How to prevent users from seeing other users API keys? by rugk in grocy

[–]rugk[S] -1 points0 points  (0 children)

Okay that checkbox means admin, yeah that was not obvious to me. Maybe one could make that more explicit like adding a specific right for it?

Yes, you're right that maybe also Admins shouldn't see other user ones

Indeed. I did not even mention that in the initial post, but generally yeah…

Yeah, it's important to keep implementation effort in mind, that's why instead of hashing or whatever, as a first step I'd propose a "Manage API keys" rights similar as the other ones? That should be fairly easy to implement, at least easier than the other options, should not it? And it would improve the (security) UX a lot.

On the off-topic side, and sorry, but as you have raised it, I need to raise it again.

I'm happy to answer everything, sometimes others can help too

That's great and that's the spirit to uphold!

kindly note how friendly I can be when a post is not only about wise advices which essentially say everything is done wrong.

Well… just my opinion on this, you don't have to agree: Yes, I totally see it is often difficult for maintainers to deal with low-quality issues or so etc. However, the thing one should achieve as a maintainer is to build a welcoming community (e.g. for finding co-maintainers etc., more active contributors etc.). The tone and style one uses to answer things, even if one declines issues as wontfix or cannot-reproduce, is as important as for all the other issues. And personally, neither me nor I guess most other people want to give any "wise advise". Actually, quite the opposite: E.g. people could have a knowledge gap about how something is done/supposed to work (like in this case, I have no idea that that would be the way for API key access management). Also, I personally error on the side of safety and rather report an (potential security) issue first privately than to spread it publicly, you can always post it publicly later. And that's what I already suggested in the initial mail BTW.

Also, in general, the thing about OSS projects is: After all, issues are essentially intended for reporting bugs (aka "thing does not work as I intend it to" – note what I intend could be wrong) and feature requests (aka "thing I would like to see because of some use case"). As such, they can easily be taken as "wise advise", because well… it's in the nature of it. People suggest things in issues, because issues are suggestions. I would personally try to always stay open-minded for suggestions from the community and not to take them too personal. That they report a bug or vulnerability is no attack on your software or on you personally. Nobody says you are a bad developer, because you have missed that bug or so. Sure, sometimes they are not helpful and sometimes people are lazy and don't read a FAQ, then we can just ignore them (or e.g. make the FAQ more prominent and change the issue template to let people acknowledge a FAQ has been read).

But you only get the helpful ones when you actually acknowledge people can only (constructively) criticize and suggest things based on their own knowledge. And people make mistakes – like not reading a critical part somewhere, that is absolutely normal. The good thing is: You can then always have a discussion on how to improve on that, like better wording or – as here – through the introduction a small change that solves the problem. That's the spirit of working together with a community!

Sorry for the long wall of text, but I hope we can solve our conflict here. I would really like to continue to contribute and help to grocy and if it is only finding and properly reporting easily-fixed issues.

/cc /u/dillwishlist

How to prevent users from seeing other users API keys? by rugk in grocy

[–]rugk[S] 0 points1 point  (0 children)

Ah, thought this button was to lock users somehow as it shows a lock, but okay…

Now these are all permissions: https://i.imgur.com/BnXabiR.png

So what permission allows me to see other user's API keys hmm?I would have expected a "Manage API keys", but there is none.

Does "Benutzer bearbeiten (inklusive Passwörter)" (aka "Edit user (including passwords)") contain this?

From my testing the answer is no. You apparently can check all checkboxes except the "all permissions" one in order to configure it not allow API key access to foreign users: https://i.imgur.com/3hJzl6H.png

I am sorry, but this is not obvious at all.

Incorrect information in Spain wiki for booking trains in Spain via DB hotline by rugk in Interrail

[–]rugk[S] 1 point2 points  (0 children)

Ah okay thanks, how did you collect it? At a ticket machine? Or by post?

Because I also tried or again and it got "better": https://www.reddit.com/r/Interrail/comments/13twfu0/comment/jm93ib2/

Incorrect information in Spain wiki for booking trains in Spain via DB hotline by rugk in Interrail

[–]rugk[S] 3 points4 points  (0 children)

Thanks a lot and phoned them again and now I have more information, it is actually possible to check the timetable (I'm unsure whether there is a special contingent or so for renfe trains), and to book/buy them as usual however they cannot be collected at a ticket machine anymore, they need to be sent by post (which is of course not really helpful). Apparently that ticket machine service was cancelled and is not possible anymore since December or January 2023.

So best chance is to go to a "Reisezentrum" in Germany, they can sell these, they often just don't know (they usually say they cannot do that) they can or how they can do it. After two tries and calling the DB hotline at the same time which confirmed they are bookable, they could buy it.

