What is Hackers' Pub?

Hackers' Pub is a place for software engineers to share their knowledge and experience with each other. It's also an ActivityPub-enabled social network, so you can follow your favorite hackers in the fediverse and get their latest posts in your feed.

1
0
0
0
0
0
0
0
0
0

: I'm looking for French and Italian-speaking volunteers to check the translations of my subtitles for the Fedi promo video...

Yes technically Italian is my native language and I'm fluent in French but I'm not used to discussing the in these languages and I could really use some help 😅

Please DM me if you're interested. I'll give you credit in the video description.

Thanks! 🙏

Edit: I got help - no more need for double-checking the French or Italian translations

0
0
0
0
1
0

여성모임, 통합방도 개설되었습니다! 통합방은 성별 통합적 논의를, 기존 성별방은 각 성별집단 내부에 더 특화된 논의를 제공할 예정입니다. [극우에 반대하는 청년여성 연대] open.kakao.com/o/gmQX68zh [극우에 반대하는 시민연대] open.kakao.com/o/geMIb9zh 많은 홍보&리포스트 부탁드립니다!

RE: https://bsky.app/profile/did:plc:opb4uvituk2fx2y6tfkndnx7/post/3lqqtd4eclc25

0
1

여성모임, 통합방도 개설되었습니다! 통합방은 성별 통합적 논의를, 기존 성별방은 각 성별집단 내부에 더 특화된 논의를 제공할 예정입니다. [극우에 반대하는 청년여성 연대] open.kakao.com/o/gmQX68zh [극우에 반대하는 시민연대] open.kakao.com/o/geMIb9zh 많은 홍보&리포스트 부탁드립니다!

RE: https://bsky.app/profile/did:plc:opb4uvituk2fx2y6tfkndnx7/post/3lqqtd4eclc25

0
0
0

아니 내가 제일 짜증나는 부분은 이거임. 성적 지향이 들어간 걸 몰랐다고 쳐. 그래서 전화 팩스에 불이 난다고 쳐. "인권위의 기준을 준용했을 뿐인데 왜 그렇게 반발이 심한지 모르겠다" 이렇게 언론에 말하면 되지. 이게 안 되면 한통속이라는 증명밖에 안 되고.

RE: https://bsky.app/profile/did:plc:eeffxw7sfmqw2rv2cgi3uj3l/post/3lqtyxfs4w22k

0
0
1
0
0
0
0
0
0

日本語の情報圏にいるということは自覚されることがほとんどないため、エスノセントリズムが相対化されることは少ない。このエスノセントリズムは自己愛を増幅させる形で情報を取捨選択する。大谷スゴイコンテンツは自己愛の投影になっている(いや大谷はすごいんですが)。

1
0
0
0
0
0
0
0

@stefanoStefano Marinelli I've been thinking a lot about when the other shoe will drop: as useful as they are if used wisely, that type of tooling has pricing that feels wildly unsustainable and I expect there to be a steep rise in costs when VC money runs out that will highlight problematic dependencies on it.

But then again, a lot of people rolled with nigh-yearly media streaming cost increases. 🫠

0

: I'm looking for French and Italian-speaking volunteers to check the translations of my subtitles for the Fedi promo video...

Yes technically Italian is my native language and I'm fluent in French but I'm not used to discussing the in these languages and I could really use some help 😅

Please DM me if you're interested. I'll give you credit in the video description.

Thanks! 🙏

Edit: I got help - no more need for double-checking the French or Italian translations

0
0
0
0
0
1
0
0
0
0
1
3
0
0

We're excited to announce Hollo 0.6.0, a significant release that brings enhanced security, better user experience, and important infrastructure improvements to your single-user microblogging setup.

Enhanced OAuth Security with Modern Standards

This release prioritizes security with comprehensive OAuth 2.0 improvements that align with current best practices. We've implemented several critical RFC standards that significantly strengthen the authorization process:

OAuth 2.0 Authorization Code Flow with Access Grants — We've overhauled the OAuth implementation to properly separate authorization codes from access token issuance, providing better security isolation throughout the authentication process.

