Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Does anyone have recommendations for a Mastodon fork that doesn't require visitors to enable JavaScript to view basic content?

Does anyone have recommendations for a Mastodon fork that doesn't require visitors to enable JavaScript to view basic content?

Scheduled Pinned Locked Moved Uncategorized
mastodonactivitypubmastoadminselfhostsecurity
9 Posts 5 Posters 1 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • seanm@infosec.exchangeS This user is from outside of this forum
    seanm@infosec.exchangeS This user is from outside of this forum
    seanm@infosec.exchange
    wrote last edited by
    #1

    Does anyone have recommendations for a Mastodon fork that doesn't require visitors to enable JavaScript to view basic content? The JavaScript dependency is a security risk and user hostile. Visitors should not be required to enable JavaScript when simply visiting a Mastodon server. Plus, the recommendation to use a native app doesn't even work for all Mastodon/ActivityPub instances.

    Also, the requirement for JavaScript makes the Mastodon development team seem incompetent. They can't even make a basic web site that doesn't require JavaScript. I could do that when I was in middle school.

    >To use the Mastodon web application, please enable JavaScript. Alternatively, try one of the native apps for Mastodon for your platform.

    #Mastodon #ActivityPub #MastoAdmin #SelfHost #Security

    jerry@infosec.exchangeJ erick@social.erick.shE seanm@infosec.exchangeS timbray@cosocial.caT 4 Replies Last reply
    0
    • seanm@infosec.exchangeS seanm@infosec.exchange

      Does anyone have recommendations for a Mastodon fork that doesn't require visitors to enable JavaScript to view basic content? The JavaScript dependency is a security risk and user hostile. Visitors should not be required to enable JavaScript when simply visiting a Mastodon server. Plus, the recommendation to use a native app doesn't even work for all Mastodon/ActivityPub instances.

      Also, the requirement for JavaScript makes the Mastodon development team seem incompetent. They can't even make a basic web site that doesn't require JavaScript. I could do that when I was in middle school.

      >To use the Mastodon web application, please enable JavaScript. Alternatively, try one of the native apps for Mastodon for your platform.

      #Mastodon #ActivityPub #MastoAdmin #SelfHost #Security

      jerry@infosec.exchangeJ This user is from outside of this forum
      jerry@infosec.exchangeJ This user is from outside of this forum
      jerry@infosec.exchange
      wrote last edited by
      #2

      @seanm I am not 100% sure it works without javascript, but try: https://elk.infosec.exchange/

      seanm@infosec.exchangeS 1 Reply Last reply
      0
      • seanm@infosec.exchangeS seanm@infosec.exchange

        Does anyone have recommendations for a Mastodon fork that doesn't require visitors to enable JavaScript to view basic content? The JavaScript dependency is a security risk and user hostile. Visitors should not be required to enable JavaScript when simply visiting a Mastodon server. Plus, the recommendation to use a native app doesn't even work for all Mastodon/ActivityPub instances.

        Also, the requirement for JavaScript makes the Mastodon development team seem incompetent. They can't even make a basic web site that doesn't require JavaScript. I could do that when I was in middle school.

        >To use the Mastodon web application, please enable JavaScript. Alternatively, try one of the native apps for Mastodon for your platform.

        #Mastodon #ActivityPub #MastoAdmin #SelfHost #Security

        erick@social.erick.shE This user is from outside of this forum
        erick@social.erick.shE This user is from outside of this forum
        erick@social.erick.sh
        wrote last edited by
        #3

        @seanm more than a fork, sounds that what you are looking for is an alternative front end that can be configure as the default on your site.

        Unfortunately I have no idea if the is such thing. I know there are plenty of alternative web clients, but again, as far as I can tell that is now what you are looking for.

        smallcircles@social.coopS seanm@infosec.exchangeS 2 Replies Last reply
        0
        • seanm@infosec.exchangeS seanm@infosec.exchange

          Does anyone have recommendations for a Mastodon fork that doesn't require visitors to enable JavaScript to view basic content? The JavaScript dependency is a security risk and user hostile. Visitors should not be required to enable JavaScript when simply visiting a Mastodon server. Plus, the recommendation to use a native app doesn't even work for all Mastodon/ActivityPub instances.

          Also, the requirement for JavaScript makes the Mastodon development team seem incompetent. They can't even make a basic web site that doesn't require JavaScript. I could do that when I was in middle school.

          >To use the Mastodon web application, please enable JavaScript. Alternatively, try one of the native apps for Mastodon for your platform.

          #Mastodon #ActivityPub #MastoAdmin #SelfHost #Security

          seanm@infosec.exchangeS This user is from outside of this forum
          seanm@infosec.exchangeS This user is from outside of this forum
          seanm@infosec.exchange
          wrote last edited by
          #4

          Just to be clear, I think JavaScript is fine for authenticated or more complex content. If I'm a user of a server, it seems acceptable that I should trust it and enable JavaScript.

