This release fixes a security vulnerability which allows an attacker to delete images uploaded by other users. You can read the details in the security advisory. Thanks to @Nothing4You for discovering and fixing it.

A new donation dialog is shown to users once per year, to help fund Lemmy development.

There are also various backports from the development branch. Importantly the “Private instance” setting can now be used with federation enabled. This way only logged-in users can browse posts and comments, which stops AI crawlers from overloading the server. Also moderators can now view votes in the post/comment options.

  • orbituary@lemmy.dbzer0.com
    link
    fedilink
    arrow-up
    3
    ·
    12 days ago

    What’s the benefit of seeing how people vote? Feels a bit invasive to me. It also feels like it has the potential for abuse in the wrong hands.

    • Fitik@fedia.io
      link
      fedilink
      arrow-up
      4
      ·
      12 days ago

      You can already see votes if you’re using different software anyways, check how it looks on my mbin instance, I can click “Activity” and see it already.

        • Fitik@fedia.io
          link
          fedilink
          arrow-up
          5
          ·
          12 days ago

          Yes, but Kbin used to show downvotes too. I don’t think there should be an illusion that they’re private, while they can be exposed.

          • Coelacanth@feddit.nu
            link
            fedilink
            arrow-up
            4
            ·
            edit-2
            12 days ago

            God I remember the debates about this back around the API exodus when Kbin still existed. Even though anyone can technically access vote information by spinning up their own instance that barrier is sufficient for most users. I don’t think making voter info completely publicly visible is a good reaction to the fact that it’s “technically public anyway”. I don’t think being able to see exactly who voted what on your posts and comments leads to anything good, neither for the environment as a whole nor for you as an individual.

            EDIT: This is for regular users, I obviously don’t have a problem with mods and admins having access to this data as it’s probably a necessary moderation tool.

            • BentiGorlich@gehirneimer.de
              link
              fedilink
              arrow-up
              7
              ·
              12 days ago

              They are just hidden, but I think no one has access to them via UI. We also have a discussion issue going about respecting the visibility a like activity specifies.

              I am torn on this issue. Just because you theoretically can always spin up an instance and just collect the info that way one should not make it as easy as it is today (imo)… But the community seems to be heavily leaning towards @Fitik@fedia.io 's view

              • Blaze (he/him) @lemmy.dbzer0.comOP
                link
                fedilink
                arrow-up
                2
                ·
                12 days ago

                I’m okay with the way Lemmy implemented it in this version:

                • admins can see votes, but they can see everything anyway
                • mods can see votes, to help with brigading
                • users can’t see votes

                But I’m not an Mbin user, so that should probably be discussed with your users

                • Coelacanth@feddit.nu
                  link
                  fedilink
                  arrow-up
                  2
                  ·
                  12 days ago

                  That’s where I am as well, but if Mbin ever takes off we’ll see if our reservations about completely public votes were baseless fears.