Good morning everyone. Fixed a NostrGram vulnerability bug that allowed somebody to add javascript into a tag in a note. Refresh the page to get the update.

Reply to this note

Please Login to reply.

Discussion

GM, nice work!

so the staff that I saw earlier today was because of that?!

If you saw anything pop up on the screen that looked out of place or had unusual text etc that's what it was. Fixed now.

GMGM ๐ŸŒž๐Ÿ”ฅ๐ŸŒž

GM ใŠใฏใ‚ˆใ†โšก

Currently, nostrgram has not released its code to the public, and some Japanese users are concerned that their private keys may have been stolen.

Sorry if this is a mistake.

็พๅœจnostrgramใฏใ‚ณใƒผใƒ‰ใŒๅ…ฌ้–‹ใ•ใ‚ŒใฆใŠใ‚‰ใšไธ€้ƒจใฎๆ—ฅๆœฌใƒฆใƒผใ‚ถใƒผใ‹ใ‚‰็ง˜ๅฏ†้ตใŒ็›—ใพใ‚Œใฆใ„ใ‚‹ใฎใงใฏใชใ„ใ‹ใจๅฟƒ้…ใฎๅฃฐใŒไธŠใŒใฃใฆใ„ใพใ™ใ€‚

#[2]

NostrGram only stores private keys in the browser memory but I strongly encourage people to use a Nip07 browser extension.

What about mobile version of safari?

I'm not sure if Safari has any Nip07 extensions on mobile.

OK๐Ÿ™†

Is the code publicly available? If not, how can I check?

No it's not open source.

ใ”ๅ›ž็ญ”ใ‚ใ‚ŠใŒใจใ†ใ”ใ–ใ„ใพใ™๐Ÿ––

Thanks for the reply. I'm rooting for you.

๐Ÿค™

#[0]

Hi, jleger. I sent DM about your app. Please check when you can.

I didn't get the DM.

Sorry, I will resend after my relay configuration

Sent again. Please check.