago
Replying to
Really? I can wrap a remote object in a Create of my own? I suppose nothing is stopping me but I figured it was disingenuous.
0
0
0
0
Open post
julian @julian@community.nodebb.org
· 6mo ago

Stoked to see BSD Cafe has a new site... Running NodeBB :sunglasses:

https://billboard.bsd.cafe/

Considering they don't run just anything, we're in good company! Their other instances run Mastodon (of course) and snac2, arguably one of the most lightweight ActivityPub services.[...]

Designed as a hybrid space, it functions as a classic discussion forum with persistent threads while also supporting ActivityPub federation, enabling cross-platform interactions without algorithmic curation. The project is built on NodeBB and aims to serve as a social hub for BSD and open-source communities, allowing users to engage in long-form discussions while participating in the broader decentralized social web.

— https://discoverbsd.com/p/f46dd3f825

BSD Cafe Billboard
BSD Cafe Billboard

BSD Cafe Billboard

0
5
0
0
Open post
julian @julian@community.nodebb.org
· 5mo ago

Since 2017, we've maintained a bug bounty program that awarded responsible disclosure of security vulnerabilities on a sliding scale of $64 to $512 based on severity.

Throughout the years we've made some unpublished changes to this bounty program, mostly related to the format (no videos, text only, allowed testing endpoints) and in some cases expanding the scope of covered plugins (e.g. 2factor, web-push).

With the rise of LLMs and the corresponding drop in ability needed to analyze and send in reports, we have been receiving a large increase in reports whose submitters have no ability to defend or support their claims, but are happy to pretend that they do. [...]

To be fair, this has been the case ever since the beginning. We've awarded our fair share of bounties to parties running static analysis scripts that output a ton of technical jargon that say very little. The difference today is the scale of these reports is whittling away what little patience I have left.

The easiest thing to do is to cancel the program outright. This would be unfair to the legitimate submitters of security vulnerabilities, and open us up to exploits that we simply would not learn about prior to exploitation. None of that sounds like the direction we want to go. I've gone on the record saying that the one thing OSS devs should set up (if they're able) is a bug bounty program, and I still stand by that claim.

Our bug bounty program remains, with one important change. AI-generated vulnerability reports will be rejected outright out of principle. If you did not do the work, you do not get to take credit for it. The social contract built into this program is, and has always been, a 1:1 exchange of humans talking to humans. Analyzing NodeBB's codebase using Claude (to use an example) and finding vulnerabilities means I should be paying Anthropic the bounty, not the person prompting Claude. If you spent 10 seconds prompting an LLM and I have to spend 20 minutes verifying that your report is not real, the only person's time wasted is my own.

Some use LLMs as a translation tool, and if this is the case, we will make a good-faith effort to take a look, although we are happy to accept reports in your native language.

Some others use LLMs to structure their reports more professionally. Please just speak to us with your own voice. It is vastly preferable.

nodebb.org

Bug Bounty - NodeBB - Modern Forum Software

NodeBB Forum Software - The Modern Discussion Platform

0
4
0
0
Open post
julian @julian@community.nodebb.org
· 27mo ago
Replying to
@netzpolitik_feed@chaos.social AI needs to die a quick death so F/LOSS devs can continue making good software.
0
0
0
0
Open post
julian @julian@community.nodebb.org
· 5mo ago

Hi everybody — late last week we released v4.11.0, which contains the following changes:

ActivityPub Specific Fixes :rotating_light: AP analytics and error pages

New pages have been added to the control panel to display analytics (send/receive counts) and error counts. There is also a new error page that will show error received within the last 24 hours, and their respective payloads. This will aid in debugging federation issues.

:writing_hand: Article vs. Note distinction updated

Prior to this version, NodeBB would determine whether a federated object was an Article or Note based on content length. This was confusing for end users, and was originally added before NodeBB supported title-less topics.

The revised distinction is much simpler. If it has a title, it's an Article. If it doesn't, it's a Note.

Smaller fixes
  • Threadiverse software publishes Delete objects wrapped in an Announce activity. This is how content is moderated across the threadiverse. NodeBB now supports this, although it has not been extensively tested at this time.
  • There was an interoperability issue with Mitra that was identified and fixed.
  • When group actors post content directly, the category info is shown in the user icon. It used to error out and show "Guest".
  • Optimized the outbound federation of content so the front-end is more responsive. A bunch of back-end optimizations to reduce the number of calculations needed.
  • Emojis now supported in DMs to remote users.
:no_bell: Ability to hide read notifications in user panel

A new option has been added to the "Notifications" sub-section of the user control panel.

d3f24e12-9426-459d-ad98-194057d76483-image.jpeg

This option will allow you to visibly hide read notifications from the notifications dropdown, which reduces visual clutter.

