GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Kirby :koronesmile: :koronebonk: :koroneThink: :korone_smug: (kirby@mstdn.starnix.network)'s status on Friday, 26-May-2023 21:34:04 JST Kirby :koronesmile: :koronebonk: :koroneThink: :korone_smug: Kirby :koronesmile: :koronebonk: :koroneThink: :korone_smug:
    • meso

    @meso is the asbestos fine

    In conversation Friday, 26-May-2023 21:34:04 JST from mstdn.starnix.network permalink
    • Embed this notice
      meso (meso@asbestos.cafe)'s status on Friday, 26-May-2023 21:34:03 JST meso meso
      in reply to
      • meso
      @kirby If Allah chooses to protect us, we embrace that. If Allah chooses that we too must fall, we accept that.
      In conversation Friday, 26-May-2023 21:34:03 JST permalink
      Alex Gleason likes this.
    • Embed this notice
      meso (meso@asbestos.cafe)'s status on Friday, 26-May-2023 21:34:04 JST meso meso
      in reply to
      @kirby probably
      In conversation Friday, 26-May-2023 21:34:04 JST permalink
    • Embed this notice
      Kirby :koronesmile: :koronebonk: :koroneThink: :korone_smug: (kirby@mstdn.starnix.network)'s status on Friday, 26-May-2023 22:45:34 JST Kirby :koronesmile: :koronebonk: :koroneThink: :korone_smug: Kirby :koronesmile: :koronebonk: :koroneThink: :korone_smug:
      in reply to
      • paulo
      • meso

      @meso @paulo this apparently mitigates the problem too

      location ~ ^/(media|proxy) {
      add_header Content-Security-Policy "sandbox;";

      In conversation Friday, 26-May-2023 22:45:34 JST permalink
      Alex Gleason likes this.
    • Embed this notice
      meso (meso@asbestos.cafe)'s status on Friday, 26-May-2023 22:45:35 JST meso meso
      in reply to
      • paulo
      @kirby @paulo tried dunno how it didnt work
      In conversation Friday, 26-May-2023 22:45:35 JST permalink
    • Embed this notice
      meso (meso@asbestos.cafe)'s status on Friday, 26-May-2023 22:45:36 JST meso meso
      in reply to
      • paulo
      @paulo @kirby

      location /api/pleroma/admin { deny all; }
      location /api/v1/pleroma/admin { deny all; }
      In conversation Friday, 26-May-2023 22:45:36 JST permalink
    • Embed this notice
      Kirby :koronesmile: :koronebonk: :koroneThink: :korone_smug: (kirby@mstdn.starnix.network)'s status on Friday, 26-May-2023 22:45:36 JST Kirby :koronesmile: :koronebonk: :koroneThink: :korone_smug: Kirby :koronesmile: :koronebonk: :koroneThink: :korone_smug:
      in reply to
      • paulo
      • meso

      @meso @paulo this is just for denying access to adminfe you should deny all javascript files on media as well

      In conversation Friday, 26-May-2023 22:45:36 JST permalink
    • Embed this notice
      paulo (paulo@marsey.moe)'s status on Friday, 26-May-2023 22:45:38 JST paulo paulo
      in reply to
      • meso
      @meso @kirby what are the silly lines :marseyclueless:
      In conversation Friday, 26-May-2023 22:45:38 JST permalink
    • Embed this notice
      Kirby :koronesmile: :koronebonk: :koroneThink: :korone_smug: (kirby@mstdn.starnix.network)'s status on Friday, 26-May-2023 22:45:39 JST Kirby :koronesmile: :koronebonk: :koroneThink: :korone_smug: Kirby :koronesmile: :koronebonk: :koroneThink: :korone_smug:
      in reply to
      • meso

      @meso did you put the silly nginx lines in the config

      In conversation Friday, 26-May-2023 22:45:39 JST permalink
    • Embed this notice
      meso (meso@asbestos.cafe)'s status on Friday, 26-May-2023 22:45:39 JST meso meso
      in reply to
      @kirby did it as soon as gleason posted them
      In conversation Friday, 26-May-2023 22:45:39 JST permalink
    • Embed this notice
      Alex Gleason (alex@gleasonator.com)'s status on Friday, 26-May-2023 23:03:06 JST Alex Gleason Alex Gleason
      in reply to
      • nekobit
      • meso
      @meso @kirby @nekofag I have confirmed that this in fact does not work.
      In conversation Friday, 26-May-2023 23:03:06 JST permalink

