2.2 breaking api changes Stephen Lynx Board owner 12/07/2018 (Fri) 22:26:24
On 2.2 the json api features were merged into the form api and removed afterwards.
So not only the json input was removed, bu also the json output of the form api was remade. The refactoring is finished and penumbra has been adapted.

2.2 is scheduled to be released on march of 2019.
Cat Board owner 01/03/2016 (Sun) 12:07:51

3 feature requests Cat 04/23/2019 (Tue) 22:43:12
Feature request 1: make it possible in the global settings to edit the footer of the chan, just as it is already possible to edit the header. It would only make sense to have both, not just one.
Feature request 2: allow board owner to enable or disable TOR posting on their board, lest the administrator hasn't disabled it globally.
Feature request 3: make it possible to view a user's post history by clicking on their hashed IP, to determine wether a user is legit or a newbie spammer.
>inb4 no no no
I think these are decent requests and handy features that should be basic to any imageboard software.
1: that footer doesn't even exist and isn't required by the back-end. You can't edit any header through settings.

2: accountability is a matter for site owners, not board owners.

3: chans are meant to be anonymous, consequently mods are meant to moderate content and not users.
>You can't edit any header through settings.
Yes you can, it's called the Site title in the global settings. It would be logical to be able to edit the footer that way too.
>accountability is a matter for site owners
Hot boards that get a lot of users and posts have more chance of receiving abuse. It would make sense to disable TOR on a hot board while leaving it enabled on, for example, a meta board.
>mods are meant to moderate content and not users
Users are content and content is users. A thing as IDs exist, thus no imageboard is 100% anonymous. It would be a handy feature to see if a user is legit or not.
>Yes you can, it's called the Site title in the global settings. It would be logical to be able to edit the footer that way too.
That is only used in the title, not in the page. Is a completely different thing and required, because there must be something on the title.

>Hot boards that get a lot of users and posts have more chance of receiving abuse.
What kind of abuse?

>Users are content and content is users.
No they are not.

>A thing as IDs exist, thus no imageboard is 100% anonymous.
Ids are limited to threads so people can follow conversations better.

>It would be a handy feature to see if a user is legit or not.
Why would that matter? Either a post break the rules or it doesn't.

LYNXCHAN IS UNSAFE Cat 02/17/2019 (Sun) 13:07:39
Prevent XSS ! Context Based Encoding
Cross Site Scripting (XSS) is one of the most common but ignored types of attacks. Since Node.js is implemented with JavaScript, there is high-risk of developers introducing XSS vulnerabilities in the code. Output encoding is one of the best ways to prevent XSS attacks. Most view engines such as Jade provides built-in encoding mechanisms. But most important thing is that you should use appropriate encoding to based on the context. Following are some situations that you should use context specific encoding.

URL encode parameters which are appended as url parameters. URL encoding can be done using encodeURI() and encodeURIComponent()javascript built-in methods.
HTML encode parameters which are displayed in HTML. HTML encoding is provided by view engines such as jade as well as frontend frameworks like Angularjs. You also can explicitly do it from server side using htmlencode npm module.
CSS encode parameters which are used in element styles
why don't you post them on /g/
Because it's all made up shit by some schizo. Why do you think I didn't give a fuck about it? I'm still waiting for his "surprise". It's been over a month, how long is "soon"?


do I smell a java developer?
You know, I'm starting to think you are talking to your self at this point by pretending to be multiple people.
lynxchan is cool and all but the logo is kinda creepy, might put people off and prevent gaining more popularity

I.C.U.P Cat 01/24/2019 (Thu) 16:18:17 Id:2341d0 No. 693 [Reply]
Lets talk about IP's. Okay so where the fuck on lynxchan do you see someone's ip? Even logged in as root, i never see my ip or any posters ip. I notice settings about ip, but never seen an ip.
>>697 Like there is some great advantage to making people click on the embed link to see what the video title is? People learn to NEVER click on links for no reason as it could be something malicious. It would be so nice to see what the video is about without having to click in the embed link. Any kind of thumbnail would be cool so people have some idea of what the video is.
>>697 also why are you so quick to discontinue the placeholder FE? The default is great for smaller sites or sites with lots of text. You should keep it going and as an option for people instead of totally getting rid of it.
Because practically no one uses it and the work required to maintain it started to become more significiant. 90% of people pick up penumbra, so I decided to focus on a project that has much more relevance. Also mind you, I wasn't quick to discontinue it. This fe has been going on for over 3 years now.
It makes pages cleaner.
i suggest fetching the title name instead [optionally]

Cat 03/25/2019 (Mon) 12:06:13 Id:fc63df No. 754 [Reply]
not sure if there's a general suggestions thread but

one of the only real feature I prefer on vichan over lynx is the fact that you can paste a picture from your clipboard into the post. it seems to work on some modern social media shit. it can save a lot of time for the user but not sure if that would jibe with what you're trying to do or if it would be a priority.
ahh okay

as for what it is if you right click an image in your browser, it usually has an option to copy an image, or if you're in gimp or whatever you can ctrl+c and copy an image to your clipboard.