Tinycon customizations

Admins can now customize the notification badge shown in the browser tab icon. We use the Tinycon library for this, and the colour values can be customized now:

55e5cf07-5c70-4b01-97df-add1a3f57148-image.jpeg

community.nodebb.org
0
0
0
0
Open post
julian @julian@community.nodebb.org
· 4mo ago
Boosted by @fedicat@pc.cafe
<p>A new feature silently dropped in v4.12.0. NodeBB now supports Activity Intents!</p> <h3>Huh? What's an Activity Intent?</h3> <p>It is <a href="https://w3id.org/fep/3b86" rel="nofollow ugc">a proposal</a> by <a href="https://mastodon.social/@benpate">@<bdi>benpate@mastodon.social</bdi></a> that aims to "extend the capabilities of an ActivityPub server beyond a user's outbox, and enable direct interactions with content on the wider social web."</p> <p>In other words, it allows you to more seamlessly use your fediverse account on other sites without having to register a new account just to contribute.</p> <p>In even simpler words, it means you can go to other forums and interact with content without needing to register a new account.</p> <p>It directly tackles one of the fediverse "hard problems" I talked about last year — <strong>account fragmentation</strong>. You won't need additional accounts just to use other sites, your identity stays whole :sunglasses:</p> <p>Let's learn more about how that works![...]</p>
A new feature silently dropped in v4.12.0. NodeBB now supports Activity Intents! Huh? What's an Activity Intent? It is a proposal by @benpate@mastodon.social that aims to "extend the capabilities of an ActivityPub server beyond a user's outbox, and enable direct interactions with content on the wider social web." In other words, it allows you to more seamlessly use your fediverse account on other sites without having to register a new account just to contribute. In even simpler words, it means you can go to other forums and interact with content without needing to register a new account. It directly tackles one of the fediverse "hard problems" I talked about last year — account fragmentation. You won't need additional accounts just to use other sites, your identity stays whole :sunglasses: Let's learn more about how that works![...] Account Fragmentation in a Nutshell Right now, when you browse to a different site, you usually have to create a new account to interact with it. For example, if you check out someone's Pixelfed profile, you're not able to comment or like their pictures without an account there. This has always been how the internet worked, and before the advent of single sign-on, which lets you log in with a different account (but still creates a new account on that site), that was just how it was. Essentially, there was no way to interact with content using your main identity. The workarounds were numerous... copying URLs, searching for the account on your instance, etc. All of which were fairly friction-heavy, so the next best thing was just to create a local account and fragment your identity. Activity Intents intends (ha!) to address this by allowing servers to advertise support for different types of social actions. How It Works You browse to another site and want to carry out an action, such as liking the post, or writing a reply. That site asks you to enter an Open Social Web handle (or log in, if you have a local account), and you enter it. It then queries your server to see what Intents it supports (e.g. "Like", "Create") If there's a match, it sends you back to your server, where you can complete the action. That's about it! There are additional details about designing the actual flow, and how to "remember" each visitor's social web handle, but the basics are as listed above. What it looks like in NodeBB We've integrated support for four intents: Like/Dislike → These map to upvote and downvote respectively Create → These would be topic creations and replies Follow → self-explanatory Object → Load an ActivityPub resource in NodeBB We integrated two-way support which means that if you land on a NodeBB and your fediverse account supports Activity Intents, then you can simply hit like, reply, or follow from NodeBB, and be sent back to your home server, all without the hassle of copying and pasting links into a search bar. Integrating Activity Intents was a high-impact way to tackle the problem of account fragmentation. Users of NodeBB (whose forums have updated to v4.12.0) should not have to feel pressure to create local accounts elsewhere if the site they end up on supports Activity Intents as well.
0
8
1
0
Open post
julian @julian@community.nodebb.org
· 2mo ago

With temperatures reaching well into the 30s (in celsius of course :sunglasses:) in the Toronto area, we're all firmly in summer mode :swimmer: :beach_with_umbrella: , but that won't stop us from forging on ahead with new features and fixes for NodeBB!

There are improvements across ActivityPub federation, administrative tooling, and security hardening. Our ActivityPub integration receives bug fixes including duplicate handling, configurable rate limiting, and better error reporting, alongside new hooks for remote user lifecycle events. The registration queue and invitations are reorganized into a dedicated UI with a new "Reject All" bulk action and improved notification handling. Security reports have been coming in consistently throughout the month with valid security reports (though almost all AI discovered and generated). This led to stricter privilege checks on post diffs, crossposts, and GDPR exports, plus protection against username enumeration. The NodeBB team strongly encourages upgrading to v4.14.0 for the latest security fixes and federation improvements. The release also includes a new tx() translation helper, Benchpress escaping improvements, and a first-run categories onboarding modal for fresh installations.

Here are the high level changes you can expect to see when you upgrade from v4.13.0 to v4.14.0... [...]

:globe_with_meridians: Federation Regression Fixes!

Around v4.12.0 or so, a number of regressions were unintentionally introduced as part of security fixes that severely hampered federation — especially with Lemmy-based instances and relays. We've resolved those regressions and Relay/Lemmy federation should resume within 24 hours after upgrading.

The public key fetch rate limiter logic was simplified and updated (due to it being faulty and not really working in the first place), streamlined some duplicate logic with Like/Dislike activities, improved the AP Errors reporting page in the ACP, added a parent traversal depth guard, fixed an issue where updates to scheduled topics were accidentally being federated out, and about a hundred other smaller bugs :slightly_smiling_face:

:ballot_box_with_check: Registration Queue updates

The registration queue was moved out of the ACP, and invitations are also managed in this page now. A "reject all" button was added to allow admins to quickly reject every queued registrant in one fell swoop.

