Chat Artifacts Gallery Guilds Search Wiki Login Register

Welcome, Guest. Please login or register. - Thinking of joining the forum??
April 11, 2026 - @606.69 (what is this?)
Activity rating: Four Stars Posts & Arts: 74/1k.beats Random | Recent Posts | Guild Recents
News: :cry: Are u having fun? Guild Events: There are no events!

+  MelonLand Forum
|-+  Materials & Info
| |-+  ⛄︎ ∙ MelonLand Info & Questions
| | |-+  BUG WATCH! - If you see a bug report it here!


« previous next »
Pages: 1 ... 15 16 [17] Print
Author Topic: BUG WATCH! - If you see a bug report it here!  (Read 59658 times)
Melooon
Hero Member ⚓︎
*****
View Profile WWWArt


So many stars!
⛺︎ My Room
SpaceHey: Friend Me!
StatusCafe: melon
iMood: Melonking
Itch.io: My Games
RSS: RSS

Guild Memberships:
Artifacts:
old-timey tunes~♪Flinstone VitaminAlways working hard!PoochKnown Apple shillcoolest melon on the web!
« Reply #240 on: February 26, 2026 @551.10 »

the welcome email it's suggested to write a greeting, but the link leads to a board where no
Thanks for the report! This is so weird, I've fixed this bug at least 3 times and somehow that link never goes away, it must be in some other file somewhere :drat:
Logged


everything lost will be recovered, when you drift into the arms of the undiscovered

Artifact Swap: shoeMicrowaveadopt a meAir MailCup o' JaneI met Dan Q on Melonland!poochLasagna
Dan Q
Hero Member ⚓︎
*****
View Profile WWWArt


I have no idea what I am doing
⛺︎ My Room
RSS: RSS

Guild Memberships:
« Reply #241 on: March 13, 2026 @402.88 »

I'm moderately confident there's an XSS vulnerability in the code that puts a message in the shoutbox when somebody creates a new thread.

When you create a new thread, the title of that thread gets posted (in a link) to the shoutbox, e.g. "Dan Q created [linked title of post]".

But that title doesn't get escaped, so any HTML code in the post title gets injected directly into the page, via the shoutbox. I haven't tested it, but a Melonlander could (deliberately or accidentally) cause a problem here. Suppose I created a thread with the subject "<script>alert('hi');</script> not working on my site", then I imagine the actual HTML code <script>alert('hi');</script> would get injected into the shoutbox!

We're a closed community, so we're probably moderately-safe (or else I wouldn't announce this in a public thread!), but it's probably still worth fixing! All that's needed is to run the titles through an escape_html(...) -like function before shoutboxing them.

I discovered this by accident when I posted this thread, which has HTML-like code in the subject.

Update: yup, verified by this thread, with which I was able to inject an image into the shoutbox. The limitation on the lengths of subject strings would make an "attack" difficult, but definitely not impossible! See attached screenshot.


* xss-in-the-shoutbox-demo.webp (23.98 kB, 537x303 - viewed 10 times.)
« Last Edit: March 13, 2026 @408.25 by Dan Q » Logged


Artifact Swap: I met Dan Q on Melonland!PolyamorousBouncy Egg!Joined 2025!Lurby
pepper
Full Member ⚓︎
***
View Profile WWWArt


she/her 🐾 local furry punk
⛺︎ My Room
SpaceHey: Friend Me!
StatusCafe: mildlypepper

Guild Memberships:
Artifacts:
Joined 2025!
« Reply #242 on: March 15, 2026 @143.18 »

This is a very odd issue but whenever I leave the forum page open in a tab and I restart my browser I get pinged notifications for alerts I have already seen and viewed.

This'll be because new alerts get picked up by each tab, but alerts that you click on only trigger an event in the current tab. And your browser is caching the DOM. I guess.
...
Refreshing the page should make them go away (because you've already viewed them).
...

This happens to me frequently, and reloading the page doesn't seem to make it go away completely? I have been getting the same notifications popping up on my OS toasts since Wednesday, across two different PCs/ browsers, even though I do not have any alerts showing on the forum.

Both PCs are Linux Mint, both are up-to-date Firefox. I am having difficulty recreating the problem reliably, but I have been for instance getting notifications about the Wednesday Website guild off and on since Wednesday. Even if I close my browser, then later re-open it, I will sometimes (but not always?) get the same notifications.

