github: shadowy octopus with the head of a robot, emblazoned with the Dreamwidth swirl (Default)
[personal profile] github

Keep accounts in the switcher across logout and account creation (#3683)

  • Keep accounts in the switcher across logout and account creation

Logging out of the active account now leaves it listed in the account switcher as signed out, instead of dropping it, while still handing off to the next usable account. A logout that leaves nothing to switch to keeps the list unless it only ever held that one account.

/logout gains "Log Out of All Accounts", which ends every session in the browser and either keeps the accounts listed (signed out) or, if asked, forgets them. Creating an account while logged in now demotes the current account into the switcher rather than silently replacing it, and /manage/accounts links to account creation and logout.

Co-Authored-By: Claude Opus 5.5 (1M context) noreply@anthropic.com

  • Abort logout when a session can't be revoked

Logging out now destroys stored sessions by their handle rather than only when they validate from the current request, so an IP-bound session from another network is revoked too. If a session can't be destroyed, logout stops before handing off or rewriting cookies, and the page reports the failure. The log-out-all option only appears when another account is actually signed in.

Co-Authored-By: Claude Opus 5.5 (1M context) noreply@anthropic.com

github: shadowy octopus with the head of a robot, emblazoned with the Dreamwidth swirl (Default)
[personal profile] github

Bump sass in /etc/build-tools in the build-tools group (#3680)

Bumps the build-tools group in /etc/build-tools with 1 update: sass.

Updates sass from 1.105.0 to 1.105.1 - Release notes - Changelog - Commits

github: shadowy octopus with the head of a robot, emblazoned with the Dreamwidth swirl (Default)
[personal profile] github

Stop correct_anum from trusting a lazily-filled ditemid (#3682)

correct_anum chose the untrusted anum whenever $self->{ditemid} was set, but ditemid() fills {ditemid} lazily on any entry. When a slug- or jitemid-loaded entry's singleton had ditemid() called on it, as the active-entries module does to emit a permalink for an entry in its own list, the shared singleton gained a {ditemid} with no {untrustedanum}; the next correct_anum then read the undef untrustedanum and reported a wrong anum. Slug permalinks for entries in a journal's active-entries list answered 404 for everyone, while numeric permalinks for the same entries did not.

Branch on untrustedanum, which the constructor sets only when it took a ditemid, so a lazily-filled {ditemid} no longer changes the answer.

Co-authored-by: Claude Opus 4.8 noreply@anthropic.com

Commit: e5c89803 Author: Mark Smith

github: shadowy octopus with the head of a robot, emblazoned with the Dreamwidth swirl (Default)
[personal profile] github

Pin CSS/JS build tools and track upgrades with Dependabot (#3679)

Commit: 57c83083 Author: Mark Smith

github: shadowy octopus with the head of a robot, emblazoned with the Dreamwidth swirl (Default)
[personal profile] github

Make active_entries compatible with MySQL 8 ONLY_FULL_GROUP_BY (#3678)

MySQL 8 rejects SELECT DISTINCT ... ORDER BY on a non-selected column (error 3065) under its default ONLY_FULL_GROUP_BY mode. Drop the SQL DISTINCT and instead scan a bounded window of the newest comments on the primary-key index, then take the first 10 distinct nodeids in Perl. Memcache behaviour and the returned itemids are unchanged.

Co-authored-by: Claude Opus 5.5 noreply@anthropic.com

Commit: 5ea420e3 Author: Mark Smith

github: shadowy octopus with the head of a robot, emblazoned with the Dreamwidth swirl (Default)
[personal profile] github

Return a login requirement for logged-out quick-reply comments (#3676)

The /_rpcaddcomment endpoint dereferenced the remote user unconditionally when building the protocol request, so a logged-out POST with a valid form auth token died with a 500 instead of a normal error. Guard for a missing remote up front and return the login requirement, matching the other handlers in this file.