🔒 Privilege & Security Fixes
  • Post diff access — Check topics:read privilege when loading post diffs
  • Crossposts — Added source category privilege check to crossposts
  • GDPR export — Prevented global moderators from performing GDPR data exports
  • Nids ownership — Don't mark nids as read/unread that you don't own
  • Upload privileges — Prevent uploading thumbnails without upload:image privilege; replaced extension-based MIME validation with content
    sniffing
  • Username enumeration — Use dummy lockout key for non-existent users to prevent enumeration
  • Category disabled flag — Check category disabled flag on getRaw
:interrobang: Benchpress Improvements

We use Benchpress as our templating engine. We updated our integration for security and performance. @baris put together a thorough write-up for that one here.

Miscellaneous
  • First-run modal — New categories onboarding modal for fresh installations
  • Dashboard warnings — Added localhost and URL mismatch warnings to admin dashboard notices
  • Push notifications should work on Safari/iOS devices now (via the web-push plugin)
Upcoming Breaking Changes for 4.14.0
NodeBB Community

Upcoming Breaking Changes for 4.14.0

Hello Everyone, The upcoming 4.14.0 release will have breaking changes for themes and plugins that display html and translation tokens via template variables...

0
3
0
0
Open post
julian @julian@community.nodebb.org
· 1mo ago
Boosted by @fedicat@pc.cafe
<p>I realized we didn't put together any release notes for v4.15.0, so here they are :smile:</p> <p><em>For reference, v4.15.0 was released 12 August 2026.</em></p> <p>[...]</p>
NodeBB v4.15.0 — QoL and security updates, plus a few new features I realized we didn't put together any release notes for v4.15.0, so here they are :smile: For reference, v4.15.0 was released 12 August 2026. [...] :lock: Security Fixes We receive many reports for vulnerabilities via our bug bounty program, and we encourage people to poke around and find vulnerabilities to report. Note that as of today (1 September 2026), any reports compiled with the help of large language models are exempt from the bounty payment. From v4.14.0 to v4.15.0 there were at least five security fixes shipped — we encourage all admins to update to the latest stable version at all times. Instant voting Voting on posts used to wait for the round-trip to complete. On high-volume instances this caused a bit of a delay between a vote and its response, so the front-end now just reflects the new vote without waiting for a confirmation from the backend. Upload UI redesigned @baris says "feat: update uploads to look nicer:tm:" so purportedly, it looks nicer. Check it out :sunglasses: ActivityPub updates Chat privileges are now exposed for fediverse users. Existing sites should automatically grant this privilege to the fediverse user. If you want to restrict chat messages from remote users, disable this setting. A couple of server-side improvements to the ActivityPub note/reply handlers so fewer database calls are made. Queued topics now automatically pull for replies when accepted, without waiting for someone to enter the topic itself. Added a configurable age cutoff for auto-categorization filters. Activity Intents are now properly gated behind the global "activitypub enabled" switch.
0
0
1
0
Open post
julian @julian@community.nodebb.org
· 5mo ago
Replying to
@evan@cosocial.ca quite possibly yes 🙂 Perhaps the concept of a bug bounty program is antiquated. We shall see how that shakes out.
0
1
0
0
Open post
julian @julian@community.nodebb.org
· 26mo ago
Replying to
@shollyethan@fosstodon.org nice! Any chance we could get NodeBB on this list?
0
2
0
0
Open post
julian @julian@community.nodebb.org
· 2mo ago
Replying to
@dansup@mastodon.social yes! Kelowna is great. Didn't they evacuate it 🤔
0
1
0
0
Open post
julian @julian@community.nodebb.org
· 22mo ago
Replying to
@trwnh@mastodon.social :sob:
0
0
0
0
Open post
julian @julian@community.nodebb.org
· 2mo ago
Replying to
@silverpill@mitra.social are they new activities or resends? I want to know whether this is an issue that has been fixed (but stale queue items persist), or whether it's an unfixed issue.
0
1
0
0
Open post
julian @julian@community.nodebb.org
· 29mo ago
Replying to
@polotek@social.polotek.net story points make no fracking sense. They make sense within the context of a team so long as the team is roughly aligned with how much a point is "worth", arbitrarily. And then of course they loop in contractors and other teams that don't share the same point worthiness and suddenly are surprised when the estimates make no sense.
0
1
0
0
Open post
julian @julian@community.nodebb.org
· 14mo ago
Replying to
@SnowyCA@social.vivaldi.net respectfully if @dansup@mastodon.social replied to every half-baked drive-by unjustified criticism of himself or his work, he'd be there all day and not have time for anything else. Valid criticisms are different altogether of course.
0
2
0
0
Open post
julian @julian@community.nodebb.org
· 3mo ago
Replying to
@deadsuperhero@social.wedistribute.org that sucks! I hope something turns around for you 🫤 you'll be missed.
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 11:12:00 UTC