Email or username:

Password:

Forgot your password?
Darius Kazemi

This is embarrassing, but about an hour ago I was alerted to an issue where edited, local-only posts in #Hometown were being federated. Please update your Hometown servers ASAP.

More info at the security patch link:

github.com/hometown-fork/homet

Most servers ignore or throw away the leaked data because it's an edit to something that it never received (the original post).

Still, unacceptable, and I'm sorry for this trouble, esp on a Friday night. I will do my best to contact admins individually.

25 comments
Darius Kazemi

(Hometown admins, if I see you faving this post I will assume you have seen it and I won't DM you!)

lakelady

@darius could you please point me to something that helps me understand what hometown is and how it fits in the fediverse? Thank you.

christa

@darius thank you for quickly fixing it!

Rob Simmons

@darius Now I get to feel clever for waiting until this weekend to upgrade to 1.1 🙃 . (Seriously — thanks for quickly fixing and for all the care you take with Hometown!)

Wesley Aptekar-Cassels

@darius thanks for the quick fix! just updated.

do you know when this was introduced? was it with the 4.0 update?

Darius Kazemi

@wesleyac Yes, it was introduced in v1.1.0 (I tried to get that across in the release notes but I see that it could be slightly clearer and will edit that)

Wesley Aptekar-Cassels

@darius thanks! one more question — do you know why the version number displayed in the footer doesn't update? (i recompiled assets and restarted in case that was it, but no change)

not a big deal, but i don't want people to see the old version number and worry that it's insecure.

Darius Kazemi

@wesleyac release has been updated in-place, thanks for the notice.

Darius Kazemi

@misty You're on an older Hometown so you should be fine, just make sure you update to whatever the latest version is when you do upgrade.

Misty

@darius I realized after a reread it was specific to edits. I’ll upgrade soon anyway!

Daneel Adrian Cayce

@darius Thanks so much for the quick fix, and for doing the work to keep us all in the loop. Appreciate it and you. 🌠

Ben Zanin

@darius you're a good and very conscientious developer, Darius.

Ben

@darius Thanks for sorting this so quickly. I was just in the weeds catching up on updates as it happened. Managed to get into trouble with unreported compile fails working on the v1.1.0 & 4.0.2 update but got there in end. The new patch was a breeze :)

Darius Kazemi

@benbyrne awesome. I tried to DM you but your server was down! Did you run out of memory on the compile updates? That's pretty common

Ben

@darius Cheers. Yeah, and it took me a little while to get to the bottom of it. Always learning.

Alexander Bochmann

@darius Thanks for fixing this quickly.

Unrelated (other than I noticed a moment after restarting my Mastodon services following the update) - The "Hometown" - link on the error page on my instance ("We're sorry, but something went wrong on our end.") points to example.org instead of anything useful?

Is there some place where I can change that link?

Darius Kazemi

@galaxis that shouldn't be happening. Can you open an issue for it? I'd like to look into this.

Alexander Bochmann

@darius Ok, will do, after rechecking if I have some setup or config error somewhere.

(((o))) Acoustic Mirror

@darius Ah, so that's what it was. @lurk was patched quickly yesterday if I remember correctly. Thank you for all the hard work!

Go Up