Piped icon indicating copy to clipboard operation
Piped copied to clipboard

New DE instance (Whatever Tinfoil)

Open privacytime101 opened this issue 2 years ago • 10 comments

Describe your question

New instance on a separate server in Nuremburg, Germany. I run the whatever.social instance, but now I’m just giving the hardcore privacy enthusiasts an edition without Cloudflare and with better privacy laws. Jokingly named Whatever Tinfoil.

Frontend: watch.whatevertinfoil.de Backend: watchapi.whatevertinfoil.de Proxy: watchproxy.whatevertinfoil.de

privacytime101 avatar Sep 12 '22 04:09 privacytime101

Thank you, there seems to be some issues with icons not showing in player (Safari 16.0).

Screenshot 2022-09-13 at 06 11 59

bbsixzz avatar Sep 13 '22 04:09 bbsixzz

@bbsixzz Interesting, do you still have this issue when opening the page in a private tab? I just tested it and it was working. I think I fixed the CSP issue that was causing this yesterday.

privacytime101 avatar Sep 13 '22 04:09 privacytime101

Works in private mode but broken otherwise.

bbsixzz avatar Sep 13 '22 04:09 bbsixzz

@bbsixzz Alright, I'm guessing the headers were cached before the fix. For now, go to Settings>Safari>Advanced>Website Data, look for whatevertinfoil.de and swipe left to delete.

I'll look into a fix for some other users that have the earlier version cached soon.

privacytime101 avatar Sep 13 '22 04:09 privacytime101

Fixed, cheers!

bbsixzz avatar Sep 13 '22 04:09 bbsixzz

Hmm no bueno, once I login again it reverts back to the same problem eventually.

bbsixzz avatar Sep 13 '22 05:09 bbsixzz

@bbsixzz After trying different methods, hooking my phone up to a mac to frantically scroll through console logs and having tons of private tabs open, I was finally able to replicate it. The result wasn't what I was hoping for, and I was able to have the issue on both instances (only on Safari iOS).

TL;DR: Piped has a bug where it's requesting fonts from Google, we may just need to wait for Kavin to check it out. Try Yattee for now?

I'm not 100% sure this is the issue, but it'd make sense. Basically, I have a very restrictive Content Security Policy that only accepts connections from certain domains/file hashes. Yesterday, after months of using the default https://fonts.kavin.rocks to get fonts, Piped started instead making requests to fonts.gstatic.com (a Google service) which I believe is the source Kavin proxies from. I reported this to Kavin on Matrix then whitelisted gstatic because both my instance icons were breaking. The Safari logs are saying it's getting errors trying to connect to fonts.gstatic.com when the icons get like that, which... wouldn't be a thing if it's still using kavin.rocks. I mean, there's probably a root cause where it's Safari being goofy again, but I'd rather blame Google.

So I guess we could wait for @FireMasterK to investigate this? I'll try digging deeper myself soon. In the meantime though, I recommend checking out Yattee (linked in Piped's readme) and using the Testflight link. You can add this instance as a custom location with the details in the original post and sign in. This obviously isn't a fix, but it's better than nothing.

privacytime101 avatar Sep 13 '22 05:09 privacytime101

Yeah that makes sense, no sweat I'm just glad to help out.

I'm using Yattee on my iPhone and Apple TV, superb project :]

bbsixzz avatar Sep 13 '22 13:09 bbsixzz

@bbsixzz I think I may have fixed it, had the issue on Chromium and its logs actually report what's going on, so whitelisting fonts.gstatic.com in connect-src (which I forgot to do) probably solved it. The core issue of direct Google font usage is still a thing, though.

privacytime101 avatar Sep 15 '22 02:09 privacytime101

Yeah I think it's fixed now it hasn't reverted back, thanks!

bbsixzz avatar Sep 15 '22 02:09 bbsixzz

I'm having issues with the instance right now and a bit earlier, not able to load subscriptions and videos; doesn't work in Yattee Apple TV or iOS.

bbsixzz avatar Sep 24 '22 00:09 bbsixzz

@bbsixzz Yep, been having some issues today with API going down. Not sure why yet but I'm looking into it. Feel free to check the status at https://status.whatever.social.

Also, it'd probably be best if you reported the instance's issues at my Session (0588cff4c1a032b40514e8c9fb1a52124e9865953c0dd052563dce47a8c727256e) or Piped's public Matrix room.

privacytime101 avatar Sep 24 '22 00:09 privacytime101

(Closing as the instance has been taken offline afaik)

Bnyro avatar Jun 18 '23 18:06 Bnyro