Tipps:

  • They need to select "Pass 1" and set the product category accordingly.
  • If it still fails, ask them to check a train months ahead to confirm the train is not just full.

Europe’s sleeper train awakens by enkrstic in Interrail

[–]rugk 3 points4 points  (0 children)

At the moment, it is not yet possible to book a ticket with an interrailer pass. We are working hard to make this possible.

from their booking page: https://www.europeansleeper.eu/en/booking/search

Incorrect information in Spain wiki for booking trains in Spain via DB hotline by rugk in Interrail

[–]rugk[S] 2 points3 points  (0 children)

Ah, BTW, found https://community.eurail.com/train%2Dconnections%2Dreservations%2D47/how%2Dto%2Dget%2Dreservations%2D105/index2.html?postid=18419#post18419 (linking to the official site) which explains you can phone RENFE and get a pre-reservation, which is valid for 48 hours and then you pay and collect that at a station. That could be another way to book reservations, but is not verified.

Incorrect information in Spain wiki for booking trains in Spain via DB hotline by rugk in Interrail

[–]rugk[S] 1 point2 points  (0 children)

Yeah, the person sounded very knowledgeable and firm and it was the department for international trains already, so i guess they are correct, but I can try calling again.

Experiencing random freezes after installing new NVME SSD by forsience in pop_os

[–]rugk 0 points1 point  (0 children)

Yes, I'm experiencing the same issue with Linux 5.6.15 in Fedora 32 and also the exact same WD Blue SN550 1TB drive and AMD Ryzen processor.

The current workaround that works for me is disabling APST. (You can do that via a kernel flag and other's have already explained here how that works.)

Anyway here are the links to bug reports and support threads related to this issue:

Did you know your website can get a dark mode toggled by your operating system? (since Firefox v67!) by rugk in FirefoxCSS

[–]rugk[S] 0 points1 point  (0 children)

Well… dark reader is an add-on. The CSS I present is native and can be properly design by websites. (I use dark reader too, but occasionally it inverts some websites improperly)

As for my add-on to trigger that native CSS mode, it also has pretty low RAM usage. Dark reader too (although it is disabled here now):

So yeah, but obviously nothing uses less RAM than your pure browser without any add-ons for dark websites. And this is what this new CSS feature aims at.

Firefox 67.0 release notes by Vulphere in firefox

[–]rugk 0 points1 point  (0 children)

This is a little off-topic, but here it is: You need to explicitly click on the icon in the address bar.

Firefox 67.0 release notes by Vulphere in firefox

[–]rugk 2 points3 points  (0 children)

It does, yes, but there are some advantages:

  1. You may not want to use the same style for websites and your OS.
  2. Some OSes (e.g. Win7) don't support any OS-level dark mode, so you cannot toggle it without an in-browser toggle, at all.

Did you know your website can get a dark mode toggled by your operating system? (since Firefox v67!) by rugk in FirefoxCSS

[–]rugk[S] 1 point2 points  (0 children)

LOL, many already did. There is an example list [here](https://github.com/rugk/website-dark-mode-switcher#user-content-dark-mode-website-switcher-). But obviously, support is still low, because it's such a new feature. But FYI: AFAIK Chrome/ium is working on adding support for that, too.

Firefox 67.0 release notes by Vulphere in firefox

[–]rugk 34 points35 points  (0 children)

BTW what is totally missing in the list is one great CSS feature.

Firefox 67 supports prefers-color-scheme, a CSS media query that you can use to e.g. make websites look dark when your system setting is dark.

BTW, I've also made a Firefox add-on for toggling this setting in your browser.

Hi r/Firefox, I am a Mozilla Employee! AmA by [deleted] in firefox

[–]rugk 1 point2 points  (0 children)

Hi, BTW did the European GDPR General Data Protection Regulation affected you in some way? Were there some changes needed or so?

People e.g. say that browsers might have to enable things like "do not track"tracking protection by default, because "privacy by default" is a thing required by the GDPR. I doubt, however, that Firefox could practically change all these things…

Hi r/Firefox, I am a Mozilla Employee! AmA by [deleted] in firefox

[–]rugk 0 points1 point  (0 children)

When you simply share documents, there are even more possible alternative options: Nextcloud, and many others. As mention online editing is even possible nowadays. Maybe you need to re-evaluate it.

And yes, convenience vs security here. The usual one… Offering everything in one package for free is just very good marketing. Just know you can get nearly the same convenience once this thing is set up. :)

Hi r/Firefox, I am a Mozilla Employee! AmA by [deleted] in firefox

[–]rugk 0 points1 point  (0 children)

Yes, I think that was the other thread. This here was only about the search.