RFC 7636 PKCE (Proof Key for Code Exchange) Support — Hollo now supports PKCE with the S256 code challenge method, which prevents authorization code interception attacks. This is particularly important for public clients and follows the latest OAuth 2.0 security recommendations outlined in RFC 9700 (OAuth 2.0 Security Current Best Practices).

RFC 8414 OAuth Authorization Server Metadata — We've added support for OAuth Authorization Server metadata endpoints, allowing clients to automatically discover Hollo's OAuth capabilities and configuration. This makes integration smoother and helps clients adapt to your server's specific OAuth setup.

Enhanced Profile Scope Support — The new /oauth/userinfo endpoint and expanded profile scope support provide applications with standardized ways to access user profile information, improving compatibility with a wider range of OAuth-compliant applications.

These OAuth improvements not only make Hollo more secure but also position it at the forefront of federated social media security standards. We encourage other fediverse projects to adopt these same standards to ensure the entire ecosystem benefits from these security enhancements.

Special thanks to Emelia Smith (@thisismissemEmelia 👸🏻) for spearheading these critical OAuth security improvements and ensuring Hollo stays ahead of the curve on authentication best practices.

Revamped Media Storage Configuration

We've significantly improved how Hollo handles media storage configuration, making it more flexible and future-ready:

New Environment Variables — The storage system now uses STORAGE_URL_BASE (replacing the deprecated ASSET_URL_BASE) and FS_STORAGE_PATH for local filesystem storage (replacing FS_ASSET_PATH). These changes provide clearer naming and better organization.

Improved Security Requirements — The SECRET_KEY environment variable now requires a minimum of 44 characters, ensuring sufficient entropy for cryptographic operations. You'll need to update your configuration if your current secret key is shorter.

Network Binding Control — The new BIND environment variable lets you specify exactly which network interface Hollo should listen on, giving you more control over your server's network configuration.

Thanks to Emelia Smith (@thisismissemEmelia 👸🏻) for leading these infrastructure improvements.

Better User Experience

Customizable Profile Themes — You can now personalize your profile page with different theme colors. Choose from the full range of Pico CSS color options to make your profile uniquely yours.

Enhanced Administration Dashboard — The dashboard now displays the current Hollo version at the bottom, making it easier to track which version you're running. You can also sign out directly from the dashboard for better session management.

Improved Post Presentation — Shared posts on profile pages now have better visual separation from original content, and the sharing timestamp is clearly displayed. This makes it much easier to distinguish between your original thoughts and content you've shared from others.

Better Image Accessibility — Alt text for images is now displayed within expandable details sections, improving accessibility while keeping the interface clean.

Syntax Highlighting — Code blocks in Markdown posts now feature beautiful syntax highlighting powered by Shiki, supporting a comprehensive range of programming languages. This makes technical discussions much more readable.

Enhanced Character Limit — The maximum post length has been increased from 4,096 to 10,000 characters, giving you more space to express your thoughts in detail.

Thanks to RangHo Lee (@rangho_220우주스타 아이도루 랭호 🌠) for the version display feature and Okuto Oyama (@yamanoku) for the image accessibility improvements.

Privacy and Content Improvements

EXIF Metadata Removal — Hollo now automatically strips EXIF metadata from uploaded images before storing them, protecting your privacy by removing potentially sensitive location and device information.

Public API Endpoints — Following Mastodon's approach, certain API endpoints are now publicly accessible without authentication, making Hollo more compatible with various client applications and improving the overall federation experience.

Thanks to NTSK (@ntekNTSK) for the privacy-focused EXIF metadata stripping implementation.

Technical Foundation

Node.js 24+ Requirement — This release requires Node.js 24.0.0 or later. We've also upgraded to Fedify 1.5.3 and @fedify/postgres 0.3.0 for improved performance and compatibility.