For the time being I think I will need to just disable notifications for the forum, which is a shame as I like knowing when threads I'm interested in have activity, I don't like to clutter my email inbox, and I have yet to set up an RSS client. (Maybe I should just set up an RSS client already, but still, this bug ... bugs me ...)
Logged

  :dog:  I'm verbose. Sorry! (not sorry)

         

Artifact Swap: I met Dan Q on Melonland!
boreal_cryptid
Sr. Member ⚓︎
****
View Profile WWWArt


без надії сподіваюсь
⛺︎ My Room

Guild Memberships:
Artifacts:
john egbertPolyamorousLucky Cat Companion +10 Dmg +5 luck +5 Stealthfaceplant neko^_^Joined 2025!
« Reply #243 on: March 15, 2026 @168.50 »

mobile version of the forum doesn't hide/spoiler users from ignore list :(
Logged

Is this how you honor MelonLand Forum, and the tribe unmourned? Write to me openly, and not by stealth.

Artifact Swap: green leaf (for outdoors enjoyers)snowy (for winter lovers)
Melooon
Hero Member ⚓︎
*****
View Profile WWWArt


So many stars!
⛺︎ My Room
SpaceHey: Friend Me!
StatusCafe: melon
iMood: Melonking
Itch.io: My Games
RSS: RSS

Guild Memberships:
Artifacts:
old-timey tunes~♪Flinstone VitaminAlways working hard!PoochKnown Apple shillcoolest melon on the web!
« Reply #244 on: March 15, 2026 @180.82 »

Both PCs are Linux Mint, both are up-to-date Firefox. I am having difficulty recreating the problem reliably
I have noticed this too, almost every time I open the forum on a computer I've not used in a while it will spam all the past notifications since I last used it, even for things I've already viewed on other computers. I don't really know much about how browser notifications work, so I have no idea why that happens! I guess its possible that push notifications are always running in the background, so the browser stacks up notifications quietly, maybe there is some command that should be sent to clear them. If anyone has experience lemmy know, otherwise it'll need some research!

hide/spoiler users from ignore list :(
It could be a chicken and egg situation; but less than 1% of forum members have ever used the ignore feature, so this is prob not a part of the site that's gonna get much time dedicated to it, but I will add it to the list! :ziped:
Logged


everything lost will be recovered, when you drift into the arms of the undiscovered

Artifact Swap: shoeMicrowaveadopt a meAir MailCup o' JaneI met Dan Q on Melonland!poochLasagna
Melooon
Hero Member ⚓︎
*****
View Profile WWWArt


So many stars!
⛺︎ My Room
SpaceHey: Friend Me!
StatusCafe: melon
iMood: Melonking
Itch.io: My Games
RSS: RSS

Guild Memberships:
Artifacts:
old-timey tunes~♪Flinstone VitaminAlways working hard!PoochKnown Apple shillcoolest melon on the web!
« Reply #245 on: March 17, 2026 @782.41 »

moderately confident there's an XSS
across two different PCs/ browsers, even though I do not have any alerts showing on the forum.
Both these should be fixed now. Alerts are prob still weird, but I'm 99% sure you will only get alerts in one tab now, and I'm 50% sure you wont get alerts showing up across multiple computers/browsers unless both are awake and on the forum at the moment you get an alert. (however its also possible I just broke notifications completely)

Dan your XSS attack path should now be fixed, hope you made some good use of it while you could :grin:
Logged


everything lost will be recovered, when you drift into the arms of the undiscovered

Artifact Swap: shoeMicrowaveadopt a meAir MailCup o' JaneI met Dan Q on Melonland!poochLasagna
Dan Q
Hero Member ⚓︎
*****
View Profile WWWArt


I have no idea what I am doing
⛺︎ My Room
RSS: RSS

Guild Memberships:
« Reply #246 on: March 18, 2026 @489.17 »

Dan your XSS attack path should now be fixed, hope you made some good use of it while you could :grin:

Ah, give me a few weeks; I'm sure I'll stumble upon another! :tongue:
Logged


Artifact Swap: I met Dan Q on Melonland!PolyamorousBouncy Egg!Joined 2025!Lurby
candycanearter07
Hero Member ⚓︎
*****
View Profile WWWArt


i like slimes
⛺︎ My Room
SpaceHey: Friend Me!
StatusCafe: candycanearter
Itch.io: My Games
RSS: RSS

Guild Memberships:
Artifacts:
it's tbhchansey!Goomy, I Choose You!Suck At Something September - Did It!uh oh! a pigeon got in!Artsy Candy Cane
« Reply #247 on: March 22, 2026 @848.87 »

Not 100% sure if this is a "bug", per-se, but the RSS feed list does not have an assigned author field for each message. It would be nice to be able to locally filter my own posts out of the feed, just for cleanliness sake. IDK how the feed code is written, and it's fine if not, but it would be handy. Thanks!
Logged

new to oldnet be nice





Artifact Swap: shoeDS Lover (replacement)Ball Creaturecards all the way down
kurohaato
Sr. Member ⚓︎
****
View Profile WWW


Full Steam Ahead! (≧∀≦)ゞ
⛺︎ My Room
SpaceHey: Friend Me!
StatusCafe: rinrinrin
iMood: kurohaato
Matrix: Chat!

