[help] [img] [forum]
[Catalog] · [Search] [News]
[Return] [▼]
Posting mode: Reply
Post reply
Name
Email
Subject
Message
CAPTCHA CAPTCHA Challenge Click to refresh.
File
Password For post deletion.
Submit  
  • Helpful information is available in the visitor guide. Currently 28 unique user posts.
  • Supported file types are JPG, PNG and GIF.
  • Maximum file size allowed is 2MB.
  • Images greater than 250x250 will be thumbnailed.
  • Supported BBCode tags are b, code, i, pre, sjis, spoiler, s and u.

1789059400562.png
Share any feedback related to running Sriracha on alternative networks (Tor, etc.) by replying to this thread.

- Set noip=true to disable recording author IP addresses.
- Set identifiers=false to disable author identifiers, which are based on IP addresses.

I have designed Sriracha for maximum compatibility (no JavaScript or WebAssembly required, no external assets), but I do not run any instances of Sriracha outside of the public Internet. Thus, I need your help to identify any related issues or potential improvements.


i run srirarcha on tor

well, kind of, the main mode of accessing the site is over a clearnet domain that points to a reverse proxy that then proxies connections to the backend onion address, the site is also directly accessible over it's onion address as well, i haven't really noticed the software behaving any differently

the only issue, and this is not really tor specific but slow network specific, is that if you have the non-default stylesheet and you reload the page/open thread etc. the page will flash white while the css loads, which doesn't happen if you have the default stylesheet, but this is i feel a minor issue


tangentially related, since you brought up tor there is a problem when it comes to moderation of posts that might be coming from tor nodes, unlike most people, i actually want to avoid banning tor nodes, but since the IPs are hashed (i understand this is a deliberate design decision), there's no way of telling from what kind of network the posts are coming from, so i simply don't use the ban functionality at all

providing an option for the software to interface with ip databases that keep track of tor ips, and marking such ips could be useful (both for people who want to disable posting from tor nodes, and for people who want to avoid banning tor nodes), but not sure if this would go against your general design of keeping minimum client information, and this could be used after all to fingerprint users connecting over tor (but you could argue that people that use tor don't really care that others know that they are using tor, since tor exit node information is public and easily accessible)


>>146
Thanks for sharing this feedback.

> the page will flash white while the css loads

This should be fixed as of >>commit/e073131a8557089627de174d7eaa5afbf644cfc3 which shipped in v1.9.0. You don't have to reveal the exact version you are running, but please let me know if you are still seeing this issue when running v1.9.0+.

I will respond to your other point when I have the time later.


>>146
OK, I've thought about this a bit and have a proposed solution. A new option is added which allows specifying one or more text files containing IP addresses and / or IP address ranges in wildcard format. Sriracha will load IPs in these text files and whitelist them from being recorded to posts. This effectively turns on the noip option for specific IP addresses. Sriracha will monitor these files automatically for changes and update the IP address whitelist. This allows the use of third party tools to download and update the files rather than introducing too much additional complexity to Sriracha. Let me know if this would resolve the issue. I am glad to discuss alternatives, this is just what first comes to mind.


>>148
So I guess I could then tell from the posts that don't have identifiers present that these are tor exit nodes (if that's the data I provided). Yeah, I guess that could work, but I thought more about and it's such a niche application very few people would use it, so honestly probably not worth your time to implement it. I like the idea of Sriracha being fed IP lists and then doing something with them, though.


>>150
I appreciate the follow-up, but I too think this feature could be useful. I've expanded the scope slightly to supporting whitelisting and blacklisting IP addresses and ranges via text files. Tracking issue:

>>issues/152


>>150
This feature is now supported, starting with Sriracha v2.1.3.