Quantcast
Channel: Discourse Meta - Latest topics
Viewing all 60721 articles
Browse latest View live

Gmail new account creation flow broken when 2FA is enabled?

$
0
0

@supermathie wrote:

On Chrome/Linux, when logging into try (and creating an account) from incognito on an account that has 2FA enabled, I get this after authenticating to Google:

If I close the window then click ‘Google’ again, everything works as normal

Posts: 5

Participants: 2

Read full topic


Open External Links in new tab by default - Not working?

Is it supposed to be possible to upload images via email?

$
0
0

@deargle wrote:

Is it supposed to be possible for users to reply to posts with images, and for those images to show up in their post? I had a user send in two images via email, and they got uploaded, but all that showed in his post was the following:

[/uploads/default/original/1X/139d611a07adf85a<snip>.jpg]

[/uploads/default/original/1X/f730b788b5d3f531a4<snip>.jpg]

And I can manually browse to those images. I was on v2.0.0.beta1 I think.

I then upgraded discourse to v2.0.0.beta3 +11, did a test post, using gmail, and my incoming image only showed the alt tag on discourse, like this:

[image: Image result for business cat]

FWIW I can successfully upload images via the browser, and those images get sent out via email, and show up in emails.

Posts: 1

Participants: 1

Read full topic

Docker's Logos setting page gone and I cannot set logos

Pasted Link Topic Notification Email Does Not Show the Link

$
0
0

@hellekin wrote:

This is the inverse of Email-in: create a topic from a link?

A new topic can be created by pasting a link in place of the topic title. This brings the link to the front, attaching it to the topic itself in a way that the link is readily accessible in the topic list. But when the notification email is sent, the link does not appear necessarily, as the body of the topic presentation can be entirely changed, including removing that link.

Example

When I paste https://pasted.example.com/some/deep-link/article/12345 as the new topic title, the system captures the URL and attaches it to the newly-created topic, eventually replacing the topic title with the captured page title, and placing the URL in the topic description’s body. Once this is done, I can edit the message at will, including removing the URL from the body, and the link will remain attached to the topic.

This is an excellent behaviour, but the experience of reading the topic on the web and by email is very different! On the web, I have direct access to the attached link, even without opening the topic, and that signals the topic as being related to a third-party page. But by email, this context can be easily lost.

Expected Outcome

When a topic is created by pasting a link

  • the notification email should ensure the actual URL is present in the message;
  • the notification email should put the link on top of the message so that the message becomes the context of the link, and not the opposite;
  • the notification email should highlight the link, e.g., by prefixing the message with:

Context URL: https://pasted.example.com/some/deep-link/article/12345

Posts: 1

Participants: 1

Read full topic

Custom flag is not showing text, again

Best practice to prevent image hotlinking?

$
0
0

@ljpp wrote:

I have images uploaded to S3 and CloudFlare enabled on my site. To my knowledge however, and correct me if I am wrong, the CloudFlare’s hotlink protection does not work due to the images being hosted on a different domain.

Any suggestions or example implementations? If the S3 bucket policy is the way to go, I would love to see a .json code example.

Posts: 1

Participants: 1

Read full topic

Smilies in internal links is not shown, bug?


To choose categories is locked when browsing, bug?

Tags global or per categories?

$
0
0

@frold wrote:

Is there a way to set tags to only be in one category?

I thinking of making a book review subforum. Books ordered in “categories” by tags instead of subforums - but it seems like if Im enabling tags it is global for all categories?

Or what do I do wrong? :smiley:

Posts: 7

Participants: 2

Read full topic

How to edit message shown after signup?

$
0
0

@nibl wrote:

Where can I edit the message shown to users after signup? The one beginning “You’re almost done! We sent an activation mail to …“.

I couldn’t find it in the admin section. Do I need to edit a source file?

Posts: 6

Participants: 3

Read full topic

Tag - set but not set

$
0
0

@frold wrote:

I have made a Tag available for a catogory using this setting:

When making a post in the frontpage - from Latest, the default Category is “Uncategorized”.

Let us say I change it to another forum “Studmed debat” with these settings

Im able to set the tag to the topic. Or i seems like so, but its not there. And it shouldn’t. But this is kind of misleading as the user might think he have added a tag…?

Bug?

Posts: 1

Participants: 1

Read full topic

Speedy Alternate Account Creation Loophole (3 alts per min!)

$
0
0

@JonnyGamer wrote:

Hey there! Recently, I stumbled across an interesting bug/bypass on the sign up page for any discourse forum. This loophole allows people to create 2 to 3 discourse accounts per minute, while using the same email address.

The limit of discourse accounts you can make per email address:
2^(number of letters/numbers before the “@” symbol minus 1)

This is because discourse thinks that these emails are separate:
te.st@mail.com and test@mail.com

But gmail recognizes them as the same, since it omits periods before the “@”

Using this method, I was able to create over 300 accounts in 3 days (It is pretty time consuming, though)
If a machine(s) were to be programmed to do the following method, the effects could be pretty interesting


Edit: With the alternate account creations, I liked a singular post over 300 times to make it the “top” topic on the hopscotch forum (or at least, the “top” filter thought it was. This is probably because the code is:
(Total likes)/(Total Replies)

Posts: 12

Participants: 5

Read full topic

Re-Download Dark Theme?

