Tangential to the flagging issue, but is there any documentation on how Immich is doing the PR site generation feature? That seems pretty cool, and I'd be curious to learn more.
https://github.com/immich-app/devtools/tree/a9257b33b5fb2d30...
51–60 of 713 posts
Tangential to the flagging issue, but is there any documentation on how Immich is doing the PR site generation feature? That seems pretty cool, and I'd be curious to learn more.
https://github.com/immich-app/devtools/tree/a9257b33b5fb2d30...
If you're going to host user content on subdomains, then you should probably have your site on the Public Suffix List https://publicsuffix.org/list/ . That should eventually make its way into various services so they know that a tainted subdomain doesn't taint the entire site....
I think it's somewhat tribal webdev knowledge that if you host user generated content you need to be on the PSL otherwise you'll eventually end up where Immich is now. I'm not sure how people not already having hit this very issue before is supposed to know about it beforehand though, one of those things that you don't really come across until you're hit by it.
Be sure to see the team's whole list of Cursed Knowledge. https://immich.app/cursed-knowledge
The Postgres query parameters one is funny. 65k parameters is not enough for you?!
is even funnier :D
They used to be more generic saying "We don't know if its safe" but now they are quite assertive at stating you are indeed an attacker.
If you're going to host user content on subdomains, then you should probably have your site on the Public Suffix List https://publicsuffix.org/list/ . That should eventually make its way into various services so they know that a tainted subdomain doesn't taint the entire site....
Is there any linkage to the semifactoid that immich Web gui looks very like Google Photos or is that just one of the coincidences?
If you're going to host user content on subdomains, then you should probably have your site on the Public Suffix List https://publicsuffix.org/list/ . That should eventually make its way into various services so they know that a tainted subdomain doesn't taint the entire site....
The root cause is bad behaviour by google. This is merely a workaround.
If you're going to host user content on subdomains, then you should probably have your site on the Public Suffix List https://publicsuffix.org/list/ . That should eventually make its way into various services so they know that a tainted subdomain doesn't taint the entire site....
Earlier quoted context omitted.
The root cause is bad behaviour by google. This is merely a workaround.
[flagged]
Google is happy to take their money and show scammy ads. Google ads are the most common vector for fake software support scams. Most people google something like "microsoft support" and end up there. Has Google ever banned their own ad domains?
Google is the last entity I would trust to be neutral here.