this post was submitted on 10 Jul 2023
4 points (100.0% liked)
Reddthat Support -> Has moved
333 readers
1 users here now
Reddthat Community Support Forum
Before posting, have you read the rules?
Introductory Required Reading
You are ready to start your adventure on Reddthat but are still unsure? That's fine! You've come to the right place.
- Ideas? Post-em
- Issues? Post-em
- Queries? Post-em
- Ideas to help Reddthat? Post-em
Alternative Support Forums
founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
You beat me to making a post about it.
The XSS exploit was related to custom emoji. As we never got round to using the custom emoji in any real use it's a non issue.
Also, yes we would have to wait for the devs for a real fix before we can safely go back to using the custom emoji.
I rotated my own jwt, but left everyone else's. :)
Tiff
I read through some of the "custom emoji exploit" updates earlier today, but wasn't sure if it was still "the latest (or only exploit)", and/or if it applied to our instance at all.
I appreciate your response! I can't even pretend to know what "rotating a jwt" truly entails, but I had read enough to know even less... and I appreciate the response because it helps things make more sense to me! Thanks again for all that y'all do here!