      Attachments


      1. https://media.gleasonator.com/223959d89698c4d750e7d539c059ed9bef149b33933e7ede260d300161efe207.png
    • Embed this notice
      meso (meso@asbestos.cafe)'s status on Friday, 26-May-2023 23:03:08 JST meso meso
      in reply to
      • nekobit
      • meso
      @kirby @nekofag works
      In conversation Friday, 26-May-2023 23:03:08 JST permalink
    • Embed this notice
      meso (meso@asbestos.cafe)'s status on Friday, 26-May-2023 23:03:09 JST meso meso
      in reply to
      • nekobit
      @kirby try adding this if you want @nekofag
      In conversation Friday, 26-May-2023 23:03:09 JST permalink
    • Embed this notice
      Kirby :koronesmile: :koronebonk: :koroneThink: :korone_smug: (kirby@mstdn.starnix.network)'s status on Friday, 26-May-2023 23:07:37 JST Kirby :koronesmile: :koronebonk: :koroneThink: :korone_smug: Kirby :koronesmile: :koronebonk: :koroneThink: :korone_smug:
      in reply to
      • Alex Gleason
      • nekobit
      • meso

      @alex @meso @nekofag sandbox implies that this is being run isolated, can you grab cookies with a script and these rules

      In conversation Friday, 26-May-2023 23:07:37 JST permalink
    • Embed this notice
      Alex Gleason (alex@gleasonator.com)'s status on Friday, 26-May-2023 23:07:37 JST Alex Gleason Alex Gleason
      in reply to
      • nekobit
      • meso

      @kirby @meso @nekofag It simply isn’t how CSP works. When you request /, you get the CSP then and there. It doesn’t matter what the CSP headers are on requests made from inside that page. Resources are either allowed or blocked before they’re requested, not after you have a response.

      In conversation Friday, 26-May-2023 23:07:37 JST permalink
    • Embed this notice
      Kirby :koronesmile: :koronebonk: :koroneThink: :korone_smug: (kirby@mstdn.starnix.network)'s status on Friday, 26-May-2023 23:11:31 JST Kirby :koronesmile: :koronebonk: :koroneThink: :korone_smug: Kirby :koronesmile: :koronebonk: :koroneThink: :korone_smug:
      in reply to
      • Alex Gleason
      • nekobit
      • meso

      @alex @meso @nekofag so you're saying that it's just a nice looking label and the web browser doesn't actually isolate it (the script) from much

      In conversation Friday, 26-May-2023 23:11:31 JST permalink
    • Embed this notice
      Alex Gleason (alex@gleasonator.com)'s status on Friday, 26-May-2023 23:11:31 JST Alex Gleason Alex Gleason
      in reply to
      • nekobit
      • meso
      @kirby @meso @nekofag CSP absolutely does work and is necessary. It specifically prevents this type of attack. But you have to move your media to a subdomain for it to work properly.
      In conversation Friday, 26-May-2023 23:11:31 JST permalink
    • Embed this notice
      Alex Gleason (alex@gleasonator.com)'s status on Friday, 26-May-2023 23:12:03 JST Alex Gleason Alex Gleason
      in reply to
      • nekobit
      • Eric Zhang
      • meso
      @EricZhang456 @kirby @meso @nekofag And if you do that... your website will be a plain white screen.
      In conversation Friday, 26-May-2023 23:12:03 JST permalink
    • Embed this notice
      Eric Zhang (ericzhang456@pl.starnix.network)'s status on Friday, 26-May-2023 23:12:04 JST Eric Zhang Eric Zhang
      in reply to
      • Alex Gleason
      • nekobit
      • meso

      @kirby @alex @meso @nekofag just do script-src none;

      In conversation Friday, 26-May-2023 23:12:04 JST permalink
    • Embed this notice
      Alex Gleason (alex@gleasonator.com)'s status on Saturday, 27-May-2023 00:34:49 JST Alex Gleason Alex Gleason
      in reply to
      • Arrian
      • nekobit
      • meso
      @Arrian @meso @kirby @nekofag "sandbox" is the not magic term. Including a CSP header at all puts the page into whitelist mode, and you can't unwhitelist a resource you already whitelisted.
      In conversation Saturday, 27-May-2023 00:34:49 JST permalink
    • Embed this notice
      Arrian (arrian@jvpiter.net)'s status on Saturday, 27-May-2023 00:34:51 JST Arrian Arrian
      in reply to
      • Alex Gleason
      • nekobit
      • meso
      Works on Firefox for me. Brave doesn't handle "Content-Security-Policy: sandbox;" correctly?
      In conversation Saturday, 27-May-2023 00:34:51 JST permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.