When you're in the reply box in vichan and you hit ctrl+v it will put that image into the files thing as clipboardimage.png.
I see.
idk if it's a feature or a mistake but if you press enter you post your Reply [meaning can't new line]

affects only the reply box on the top of the page, quick reply is ok
Ah yeah, you are right. I was confused by that the other day but didn't pick it up. I'll fix it real quick, I know what it is.
Alright, fixed on 2.1, master and lynxhub branches.

LynxChan Installation Tutorial Cat 01/06/2017 (Fri) 01:14:08 Id:e5d5f0 No. 385 [Reply]
This is for debian.

Pre-install: Make sure you've created a user account with sudo rights, and use it for the rest of the tutorial. Do not run lynxchan on the root account.

1. Install nodejs

curl -sL https://deb.nodesource.com/setup_6.x | sudo -E bash -
sudo apt-get install -y nodejs
sudo apt-get install -y build-essential

2. Install Mongodb
sudo apt-key adv --keyserver hkp://keyserver.ubuntu.com:80 --recv EA312927
echo "deb http://repo.mongodb.org/apt/debian wheezy/mongodb-org/3.2 main" | sudo tee /etc/apt/sources.list.d/mongodb-org-3.2.list
sudo apt-get update
sudo apt-get install -y mongodb-org

3. Install imagemagick

i dont fucking get what im supposed to do with domain.org?????????? is it a placeholder for my own domain? the symlink command isn't even working, and "sudo service lynxchan start" gives me "Failed to start lynxchan.service: Unit lynxchan.service not found."
If the lynxchan service wasn't found, you didn't run the root-setup script and asked for it to install the service.
Link broke.
it's not that complicated

A GUI proposition Николай Кучумов 02/13/2019 (Wed) 17:45:42 Id:f0f324 No. 722 [Reply]
I noticed you're developing a "fast" backend for an imageboard.
I'm a developer of a general-purpose GUI for an abstract imageboard.
Have a look at 4chan.org integration:
The project is hosted on GitHub:
If you're interested I could add support for `lynxchan` in that GUI.
Lynchan maker is a rude egotistical faggot who is too stupid to use ssl on lynxhub.com which puts everyone at risk of malicious injections. ON TOP of that is the fact that node.je is extremely unsafe in general, as is the mongo db. It is a honeypot and full of major security issues. Go ahead and work with the lynxchan maker... good luck with that. You will find out that he is a total faggot moron.
If you want security I suggest you leave for sshchan
(306.14 KB 593x540 798.png)
>11 commits
>no mention of why lynxchan is not secure
Cute. I won't even delete it.
>>740 Says the faggot who is too stupid to use ssl on lynxhub.com which puts every single visitor to that site at risk of malicious code injections. Fucking faggot.
have you heard of 4 chan x

2.2 Lou Skunt 03/16/2019 (Sat) 01:58:25
Will lynxchan ver 2.2 render penumbra useless?
Will lynxchan ver 2.2 render penumbra useless?
Much on the contrary, 2.2 will install penumbra as the default front-end from the setup script.

Why do you ask?
I asked because penumbra looks like shit on mobile phones. People use browsers from mobile phones. I was hoping that someone would make a decent front end. Thousands of people go to stupid php boards on mobile phones each hour like 4chan. But hey, let's fucking ignore the world trend of people using mobile to browse.
Oah, and your efforts to block people are so fucking stupid. Hey, dipshit. It is impossible to block people from a forum. Your time would be better spent learning some manners or making lynxchan moblile capable. Fucking douchebag.

Oah, and use ssl on this shitty site. Who would trust code from a jackass who is too fucking stupid to use a basic security measure like ssl. You OBVIOUSLY have no respect for other people's security. Fucking faggot douchebag.
If you want to submit patches to make penumbra work better on mobile, you are welcome.

This site is not meant to be heavily used. Feel free to stop posting here and instead use some other means of communication, like irc or e-mail.
>phone poster woes
who cares


no cookies?