Quantcast
Channel: Discourse Meta - Latest topics
Viewing all 60279 articles
Browse latest View live

Security breach in Discourse forum with SSO

0
0

@Rojoss wrote:

Hello, we've recently setup a Discourse forum with SSO.
Now one of our users claims to be a hacker and I believe it's actually legit.
He has given me screenshots of the user database which matches exactly with the Discourse database.
So he has emails from all our users and ip addresses.
The reason it must be from Discourse is because our own database stores different IP addresses and doesn't have flag_level.

I'd like to get in contact with a developer or someone experienced so that the security issues can be resolved.
It really shouldn't be possible for anyone to hack into the forum to access private data from all users.

The image on the right is the one the hacker sent us and the one on the left is from the data explorer on our site. (we just installed that to find out of it came from the forum it wasn't installed before)
I blurred most of it but as you can see the stuff that isn't blurred matches with the forum.

It's either the forum itself or SSO but there's obviously a security breach and I really hope an expert can contact me so that it can be resolved.

Posts: 17

Participants: 4

Read full topic


Docker install: Module aufs not found - again

0
0

@brahn wrote:

Following the guide, I have tried at both SF and NYC regions with ubuntu 16.04 and cannot get past installing docker without first following the recommendations from this old topic.

sudo apt-get install lxc wget bsdtar curl
sudo apt-get install linux-image-extra-$(uname -r)
sudo modprobe aufs

Either I am doing something odd or the guide needs updating yeah?

Posts: 2

Participants: 2

Read full topic

Hovering over the 'view' column shows title text: `[object Object]`

0
0

@Qqwy wrote:

When hovering over one of the fields of the 'view' column in the topic list, the title text shows [object Object] instead of some descriptive text. It seems there is a JavaScript bug there somewhere.

This was first mentioned by the user Eiji on the ElixirForum.
It definitely is reproducible across Discourse forums.

Posts: 8

Participants: 4

Read full topic

Post fade colour when going to thread from latest - has it changed colour?

0
0

@AstonJ wrote:

Not sure if this is a bug or if it's been intentionally changed.

When going to a thread from the latest page, it takes you to the first unread post - previously this post would fade in from a colour which I think is this one that can be set in the customisations:

highlight
The background color of highlighted elements on the page, such as posts and topics.

or might have even been:

tertiary
Links, some buttons, notifications, and accent color.

However, now it fades from white, which makes it look like a glitch if the post colour is anything other than white.

If it's been intentionally changed is there a css class we can target to change it back?

Edit: Hmmm, interesting, here on DC it still fades from blue :confused: (this suggests it is using 'tertiary' from the customisations... but why isn't it respecting mine?)

Edit 2: This gets weirder - it seems to actually be fading from the tertiary colour to white and then snaps to my post colour. So it looks like the fade has been hard-coded to fade to white from the tertiary colour (rather than to post colour) - this must have been introduced recently?

Posts: 1

Participants: 1

Read full topic

Helping with RSS issue

0
0

@Arta_S wrote:

Hey guys,

Need someone to help me with RSS with our Persian Forum.
The language tag for RSS is fa_IR which is wrong and RSS Validator does not validate.
See here: http://bit.ly/2idlnhG

The code for language must be fa-IR
note: Dash (-) instead of Underline (_)

Here is my previous topic that couldn't find solution and can be useful to track the actual problem:

Budget $20 USD (Can pay via Paypal or pay at your gateway)

Thank you

Posts: 8

Participants: 2

Read full topic

Markdown link not parsed when prepended with `[Text] `

Setting for reading topics from top insted bottom

0
0

@terraboss wrote:

Is there any setting for this use case of Discourse?

I have a lot of wiki topics with continues information... e.g. law cases, definitions, ...

I would like to use the first post of a new topic for specific categories as table of contents. Therefore I'd like to start at beginning even after reading all posts.

Any clue how to get more structure / overview in Discourse?

Sometimes it's pretty annoying inside specific categories, they couldn't be sorted by topic name. This is a big issue by using Discourse as knowledge base.

Best

Posts: 1

Participants: 1

Read full topic

Staff color applies to quoted message

0
0

@Silvanus wrote:

A post was written by staff member. The post is a response to another post (by non-staff member) and has the "in response to X" symbol at the top right corner. (As it happens, the message is the one right above it.) Clicking the symbol opens up the message again on top of the message (showing the message to which the post is a reply to).

The post by staff member had staff color added. The color applied (bug!) to the replied message as well.

Screenshot:

Posts: 1

Participants: 1

Read full topic


Applying staff color to avatar area

New Topic - Weekly - How i can change?