Co-authored-by: Claude Opus 4.8 noreply@anthropic.com

Commit: d90b2464 Author: Mark Smith

github: shadowy octopus with the head of a robot, emblazoned with the Dreamwidth swirl (Default)
[personal profile] github

Fix login panel and restore community join link on the not-found page (#3677)

The shared 404 page for hidden or missing entries (error/unavailable.tt) included login.tt for everyone, so logged-in viewers got the "you're logged in / change login options" panel instead of nothing. Show the login form only to logged-out viewers.

Restore the community join prompt the old protected page had: when the journal is a community the viewer could join, offer a /circle//edit link. The decision uses only the journal and the viewer, never the entry, so a hidden entry and a missing one in the same community still render byte-identical bodies. The protected handler reads the journal from the request note both entry paths already set.

Co-authored-by: Claude Opus 4.8 noreply@anthropic.com

Commit: bef46050 Author: Mark Smith

github: shadowy octopus with the head of a robot, emblazoned with the Dreamwidth swirl (Default)
[personal profile] github

Answer slugs under the wrong date the same as missing slugs (#3675)

A slug requested under the wrong date got the stock 404 page when the slug existed, even for a private entry, while a missing slug got the unavailable page. The different page revealed that the slug exists.

determine_view now drops the entry for a date mismatch, so the request falls through to the same not-found answer as a missing slug.

Co-authored-by: Claude Opus 5.5 noreply@anthropic.com

Commit: 487a2ad7 Author: Mark Smith

github: shadowy octopus with the head of a robot, emblazoned with the Dreamwidth swirl (Default)
[personal profile] github

Clean up comment posting preview and add tests

Simplify how the talkpost_do preview path and the unscreen-parent option are built, and add regression tests for comment posting previews.

Co-Authored-By: Claude Opus 4.8 noreply@anthropic.com EOF

Commit: 9df16a61 Author: Mark Smith

github: shadowy octopus with the head of a robot, emblazoned with the Dreamwidth swirl (Default)
[personal profile] github

Answer hidden entries and comments the same as missing ones (#3674)

  • Answer hidden entries with the same 404 as missing ones

Entry URLs let anyone probe for hidden entries. A private entry's slug URL got a 403 "protected" page while a missing slug got 404, and in an adult-flagged journal the interstitial answered for wrong-anum and missing slug URLs but not for hidden entries.

DW::Controller::Journal now decides before the adult interstitial and make_journal: a missing entry, wrong anum, or entry the viewer can't see gets one 404 page (error/unavailable.tt, shared with the JS journal server) that depends only on the viewer. Public suspended entries keep their suspension notice, since their existence is already public.

correct_anum loads the row before reading anum, so slug lookups no longer report a wrong anum.

Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com

  • Answer hidden comments the same as missing ones

A comment id in a request could tell a comment the viewer can't see (screened, deleted, by a suspended user, on another entry, or with the wrong anum) from one that doesn't exist. ?thread= rendered a hidden comment's placeholder instead of falling back to the whole entry, and ?view= could pick its page. ?replyto= answered 403 for screened comments and suspended posters but 404 for missing ones, ?edit= and talkpost_do edits said "not yours" instead of "invalid", and replies through talkpost_do were accepted for hidden parents. /go threadroot redirected for hidden comments, /talkscreen and /delcomment named deleted comments before checking permission, and /manage/tracking named deleted comments and hidden entries.

LJ::Entry->visible_comment is now the one test for all of these. The journal controller answers hidden replyto and edit ids with the same 404 as hidden entries, before the adult interstitial. load_comments ignores hidden thread and view ids as it does missing ones. Journal managers keep the detailed talkscreen and delcomment errors, since they can act on every comment in the journal.

Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com

github: shadowy octopus with the head of a robot, emblazoned with the Dreamwidth swirl (Default)
[personal profile] github

Update makertube embed filter (#3658)

  • Update embed whitelist

  • Update makertube.net embed filter

  • Merge issues

Commit: 3c051e81 Author: chebegeek

github: shadowy octopus with the head of a robot, emblazoned with the Dreamwidth swirl (Default)
[personal profile] github

Bump js-yaml from 4.2.0 to 4.3.2 in /api (#3664)

Bumps js-yaml from 4.2.0 to 4.3.2. - Changelog - Commits

github: shadowy octopus with the head of a robot, emblazoned with the Dreamwidth swirl (Default)
[personal profile] github

Support service configuration for small self-hosted sites (#3666)

Commit: b39a3822 Author: Mark Smith

github: shadowy octopus with the head of a robot, emblazoned with the Dreamwidth swirl (Default)
[personal profile] github

Move Node.js from 20 to 24 LTS (#3673)

Node 20 reached end of life in April 2026; 24 is the current Active LTS. Both the devcontainer and the production base22 image install it from NodeSource for sass and esbuild.

Co-authored-by: Claude Opus 5.5 noreply@anthropic.com

Commit: 303817ab Author: Mark Smith

github: shadowy octopus with the head of a robot, emblazoned with the Dreamwidth swirl (Default)
[personal profile] github

Fix API rate limiting on the Plack request object (#3672)

DW::API::RateLimit->wrap called $r->connection->remote_ip and $r->headers_out->{...}, which DW::Request::Plack does not provide, so every rate-limited REST endpoint died before running. Use the native get_remote_ip and header_out methods.

Co-authored-by: Claude Opus 5.5 noreply@anthropic.com

Commit: 802db096 Author: Mark Smith

github: shadowy octopus with the head of a robot, emblazoned with the Dreamwidth swirl (Default)
[personal profile] github

Complete opt-in TOTP login enforcement (#3667)

Enables 2FA enforcement for accounts that have enabled it. Also promotes it out of beta so it's available for everybody.

Commit: 9ddd4c2b Author: Mark Smith

github: shadowy octopus with the head of a robot, emblazoned with the Dreamwidth swirl (Default)
[personal profile] github

Make account switcher removal a link with confirmation (#3668)

Commit: e1c5bfd9 Author: Mark Smith

github: shadowy octopus with the head of a robot, emblazoned with the Dreamwidth swirl (Default)
[personal profile] github

Fix adult content regression from Plack migration (#3665)

  • Fix adult content regression from the Plack migration. Also fix a few other edge cases identified by GPT Astra around input validation and cut expansion.

Commit: d9ea4bea Author: Mark Smith

github: shadowy octopus with the head of a robot, emblazoned with the Dreamwidth swirl (Default)
[personal profile] github

Make project guidance harness-neutral

Commit: 892c1589 Author: Mark Smith

github: shadowy octopus with the head of a robot, emblazoned with the Dreamwidth swirl (Default)
[personal profile] github

Dump the FAQs and their edit history for archiving

FAQs live only in the database and are edited in place: Admin/FAQ.pm does UPDATE faq SET ... lastmodtime=NOW(), keeping only who last touched a FAQ and when, never the prior text.

The revision history does exist, though, in the translation tables. Every edit also calls LJ::Lang::set_text for .1question/.2answer/.3summary, and set_text appends a new ml_text row rather than updating one, so the faq domain holds every revision back to 2009 -- 5425 rows over 685 item/language pairs, one item with 87 of them. ml_latest marks which is live.

Dump the faq and faqcat tables plus that history, joined against ml_items / ml_langs with an is_current flag. Output is JSON Lines because answers are HTML containing newlines, and JSON is given utf8(0) against a :raw handle because DW never sets mysql_enable_utf8 -- DBI returns UTF-8 bytes, and encoding them again would double-encode every non-ASCII character.

Co-Authored-By: Claude Opus 5 noreply@anthropic.com

Commit: 9bcb3dea Author: Mark Smith

Profile

Dreamwidth Changelog

October 2026

S M T W T F S
     12 3
4 5 678910
11121314151617
18192021222324
25262728293031

Syndicate

RSS Atom

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags
Page generated Oct. 6th, 2026 10:56 pm
Powered by Dreamwidth Studios