          However, if I am some random visitor to your instance and just trying to view a post or user profile, that should not require JavaScript.

          The JavaScript ecosystem (e.g., npm) is rife with supply chain hacks. Plus, there are many poorly maintained Mastodon instances (e.g., mastodon.social, I think?). Although, I guess those poorly maintained instances are not pulling down the latest backdoored npm packages... Regardless, it is a security risk to require visitors run JavaScript from every instance they visit for simple content.

          #Mastodon #ActivityPub #InfoSec #Security #MastoAdmin

          1 Reply Last reply
          0
          • jerry@infosec.exchangeJ jerry@infosec.exchange

            @seanm I am not 100% sure it works without javascript, but try: https://elk.infosec.exchange/

            seanm@infosec.exchangeS This user is from outside of this forum
            seanm@infosec.exchangeS This user is from outside of this forum
            seanm@infosec.exchange
            wrote last edited by
            #5

            @jerry unfortunately, it is just a blank page with JavaScript disabled.

            1 Reply Last reply
            0
            • erick@social.erick.shE erick@social.erick.sh

              @seanm more than a fork, sounds that what you are looking for is an alternative front end that can be configure as the default on your site.

              Unfortunately I have no idea if the is such thing. I know there are plenty of alternative web clients, but again, as far as I can tell that is now what you are looking for.

              smallcircles@social.coopS This user is from outside of this forum
              smallcircles@social.coopS This user is from outside of this forum
              smallcircles@social.coop
              wrote last edited by
              #6

              @erick @seanm

              I am not sure either, but for a good overview I can point you to the delightful fediverse experience curated list I maintain at:

              Link Preview Image
              delightful fediverse experience

              Delightful curated lists of free software, open science and information sources.

              favicon

              (delightful.coding.social)

              There are 2 other fedi related list, see.. https://delightful.coding.social/

              seanm@infosec.exchangeS 1 Reply Last reply
              0
              • erick@social.erick.shE erick@social.erick.sh

                @seanm more than a fork, sounds that what you are looking for is an alternative front end that can be configure as the default on your site.

                Unfortunately I have no idea if the is such thing. I know there are plenty of alternative web clients, but again, as far as I can tell that is now what you are looking for.

                seanm@infosec.exchangeS This user is from outside of this forum
                seanm@infosec.exchangeS This user is from outside of this forum
                seanm@infosec.exchange
                wrote last edited by
                #7

                @erick it's crazy that this is such a problem. Old Reddit, Twitter, Gmail, and most every popular website started as HTML/CSS functional. There are frontends like Nitter (for Twitter) that show this functionality is still possible.

                Why is there such a drive to be so hostile to users and increase the risk to visitors?

                1 Reply Last reply
                0
                • smallcircles@social.coopS smallcircles@social.coop

                  @erick @seanm

                  I am not sure either, but for a good overview I can point you to the delightful fediverse experience curated list I maintain at:

                  Link Preview Image
                  delightful fediverse experience

                  Delightful curated lists of free software, open science and information sources.

                  favicon

                  (delightful.coding.social)

                  There are 2 other fedi related list, see.. https://delightful.coding.social/

                  seanm@infosec.exchangeS This user is from outside of this forum
                  seanm@infosec.exchangeS This user is from outside of this forum
                  seanm@infosec.exchange
                  wrote last edited by
                  #8

                  @smallcircles @erick thank you. I'll take a look at those. I appreciate that the site doesn't require JavaScript just to view.

                  1 Reply Last reply
                  0
                  • seanm@infosec.exchangeS seanm@infosec.exchange

                    Does anyone have recommendations for a Mastodon fork that doesn't require visitors to enable JavaScript to view basic content? The JavaScript dependency is a security risk and user hostile. Visitors should not be required to enable JavaScript when simply visiting a Mastodon server. Plus, the recommendation to use a native app doesn't even work for all Mastodon/ActivityPub instances.

                    Also, the requirement for JavaScript makes the Mastodon development team seem incompetent. They can't even make a basic web site that doesn't require JavaScript. I could do that when I was in middle school.

                    >To use the Mastodon web application, please enable JavaScript. Alternatively, try one of the native apps for Mastodon for your platform.

                    #Mastodon #ActivityPub #MastoAdmin #SelfHost #Security

                    timbray@cosocial.caT This user is from outside of this forum
                    timbray@cosocial.caT This user is from outside of this forum
                    timbray@cosocial.ca
                    wrote last edited by
                    #9

                    @seanm Since you're obviously smarter than the Masto team, why don't you code that up? The API is stable and well documented.

                    1 Reply Last reply
                    1
                    0
                    • R relay@relay.mycrowd.ca shared this topic
                    Reply
                    • Reply as topic
                    Log in to reply
                    • Oldest to Newest
                    • Newest to Oldest
                    • Most Votes


                    • Login

                    • Login or register to search.
                    • First post
                      Last post
                    0
                    • Categories
                    • Recent
                    • Tags
                    • Popular
                    • World
                    • Users
                    • Groups