• Fixed Markdown pasted into the rich text editor appearing as plain text instead of formatted content.
  • Fixed a server-side request forgery in profile and image resolution. DID documents, PDS endpoints, handles, and member avatars and images now go through the same hardened, address-vetted fetcher the extension system already used, so a crafted DID document or handle can no longer make the server read from the shard's own network through member pages or Open Graph images.
  • Avatar and webring redirects now refuse to send a browser to a host that resolves onto the shard's own network, and the webring only redirects to a syntactically valid handle.
  • bun run check now typechecks the whole app, not just the generated lexicon code, and runs svelte-check so .svelte components are covered too. TypeScript is pinned to 6.0 because SvelteKit's type generator does not yet support TypeScript 7.

Hi, I'm Keith! You can @ me with any bugs or problems or ideas, but pls be nice.

have something to add?

Jump into the conversation.

Already use Bluesky, Leaflet, or another app on the network? You already have an atmosphere account. Log in with it here to add your reply—there's no separate forum account to create.

What's an atmosphere account?

It's an account that works across Bluesky, Leaflet, and other apps on the same network. You can use that account here too.

some apps on the network
Bluesky Leaflet Surf Spark pckt PDSls plyr.fm Tangled BookHive Grain
create an account on Bluesky →