Test Coverage & Quality Assurance — The codebase now includes comprehensive testing infrastructure and test coverage. We're committed to expanding this coverage and integrating testing more deeply into our development and release workflows. This also provides an excellent opportunity for first-time contributors to get involved by writing tests.

Cross-Origin Request Support — OAuth and well-known endpoints now properly support cross-origin requests, aligning with Mastodon's behavior and improving client compatibility.

Cleaner Token Endpoint — The scope parameter is now properly optional for the OAuth token endpoint, clarifying that it only affects client credentials flows (not authorization code flows, where it was already ignored).

Looking Forward

This release represents a major step forward in making Hollo not just a great single-user microblogging platform, but also a leader in federated social media security standards. The OAuth improvements we've implemented should serve as a model for other fediverse projects.

We're particularly excited about the OAuth security enhancements, which demonstrate our commitment to staying ahead of security best practices. As the federated web continues to evolve, we believe these standards will become increasingly important for maintaining user trust and ensuring secure interactions across the fediverse.

Upgrading

Upgrading to Hollo 0.6.0 is straightforward, but there are a few important considerations:

Railway Deployment

  1. Go to your Railway dashboard
  2. Select your Hollo project and service
  3. In the deployments tab, click the three-dot menu and select Redeploy

Docker Deployment

  1. Pull the latest image: docker pull ghcr.io/fedify-dev/hollo:latest
  2. Stop your current container
  3. Start with the new image using your existing configuration

Manual Installation

  1. Pull the latest code: git pull
  2. Install dependencies: pnpm install
  3. Restart the service: pnpm run prod

Important Upgrade Notes

Environment Variables: Update your configuration if you're using deprecated variables:

  • Replace ASSET_URL_BASE with STORAGE_URL_BASE
  • Replace FS_ASSET_PATH with FS_STORAGE_PATH
  • Ensure your SECRET_KEY is at least 44 characters long

Session Reset: Due to the OAuth security improvements, existing user sessions may be invalidated during the upgrade. You'll likely need to log in again through your client apps (like Phanpy, Moshidon, etc.) after upgrading. This is a one-time inconvenience that ensures you benefit from the enhanced security features.

Thank you to everyone who contributed to this release, and to the community for your continued support. Hollo 0.6.0 brings significant improvements to security, usability, and the overall experience of running your own corner of the fediverse.

1
2
1

豬油拌飯現在很少被提到,但它真的是台灣最經典的菜色。小時候豬油是家裡自己炸的,豬背脂肪分切小塊,放進大鍋裡慢慢煎,油開始出現,轉小火等候,脂肪塊漸漸縮小,整個廚房都是豬油香,香味從廚房漫到整個三合院、跨過院子,鄰近的八叔公、四叔公家都聞到香氣,拿著碗公來分一碗回去。

炸過的豬背脂縮的小小、脆脆帶著褐色,帶著油香的小塊灑點鹽就是很棒的零嘴。我媽會用大菜刀把它切又敲成碎碎的。

剛煮好的白飯、淋上一點豬油、醬油、灑上豬背脂碎片,或偶爾再煎個荷包蛋,在成長期的年紀沒有比這個更下飯的,瞬間一個小碗公的飯就會消失在嘴裡。

1990年代電視開始宣傳吃豬油會影響心臟的健康,慢慢的家裡也少吃了。但回憶起來豬油拌飯真的超讚的啦。看到昇哥這篇文,明天就到市場去買塊豬背肉炸個豬油😆 。

寫到這裡突然想起,當時給我家餐桌豬油拌飯致命一擊的是1997年爆發的口蹄疫,當年還是大學生,要是去當兵就有搬不完的豬屍了😅 ,歷經多年在豬農、政府人員們的努力台灣從OIE口蹄疫名單上除名,這樣的努力要肯定,我們國家有一點一點的在變好。感謝所有人們的努力🙏

0
0
0
0
0
0