{"p":"","h":{"iv":"ROXSYW+cfvEbFHu5","at":"ocxplSQjdRC3tXEtB/9/wg=="}}

Darius Kazemi

This is embarrassing, but about an hour ago I was alerted to an issue where edited, local-only posts in were being federated. Please update your Hometown servers ASAP.

More info at the security patch link:

github.com/hometown-fork/homet

Most servers ignore or throw away the leaked data because it's an edit to something that it never received (the original post).

Still, unacceptable, and I'm sorry for this trouble, esp on a Friday night. I will do my best to contact admins individually.

14
Share
Share on Mastodon
Share on Twitter
Share on Facebook
Share on Linkedin
Darius Kazemi

(Hometown admins, if I see you faving this post I will assume you have seen it and I won't DM you!)

1
2y
christa

@darius thank you for quickly fixing it!

0
2y
0
2y
Rob Simmons

@darius Now I get to feel clever for waiting until this weekend to upgrade to 1.1 ๐Ÿ™ƒ . (Seriously โ€” thanks for quickly fixing and for all the care you take with Hometown!)

0
2y
0
2y
Wesley Aptekar-Cassels

@darius thanks for the quick fix! just updated.

do you know when this was introduced? was it with the 4.0 update?

1
2y
Misty

@darius Thanks for the heads up.

1
2y
tedu
@darius tangential, but I don't think it's reasonable to assume Update is discarded. Messages are often delivered out of order, so an Update without a Create is not abnormal. Doing so would mean that when the create eventually arrives, old content is displayed.
1
2y
Daneel

@darius Thanks so much for the quick fix, and for doing the work to keep us all in the loop. Appreciate it and you. ๐ŸŒ 

0
2y
Ben Zanin

@darius you're a good and very conscientious developer, Darius.

0
2y
Ben

@darius Thanks for sorting this so quickly. I was just in the weeds catching up on updates as it happened. Managed to get into trouble with unreported compile fails working on the v1.1.0 & 4.0.2 update but got there in end. The new patch was a breeze :)

1
2y
Tom

@darius One for you @mistertim @support โ€ฆ ?

0
2y
Alexander Bochmann

@darius Thanks for fixing this quickly.

Unrelated (other than I noticed a moment after restarting my Mastodon services following the update) - The "Hometown" - link on the error page on my instance ("We're sorry, but something went wrong on our end.") points to example.org instead of anything useful?

Is there some place where I can change that link?

1
2y
(((o))) Acoustic Mirror

@darius Ah, so that's what it was. @lurk was patched quickly yesterday if I remember correctly. Thank you for all the hard work!

0
2y
Replies