Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

VSP self-hosted captcha upgrade progress #326

Open
19 of 25 tasks
xaur opened this issue Apr 5, 2019 · 12 comments
Open
19 of 25 tasks

VSP self-hosted captcha upgrade progress #326

xaur opened this issue Apr 5, 2019 · 12 comments

Comments

@xaur
Copy link

xaur commented Apr 5, 2019

This issue tracks VSP upgrade progress to close exposure of their users to Google recaptcha.

Updated 2020-03-23.

Other issues:

@xaur
Copy link
Author

xaur commented Apr 5, 2019

Additionally, during testing it was discovered that https://dcrpool.dittrex.com/ also calls Twitter to load widgets. Shame!

@xaur
Copy link
Author

xaur commented Apr 16, 2019

https://dcr.farm/ is upgraded but it hits fonts.googleapis.com

edit: the font is now self-hosted (2019-04-19), but a hit to coinmarketcap.com remains

@jholdstock
Copy link
Member

dittrex and tokensmart upgraded
pos.dcr.fans doesnt have recaptcha

@xaur
Copy link
Author

xaur commented May 27, 2019

@jholdstock thanks, updated checklist. I think you have perms to edit the top comment too.

pos.dcr.fans still hits google.com and gstatic.com to load recaptcha. decred.raqamiya.net had 502 Bad Gateway when I checked.

@jholdstock
Copy link
Member

Tried editing the top comment but couldn't. Two updates

@xaur
Copy link
Author

xaur commented Jul 31, 2019

@jholdstock just tried https://pos.dcr.fans/signup and it tried to load recaptcha, it is also in the page source.

Moved raqamiya to Other section.

It's weird you can't edit other's issue descriptions because I can in my repos. Not sure what permission level that requires though.

@jholdstock
Copy link
Member

You're correct about pos.dcr.fans. Strange how it is never displayed.

Probably because you dont own this repo, its permissions will be set by the github.com/decred organisation

@chappjc
Copy link
Member

chappjc commented Aug 10, 2019

Wow, their site is still broken. No signups for weeks and they haven't noticed...

@JoeGruffins
Copy link
Member

JoeGruffins commented Jan 30, 2020

@xaur
Copy link
Author

xaur commented Jan 31, 2020

Indeed. Updates:

  • Removed d1pool, grassfed and dcr.fans. They were removed from dcrwebapi and are no longer listed. I'm surprised GrassFed failed to keep their VSP up.
  • idcray and decredbrasil load fine for me.
  • megapool and stakepool.eu are the only remaining VSPs that load Google recaptcha.
  • The new 99split.com hits googletagmanager.com, added to Other Issues
  • raqamiya hits Google fonts and coinmarketcap, added to Other Issues.
  • decred.yieldwallet.io looks ok.
  • dcr.farm no longer hits 3rd party domain, at least their VSP site.

I think as soon as the remaining 2 VSPs get rid of the recaptcha we can close this issue since recaptcha is the biggest problem (imo), and move "Other Issues" to a new issue.

@jholdstock
Copy link
Member

I've just noticed that dcrpool.dittrex.com is using sendgrid for their emails which seems odd.

For an example, try signing up with a temporary email and look at the email sender and the registration URLs included in the body

@xaur
Copy link
Author

xaur commented Mar 23, 2020

Updated the issue to add the use of sendgrid by dittrex. As of writing their page shows 502 and last update on our VSP page is 18 hours ago.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants