hello. i'm a happy user of lemmy.today.

i've always used the mlmym frontend available on old.lemmy.today, it generally works well enough. however, there are some minor minor bugs and missing features. (e.g. impossible to navigate to next page when viewing saved posts, impossible to see down/upvotes separated)

i recently came across this fork of mlmym (from this github issue) and it seems to have all those bugs fixed. can we replace the current mlmym with this fork?

thanks for reading

you are viewing a single comment's thread
view the rest of the comments
[–] 2 points 2 months ago* (last edited 3 weeks ago) (2 children)

Hello! I'm the person who made that fork.

If it does get set up here and you have any questions or run into any issues (which could very well happen, as I've done some major refactors), feel free to contact me, either by email at mlmym@lists.mschae23.de or in the #mlmym:mschae23.de matrix room.

You can also try it out already at discuss.mschae23.de (only logged-out here, of course, which doesn't give you all options) or by running it up locally with LEMMY_DOMAIN set to lemmy.today.

I'd also recommend enabling some of the options instance-wide by default, especially SHOW_UNREAD_COMMENTS (this one has been really useful for me).

  • source
  • hideshow 4 child comments
  • [–] 2 points 2 months ago (1 child)

    I wanted to ask you also if you could forward certain http headers to lemmy when it makes a request? Currently it doesnt forward them so lemmy thinks all the requests from mlmym to lemmy are from the docker ip its running on. And that makes it much harder to rate limit or ban bots since all requests are from the docker ip.

    So basically, mlmym should preserve and forward X-Real-IP, X-Forwarded-For, X-Forwarded-Proto, and X-Forwarded-Host when proxying API/backend requests to Lemmy, because Lemmy uses these headers for correct client IP detection and rate limiting.

    Something like this in the code where the incoming request is handled:

    const forwardedFor = request.headers.get("x-forwarded-for");
    const realIp =
      request.headers.get("x-real-ip") ??
      forwardedFor?.split(",")[0]?.trim();
    
    const headers = new Headers(request.headers);
    
    if (forwardedFor) {
      headers.set("x-forwarded-for", forwardedFor);
    }
    
    if (realIp) {
      headers.set("x-real-ip", realIp);
    }
    
    headers.set("x-forwarded-proto", request.headers.get("x-forwarded-proto") ?? "https");
    headers.set("x-forwarded-host", request.headers.get("host") ?? "");
    

    That would really help a lot and allow me and others to remove a lot of complicated workarounds for trying to get the source ip.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 1 point 2 months ago (1 child)

    I have some handling for X-Forwarded-For, but none of the others. This could actually explain why I was still seeing rate limit errors despite not having made many requests from my IP address.

    I'm unfortunately busy this week, but I hope I can still find some time in the next few days to implement this.

    headers.set("x-forwarded-proto", request.headers.get("x-forwarded-proto") ?? "https");

    Shouldn't that fallback be http, since mlmym doesn't do HTTPS itself? And I assume the reverse proxy will have set X-Forwarded-Proto to https.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 2 points 2 months ago (1 child)

    Yeah, I have a custom setup currently just to try and get the source ip, but it doesn't work properly in all cases. And most of the bots use old.lemmy.today since they know mlmym doesn't forward the source ip address, and therefore it's hard to rate limit them.

    So it would be amazing if you could forward those 4 headers. Then I will setup nginx to forward those headers to mlmym, and mlmym will forward them when making a request to Lemmy.

    I actually thought it was making a https connection to Lemmy but perhaps it doesn't, and nginx just forwards http to https. Not sure. Will have to look into this more.

    But yeah, whenever you have time to add the headers, i will investigate more. Not super urgent but will be interesting to play with that later. And it will protect all Lemmy instances that use your fork, so thats good.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 2 points 2 months ago (2 children)

    Then I will setup nginx to forward those headers to mlmym

    If you configure it to set X-Forwarded-For, you should have at least that information now already.

    I actually thought it was making a https connection to Lemmy but perhaps it doesn't

    That depends on the setup. If you haven't already, you should definitely set LEMMY_INTERNAL_URL so that mlmym connects to lemmy directly without TLS or a reverse proxy, which should be a lot faster (but that's only possible if they're running on the same machine, of course).

    X-Forwarded-Proto is supposed to say what protocol the user (of mlmym) originally connected with though, right? Which will still end up being https in the common case of it being behind a reverse proxy that does TLS.

  • source
  • parent
  • hideshow 4 child comments
  • [–] 2 points 2 months ago (1 child)

    I ended up using the external nginx for setting rules for rate limiting and such, and there I see the real ip. It's before traffic even gets to mlmym so that's good.

    Also made sure to make it use the internal Lemmy url and skip a lot of the proxy stuff I was using earlier. It seems faster now.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 2 points 2 months ago (2 children)

    I implemented the headers today, so version 26.2.1 should hopefully do this correctly now.

    I could only really test it in my deployment, so feel free to let me know if you have any issues!

  • source
  • parent
  • hideshow 4 child comments
  • [–] 2 points 1 month ago

    It works! I discovered way too late that lemmy was rate limiting traffic from mlmym, because it wasnt part of my nginx config. It was lemmy itself that was doing rate limiting since all requests came from the same docker ip.

    But forwarding the real ip headers fixed that, so very good. Huge thanks!

  • source
  • parent