Pin post in top of categories


Drag-and-drop reordering in /admin broken?

$
0
0

@steve_pd wrote:

I was pretty sure that the last time I tried to change top bar order, I could just drag the ‘top bar’ entries around via ‘Admin->Settings->Basic Settings->top bar’ but today I can’t.

I can click on each entry, which applies the ‘is-highlighted’ style, but can’t otherwise interact other than hitting the x to remove them.

Was this a thing?

Google Chrome (64.0.3282.167) and Safari (11.0.3)
Discourse: 2.0.0 beta3 +3

Edit: updated to +11, still happening.

Posts: 3

Participants: 2

Read full topic

Are there other workarounds to not having category moderation such as multiple instances of the board?

$
0
0

@MostHated wrote:

Hey there,
I was sad to see that I didn’t realize there were no category-specific permissions for moderation until after I got everything all set up and what not but I really like the forum in general and am trying to find some sort of way to work around this. I see that there is a tag system, is are there anyways to have custom permission based on the tags applied to threads or anything of the like?

Essentially the main goal is Developer-A has Category-A, Dev-B has Cat-B, Both Dev-A and Dev-B can see each other’s categories, post on them see the rest of the forum as normal users would, but Dev-A can edit posts, make stickies, delete things, etc only in Cat-A, and same for Dev-B and Cat-B.

I realize that this is not currently possible neither with the trust levels or Moderation permissions, but is there any sort of other workarounds to restrict editing of anything except for the category you are assigned? Even if it is simply not showing the edit or delete functionality in other categories besides your own based on user-specific setting, or group membership.

If still, that is not possible, what kind of requirements are there of setting up more than one board within the docker image, even if it just uses the same database, perhaps with a different prefix or something? Instead of restricting by category, it could just be another small forum for a development team. I could make an admin account on each board, then give out moderator permission to each team on their board and they could it up how they wish. I would imagine once docker and the DB are up and running, is it crazy to assume that another instance of the site could just function from a subdomain independently?

I know it is not comparing apples to apples, but the last forum I used was using tags to allow or disallow edits, a group is assigned to a tag, if the tag is a parent and they have permissions for the parent, then anything under there they can do with as they see fit, is there any modifications available to Discourse along those lines?

I definitely appreciate any insight anyone has into this, especially information on running multiple instances if you have any experience with its performance and the steps involved in accomplishing it.

Thanks!

Posts: 1

Participants: 1

Read full topic

LetsEncrypt ssl on email tracking domain

$
0
0

@Umashankar_Ankuri wrote:

Hi Team,

Some of the providers like elasticemail.com rewriting email content links.
Example. elasticemail requires tracking CNAME to be configured while verifying/adding sending domain also don’t allow verifying sub domains

actual link
https://discourse.domain.com/u/activate-account/9c9f071732482a63ef28591e4ef5017d

Rewriting email link for account activation email look like below

http://tracking.domain.com/tracking/click?d=yExJPVlLMbyKmyDMop0JMq3ZHFfxA0TPZhe0Dy6Osv7iSNeDEk_1YGRZuQPwP1YTRIWALOBW-3a-mSMo0qq7qDC_W6tBz4gqSpvAUgaJZR4nqhe6fjoRW4vNnZB_u1GnzhYWK1xV-KBHPacw2mGlxR6-6Sza2dieOrdQeyRq35xkMSY9L2ND6D_2riBkYCGD9A2

as discourse install didn’t install cert on tracking.domain.com leaving an insecure message on browser when we set force ssl setting.

As Discourse LetsEncrypt module will install certs on configured domain, Is there any way that installing certs on tracking domain

This is not a multisite.

Also LetsEncrypt is going to issue wildcard ssl in a week.(ETA: February 27, 2018 from LetsEncrypt forums) incorporating that to letsencrypt module is good choice to avoid these instances

Thank you.

Posts: 1

Participants: 1

Read full topic

Impersonating a user

$
0
0

@Biscuit wrote:

I clicked impersonate a user, as they requested assistance and I wanted to see what access they had. I also wanted to understand how impersonate a user worked and what it’s used for.

I expected to simply see the same screen options that user would see, but was surprised when the screen displayed a draft of a post they were writing. It was an innocent post, but I didn’t feel comfortable seeing this work in progress & tried to exit immediately to respect their privacy. But I didn’t know how! I closed the browser, but when I returned to the site, it opened as the impersonated user again. I ended up logging out as that user, without knowing if I was also logging out the real user.

The lack of “EXIT” button during impersonation was discussed in this thread in 2014:

Feature suggestions:

  1. Display a confirmation message when someone clicks impersonate providing an indication of what’s involved, as it’s a serious action to take.

  2. Add an obvious Exit or Stop Impersonating button.

  3. If you don’t want to do #2 above, consider displaying a banner at the top saying something like:
    "Currently impersonating User XXXXX - (take this action) to stop impersonating"
    There’s currently no UI guidance about how to exit impersonation.

Posts: 7

Participants: 5

Read full topic

Gravatar profile picture broke

Viewing all 60721 articles
Browse latest View live




Latest Images