leeola has quit [Quit: Connection closed for inactivity]
OatWalker has joined #sandstorm
OatWalker has quit [Client Quit]
bodisiw has joined #sandstorm
prettyvanilla_ has quit [Ping timeout: 240 seconds]
prettyvanilla_ has joined #sandstorm
bodisiw has quit [Quit: Leaving]
prettyvanilla has joined #sandstorm
prettyvanilla_ has quit [Ping timeout: 255 seconds]
prettyvanilla has quit [Read error: Connection reset by peer]
jemc has quit [Ping timeout: 255 seconds]
jemc has joined #sandstorm
Tryum has quit [Ping timeout: 256 seconds]
KooBaa has joined #sandstorm
KooBaa has quit [Ping timeout: 260 seconds]
prettyvanilla has joined #sandstorm
Tryum has joined #sandstorm
prettyvanilla has quit [Ping timeout: 240 seconds]
prettyvanilla has joined #sandstorm
ill_logic has joined #sandstorm
ill_logic has quit [Read error: Connection reset by peer]
<ocdtrekkie>
mrdomino: strugee: Just FYI, kentonv may or may not respond much this week.
<ocdtrekkie>
FWIW, strugee, every page of Sandstorm code says it is copyright "Sandstorm Development Group, Inc. and contributors"
<ocdtrekkie>
The Collections app just says copyright "Sandstorm Development Group, Inc."
<ocdtrekkie>
I would guess there is a strong evidence in that to say the company owns the copyright of code written by employees. Although since all of it is published under permissive open source licenses, it's debateable how relevant that fact is from a practical sense.
nwf has quit [Ping timeout: 255 seconds]
nwf has joined #sandstorm
FredFredFred_ has joined #sandstorm
FredFredFred has quit [Ping timeout: 260 seconds]
FredFredFred has joined #sandstorm
FredFredFred_ has quit [Ping timeout: 240 seconds]
KooBaa has joined #sandstorm
KooBaa has quit [Ping timeout: 260 seconds]
FredFredFred_ has joined #sandstorm
FredFredFred has quit [Ping timeout: 268 seconds]
zopsi has quit [Ping timeout: 260 seconds]
zopsi has joined #sandstorm
Mitar has quit [Ping timeout: 240 seconds]
prettyvanilla has quit [Ping timeout: 240 seconds]
FredFredFred has joined #sandstorm
FredFredFred_ has quit [Ping timeout: 240 seconds]
jemc has quit [Ping timeout: 255 seconds]
xet7 has joined #sandstorm
dxf has joined #sandstorm
dxf has left #sandstorm [#sandstorm]
prettyvanilla has joined #sandstorm
prettyvanilla has quit [Ping timeout: 268 seconds]
<TimMc>
BASE_URL and WILDCARD_HOST used to end with :6443, because I had the router set to pass 6443 on the inet side to 6443 on sandstorm.
<TimMc>
I've changed the router to *also* pass 443 external to 6443 on sandstorm, and I was hoping that sandstorm would just issue redirects when called with a URL bearing the old 6443 port.
nwf has quit [Ping timeout: 255 seconds]
nwf has joined #sandstorm
<TimMc>
On another note -- it makes me a little nervous that the email token signup flow allows the client to control the URL sent out in the login email.
<dwrensha>
I think it used to at one point, but we fixed that
<TimMc>
Still does.
<TimMc>
I noticed because my server is listening on two ports, and signing in on one port vs. the other generates different URLs.
<TimMc>
*Could* be wrong, I can check more...
<dwrensha>
oh, I was thinking about the share-by-email form
<dwrensha>
... where the email goes to a different person
<dwrensha>
what you describe sounds weird, but I'm not sure there's anything serious to be nervous about
<TimMc>
Mildly nervous. :-P
<dwrensha>
you can send yourself an email that points to an arbitrary URL? does not sound too dangerous
<dwrensha>
you can cause login emails to get sent to other people, but presumably they will be ignored as spam
<TimMc>
You can send someone else what looks like a login email to a sandstorm server, but actually goes to your server. Then you harvest the login token and use it. (Or does it need to be combined with a cookie?)
<TimMc>
(Nope, it doesn't.)
<dwrensha>
hm interesting
<dwrensha>
TimMc: do you want to submit a pull request to fix this?
<dwrensha>
it should be easy to detemine the correct rootUrl on the server side without getting it from the client
<TimMc>
Can't, even though it's probably a one-liner. Have to get back to work, and I've never built sandstorm. :-/