All deployments
Peter Theill
deployed a security update
1 day ago
Peter Theill
deployed a performance improvement
1 day ago
Peter Theill
deployed a documentation update
1 day ago
Peter Theill
deployed a documentation update
3 days ago
Peter Theill
deployed a documentation update
3 days ago
Peter Theill
deployed a feature
3 days ago
Peter Theill
deployed a documentation update
3 days ago
Peter Theill
deployed a security update
3 days ago
3 days ago
🔒️ Blocks hold on the website too; reports only reach what the reporter can see
rule lives in the model (Donation#open_to?, a Comment validation), so any
future path is covered as well.
the owner, so they can't be used to find out that a draft exists.
- The web comment form and "ask for this item" now honour blocks, and the
rule lives in the model (Donation#open_to?, a Comment validation), so any
future path is covered as well.
- The web comment controller hides drafts like the donation page does.
- Reports of a draft listing, or of a comment on one, 404 for anyone but
the owner, so they can't be used to find out that a draft exists.
Peter Theill
deployed a documentation update
3 days ago
3 days ago
:shield: Report, block, filter and terms for user content; new privacy policy and terms; OpenStreetMap tiles
What App Review guideline 1.2 asks of an app with user content:
support straight away.
are hidden, their requests are withdrawn, and they can no longer ask for
or comment on the blocker's things.
descriptions and comments, in all seven languages.
post, comment or ask for things.
The privacy policy now names every service that handles data (Hetzner,
Resend, OpenAI for photo suggestions, the sign-in providers), how long data
is kept and how to delete an account; the terms state zero tolerance for
objectionable content and how reports are handled. Both are now in all
seven languages instead of English only.
Maps use OpenStreetMap's tiles, with the attribution they require, instead
of Carto.
- Reports of listings, comments and people (POST /api/reports), emailed to
support straight away.
- Blocks (/api/blocks): a blocked person's listings, comments and activity
are hidden, their requests are withdrawn, and they can no longer ask for
or comment on the blocker's things.
- A whole-word filter (config/content_filter.yml) on listing titles,
descriptions and comments, in all seven languages.
- App users must accept the terms (POST /api/me/accept_terms) before they
post, comment or ask for things.
The privacy policy now names every service that handles data (Hetzner,
Resend, OpenAI for photo suggestions, the sign-in providers), how long data
is kept and how to delete an account; the terms state zero tolerance for
objectionable content and how reports are handled. Both are now in all
seven languages instead of English only.
Maps use OpenStreetMap's tiles, with the attribution they require, instead
of Carto.
Peter Theill
deployed a performance improvement
3 days ago