0
0

@Ogulcan wrote:

How i can change weekly topic to unlimited.
Hafta = Weekly

And I have one more question. How i can do that = Prevent image uploading within the topic.
Sorry my english bad. Thank you :slight_smile:

Posts: 6

Participants: 2

Read full topic

Following the setup instructions, so close! Error at very end!

0
0

@JamesDaly wrote:

Hey guys,

Very impressed by the setup instructions found on https://github.com/discourse/discourse/blob/master/docs/INSTALL-cloud.md

Not only is a beginner like me able to follow them, I'm also learning loads while doing so, so thanks for that :slight_smile:

However, I'm stumped right at the finish line! And I'm hoping you can help me out.

I've followed each step, everything's going swimmingly (including a 2GB drop), and at the last step I get this (have removed duplication for brevity of this post, also has an actual API key in SMTP password):

root@invincibletricking:~# /var/discourse/discourse-setup
Ports 80 and 443 are free for use
cp: cannot stat 'samples/standalone.yml': No such file or directory
Found 2GB of memory and 2 physical CPU cores
sed: can't read containers/app.yml: No such file or directory
sed: can't read containers/app.yml: No such file or directory

Does this look right?

Hostname : forum.invincibletricking.co
Email : james@invincibletricking.com
SMTP address : smtp.sparkpostmail.com
SMTP port : 587
SMTP username : SMTP_Injection
SMTP password : ••••••••••••••••••••••••••••••••••••

**ENTER to continue, 'n' to try again, Ctrl+C to exit: **
sed: can't read containers/app.yml: No such file or directory
DISCOURSE_HOSTNAME change failed.
sed: can't read containers/app.yml: No such file or directory
DISCOURSE_DEVELOPER_EMAILS change failed.
sed: can't read containers/app.yml: No such file or directory
DISCOURSE_SMTP_ADDRESS change failed.
sed: can't read containers/app.yml: No such file or directory
DISCOURSE_SMTP_PORT change failed.
sed: can't read containers/app.yml: No such file or directory
DISCOURSE_SMTP_USER_NAME change failed.
sed: can't read containers/app.yml: No such file or directory
DISCOURSE_SMTP_PASSWORD change failed.

Unfortunately, there was an error changing containers/app.yml

Apologies if this is a super beginner question, very much hoping you can help me out!

Posts: 4

Participants: 3

Read full topic

_registerPluginCode is not a function

0
0

@Silvanus wrote:

Uncaught TypeError: Discourse._registerPluginCode is not a function
Url: https://uskojarukous.fi/users/activate-account/6e346b8900ec9c450e4ce27633b08f7f
Line: 49
Column: 23
Window Location: https://uskojarukous.fi/users/activate-account/6e346b8900ec9c450e4ce27633b08f7f

I found this in my logs. There's quite a few lines in there, I'll make new topics of the things that appear most (or is it fruitful?). This caught my eye, because account activation seems the one place where security is a high issue...

Posts: 1

Participants: 1

Read full topic

Two errors from logs

0
0

@Silvanus wrote:

I have these two errors in my logs popping all the time. Will paste only one example of each error, array length must be a finite positive integer and argument not optional:

Array length must be a finite positive integer
Url: https://uskojarukous.fi/assets/ember_jquery-60dedd1dca1d8b8ce48b6d0087db3b96f3149b9b5af2d0c7c6357967d29031fb.js
Line: 3
Column: 29556
Window Location: https://uskojarukous.fi/t/ylen-rooli-mediavaikuttajana/961/9

Another one:

Argument not optional
Url: https://uskojarukous.fi/assets/application-becfabe86f7be04bd04e977e9bf45e9742dd36a4acc03703eb345d5e3afb5f81.js
Line: 19
Column: 25844
Window Location: https://uskojarukous.fi/t/kirkossakayntitilastoa/917/35

Are these anything I have to worry about?

Posts: 1

Participants: 1

Read full topic

Installation Failed on CoreOS?

0
0

@Blackglade wrote:

Not sure what is happening here, but I can't seem to get my installation for Discourse working on a CoreOS container by Digital Ocean. Everything went fine until the ouput the very end

Here is a pastebin of my cloud config file I used to start the container if that's relevant: http://pastebin.com/raw/5SyXP4Vh

I ran the commands EXACTLY as listed on the guide. I cloned the repo in the relevant directory and ran the bash script!

Posts: 7

Participants: 2

Read full topic

No matter what I do, can't get email working on new install

0
0

@JamesDaly wrote:

I'm sorry to ask yet another question, I'm doing my best to solve this myself, as I know beginner questions can be annoying (I've been reading through this excellent page here https://meta.discourse.org/t/troubleshooting-email-on-a-new-discourse-install/16326/2) but no matter what I try I don't receive an email to set up the admin account :frowning:

I'm not receiving the confirmation email when setting up. I must have made a mistake when setting up my email, but for the life of me I can't figure out what it is. Perhaps something to do with the domain vs subdomain with my mail provider.

I've set up forum@invincibletricking.co with my domain name company, forwarding it to my usual email account, and have put these details into Spark Post.

I receive standard emails sent to forum@invincibletricking.co, so the forwarding address itself works.

Have configured Spark Post as set out in the instructions, and then entered it all into the app.yml file:

## TODO: List of comma delimited emails that will be made admin and developer
## on initial signup example 'user1@example.com,user2@example.com'
DISCOURSE_DEVELOPER_EMAILS: 'forum@invincibletricking.co'

## TODO: The SMTP mail server used to validate new accounts and send   notifications
DISCOURSE_SMTP_ADDRESS: smtp.sparkpostmail.com
DISCOURSE_SMTP_PORT: 587
DISCOURSE_SMTP_USER_NAME: SMTP_Injection
DISCOURSE_SMTP_PASSWORD: b625 ••••••••••••••••••••••••••••••••••••
#DISCOURSE_SMTP_ENABLE_START_TLS: true           # (optional, default true)

And in Spark Post SMTP Relay settings on their site:

SMTP Relay

Use the information below to configure your SMTP client to relay via SparkPost.
You need an API key to use as a password when filling out the information.
Host:smtp.sparkpostmail.com
Port:587 (Alternative Port: 2525)
Authentication:AUTH LOGIN
Encryption:STARTTLS
Username:SMTP_Injection
Password: b625 ••••••••••••••••••••••••••••••••••••

Verified sending domain panel screenshot from Spark Post is here: http://conversantm.com/68pl/2g3lj9931

And the URL of my forum is a subdomain of https://invincibletricking.co

It's doing my head in haha hoping you'll be able to help a learner like myself out :innocent:

Posts: 1

Participants: 1

Read full topic


For Security Reasons, I want to edit /admin URL

0
0

@bRionZ wrote:

Hello,

I just installed newest Discourse BETA version on my new server. I want to know how to edit admin URL to a custom prefix (discsourse.example.com/admin > discourse.example.com/custom).
I cannot edit because I don't know how to implement on Ruby.

Thanks before.

Posts: 5

Participants: 3

Read full topic

Very secret info and email notifications

0
0

@intagger wrote:

I have a private forum with confidential information which must be stored only on our own server and should not pass to any other systems like gmail, etc. via email notifications. How can I configure email notifications to not include any info from the forum except only for number of new posts/mentions etc.?

Posts: 2

Participants: 2

Read full topic

Open Sans 300 in Custom Header

0
0

@harveywun wrote:

Trying to add a custom header (to match my primary site and take users back, if needed). My brand logo uses Open Sans 300 light (with 4px letter spacing, not important). So:

@import url(http://fonts.googleapis.com/css?family=Open+Sans);

Then I style it:

.top-brand-nav-link {
  font-family: "Open Sans";
  font-weight: 300;
  font-size: 25px;
  letter-spacing: 4px;
}

Anyway, it all works and the header looks fine except that the font weight is off! It gives me Open Sans 400 (not 300)! I'm a little puzzled because when I change font-weight to 600 (semibold) or 700 (bold), it gets styled correctly (so my code should be fine). Obviously 400 is fine, but I cannot seem to get it to 300 (light). 300 just gives me 400.:sweat:

Any idea why?

Posts: 4

Participants: 2

Read full topic

Promoting new forum

0
0

@azaleas wrote:

Hey guys,

Was wondering is there any chance to use online survey widgets with discourse? Like Rafflecopter for example?

We would like to create a monthly competition for most likes for posts and so on. Also, initial survey where users will have to register to discourse, like our tweeter page, retweet and etc.

Any ideas?

Posts: 1

Participants: 1

Read full topic

Random iOS observation on page navigation

0
0

@charleswalter wrote:

As you scroll on iOS, the bottom bar of Safari disappears. When this happens, if you tap on the bottom 20 or so pixels, it doesn't interact with your page, but it first brings up the Safari navigation. So, in trying to interact with the page navigation on iOS, you'll actually need to tap twice.

I realized this when recently adding a Go To Top button which can help on category fronts if you want to quickly see if there are new posts, or if you've scrolled down and want an easy way to get to the mobile breadcrumbing to go to the category.

At first, I only had a 10 pixel bottom margin, and always found myself double tapping to activate it. but once I changed the margin to 30 pixels, it worked much better. The only negative to the button is that if I happen to enter a first large topic and didn't start at the top, it won't take me to post 1.

Anyhow, just wanted to share this experience. Perhaps it's something we should consider in the future regarding the placement of the page navigator, though it may look funny floating a bit higher.

Posts: 4

Participants: 2

Read full topic

Viewing all 60279 articles
Browse latest View live




Latest Images