Conversation

Notices

  1. Back to not seeing @nerthos on my server, Fix your apple RDN

    Monday, 30-May-16 01:20:47 UTC from shitposter.club
    1. @moonman @nerthos I can see him on my gorf.club account and on my instance now, but he still isn't appearing here for w/e reason.

      Monday, 30-May-16 01:23:10 UTC from shitposter.club
      1. @normandy @nerthos He does for a little while then disappears again.

        Monday, 30-May-16 01:24:20 UTC from shitposter.club
        1. @moonman @nerthos He only seems to appear when he's in a conversation with at least one SPC user.

          Monday, 30-May-16 01:25:22 UTC from shitposter.club
        2. @moonman @nerthos He's like a phantom ;)

          Monday, 30-May-16 01:25:42 UTC from shitposter.club
          1. @normandy http://orig04.deviantart.net/f181/f/2013/143/3/7/profile_picture_by_itsamystery_plz-d66aysf.png

            Monday, 30-May-16 01:27:08 UTC from web
            1. Alas poor @nerthos 
              I knew him well...

              Monday, 30-May-16 01:38:19 UTC from shitposter.club
              1. @normandy On the plus side as a ghost I can spook things.

                Monday, 30-May-16 01:38:58 UTC from web
        3. @moonman I can always tell when RDN disappears bc my little green TLS lock in FF doesn't turn a sad gray =p @nerthos @normandy

          Monday, 30-May-16 01:35:57 UTC from sealion.club
          1. @fl0wn @normandy @nerthos I want to enforce full TLS on my server using a Content Security Policy header, but I can't because of non-TLS servers. And apparently there's no good fix for servers that predate strict TLS usage.

            Monday, 30-May-16 01:39:13 UTC from shitposter.club
            1. @moonman yeah, that came up earlier when chatting w/ @ceruleanspark . There doesn’t seem to be a simple solution currently that won't totally bork federation @nerthos @normandy

              Monday, 30-May-16 01:45:16 UTC from sealion.club
              1. @fl0wn @normandy @nerthos @ceruleanspark On the frontend it's the resources that kill it, right? So like, images and stuff. The federation hoo-ha happens on the backend. I realize this is work, but I think that images/etc can be configured to be served from a different domain (like normally a CDN) but instead just have the subdomain serve from the same server but with a redirect from http to https and an HSTS header that requests the browser to always use HTTPS.

                To be clear, I am NOT making any demands on anybody to do anything, but maybe something like this would be a solution

                Monday, 30-May-16 02:00:34 UTC from shitposter.club
                1. @nerthos @fl0wn @ceruleanspark @normandy I just realized I was only thinking about remote servers not RDN itself, haha :-(

                  Monday, 30-May-16 02:02:15 UTC from shitposter.club
                  1. @moonman RDN has a subdomain for attachments.

                    Monday, 30-May-16 02:04:56 UTC from web
                    1. @nerthos Can you post something with an embedded image attachment please?

                      Monday, 30-May-16 02:07:27 UTC from shitposter.club
                      1. @moonman http://rainbowdash.net/attachment/845540

                        Monday, 30-May-16 02:08:36 UTC from web
                        1. @nerthos @moonman  https://bananaposter.club/attachment/87936

                          Monday, 30-May-16 02:11:09 UTC from shitposter.club
                        2. @nerthos Yeah it's only the profile avatar stuff that's blowing it up since it's pulled from the profile image and loaded dynamically. I am tempted to make a special patch for my Qvitter to just automatically rewrite RDN image/attachment URLs to be https, haha.

                          Monday, 30-May-16 02:13:55 UTC from shitposter.club
                          1. @moonman It happens over here too. Today everyone's avatars loaded right except @zemichi

                            Monday, 30-May-16 02:15:21 UTC from web
                            1. @nerthos @zemichi I popped over to RDN to look at one profile and basically almost none of the profile pics for the "following" were loaded, they were all broken :-(

                              Monday, 30-May-16 02:16:41 UTC from shitposter.club
                              1. @moonman This problem weirds me out as it's really recent. http://rainbowdash.net/attachment/845544

                                Monday, 30-May-16 02:18:36 UTC from web
                                1. @nerthos I wonder if it's because I updated my own server to main branch...

                                  Monday, 30-May-16 02:20:44 UTC from shitposter.club
                                  1. @moonman @nerthos No, my instance is on main and I can see nerthos fine.

                                    Monday, 30-May-16 02:21:38 UTC from shitposter.club
                                    1. @normandy @nerthos I meant the broken icon for me.

                                      Monday, 30-May-16 02:22:36 UTC from shitposter.club
                                      1. @moonman @nerthos Your icon appears on RDN in my browser.

                                        Monday, 30-May-16 02:23:30 UTC from shitposter.club
                                    2. @normandy @moonman Nevermind then

                                      Monday, 30-May-16 02:22:51 UTC from web
                                  2. @moonman It could be that. It could be that the latest version of GNUsocial broke it, not RDN, and RDN looks like the culprit just because it's the only one on the older software.

                                    Monday, 30-May-16 02:22:26 UTC from web
                                  3. @moonman meh, I'm trying to avoid headaches until Hope migrates us to our new home. I figure I might as well sit back and enjoy the weekend bc who knows what kind of kiwiery's going to pop up during/ after the move  @nerthos

                                    Monday, 30-May-16 02:34:36 UTC from sealion.club
                          2. @moonman will maek RDN Great (again?)  @nerthos

                            Monday, 30-May-16 02:30:52 UTC from sealion.club
                            1. @fl0wn @nerthos welp in Chrome I just made a custom HTTPSEverywhere ruleset for the RDN domains, which works if you navigate to the image manually but fails (BLOCKED BY CLIENT) when loaded in the browser and still makes the green happy cert disappear.

                              :-(

                              Monday, 30-May-16 02:35:05 UTC from shitposter.club
                2. @moonman @nerthos @fl0wn @ceruleanspark There is a script one can run on their instance to change HTTP feed urls to HTTPS. But it has to be done on each of the remote servers.

                  Monday, 30-May-16 02:04:11 UTC from shitposter.club