Guild Memberships:
Artifacts:
BobYellow FishThe World's Cutest Predator BurbyFirst 1000 Members!Joined 2023!
« Reply #248 on: April 08, 2026 @856.61 »

There seems to be an issue where the font list is getting cut off whenever you make or reply to a post. It's most noticeable with the guilds where the text editor cuts it off at Flavors, but even the normal sized text editor cuts it off at Trash Hand (which I'm sure is annoying for the one person here that knows how to use wingdings). Messing around with inspect element lets me access the other fonts by changing the height of the div with the .sceditor-container class, but it would probably be better if we were able to scroll through the list instead of changing the text editor height. I've attached two screenshots below showing the issue on the normal forum text box and the guilds text box.


* guild-text-cutoff-screenshot.png (80.62 kB, 1743x487 - viewed 6 times.)

* regular-text-cutoff-screenshot.png (205.65 kB, 1423x813 - viewed 8 times.)
Logged

It ain't much but it's honest work

Artifact Swap: Waxed Lightly Weathered Cut Copper StairsWildflowers!Cherry Blossom PetalsA Little Frosty
IndigoGolem
Full Member ⚓︎
***
View Profile WWW


What's personal text?
⛺︎ My Room

Artifacts:
Joined 2025!
« Reply #249 on: April 10, 2026 @889.68 »

When you multi-quote a message and then pull it up with the quote button that appears, the quote displays behind the sidebar. At least in the default rain-and-flowers theme. This makes some of the buttons inaccessible.

To reproduce: multi quote a message, click the "n Quotes" button in the bottom-left corner of the screen.
Logged

Melooon
Hero Member ⚓︎
*****
View Profile WWWArt


So many stars!
⛺︎ My Room
SpaceHey: Friend Me!
StatusCafe: melon
iMood: Melonking
Itch.io: My Games
RSS: RSS

Guild Memberships:
Artifacts:
old-timey tunes~♪Flinstone VitaminAlways working hard!PoochKnown Apple shillcoolest melon on the web!
« Reply #250 on: Today at @988.94 »

the quote displays behind the sidebar
Thanks for this report, it should now be fixed with a cache clear!

t's fine if not, but it would be handy.
A good suggestion! I think I got it, but lemmy know!

There seems to be an issue where the font list is getting cut off whenever you make or reply to a post
This issue is basically that the editor exists within an iframe so it cant flow out of the editor area, however there are a few editor bugs I'm aware of, so I'll see what I can do as I work on this! A scroll might be do-able.
Fixed!
« Last Edit: Today at @6.44 by Melooon » Logged


everything lost will be recovered, when you drift into the arms of the undiscovered

Artifact Swap: shoeMicrowaveadopt a meAir MailCup o' JaneI met Dan Q on Melonland!poochLasagna
arcus
Sr. Member ⚓︎
****
View Profile WWW


⛺︎ My Room
Matrix: Chat!

Guild Memberships:
Artifacts:
Great Posts PacmanFirst 1000 Members!Joined 2023!
« Reply #251 on: Today at @382.65 »

Guild notes no longer display with Javascript disabled.

The MelonLand Nav overlaps on elements on Netsurf. Minor, but worth noting.

If this post goes through, then the "Save as Draft" button is still bugged.
Logged

Pages: 1 ... 15 16 [17] Print 
« previous next »
 

Melonking.Net © Always and ever was! SMF 2.0.19 | SMF © 2021 | Privacy Notice | ~ Send Feedback ~ Forum Guide | Rules | RSS | WAP | Mobile


MelonLand Badges and Other Melon Sites!

MelonLand Project! Visit the MelonLand Forum! Support the Forum
Visit Melonking.Net! Visit the Gif Gallery! Pixel Sea TamaNOTchi

MelonLand Nav

@000

Want to Login or Join ?

Minecraft: Online
Join: craft.melonking.net