Skip Navigation

InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/„Initials” (https://github.com/dicebear/dicebear) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)EL
Posts
4
Comments
250
Joined
2 yr. ago

  • Not quite. If they had overlooked a few accounts, they'd probably not even implemented that function. They'd just said "well, if you forget your password - or need to change it - you need to use the forgot password workflow that sends an email. Everyone without an email Adresse associated with their account would be SOL.

    Since they implemented it, they are aware of such accounts. But since "providing freely any email address for a password reset" makes absolutely no sense, this should only work for this special case - accounts without an associated email address.

    Whether it's only done for unlocking accounts, whether this would have also worked when clicking on "Forgot Password" or whether this account lock and unlocking workflow might even be intentional to associate an email address to such accounts, is unknown (to me)

  • I think newer accounts can only be created, when providing an email address. There may be some old accounts that don't have an email address associated. So, in most cases, you'd just be able to restore the account if you have access to both the account password and the email address. This breaks apart, if there's no email address associated so I think they provided this way of recovery although it doesn't improve security since it only applies to very few accounts?

  • My newest vps runs with Caddy. Works like a charm. The downside was, that I didn't think of the automatic certificate deployment when I set everything up and it wouldn't come up a first when I only wanted to connect locally to it, as it tried to get a certificate but the challenge failed because I hadn't the firewall open yet. But besides that it was very smooth so far.

  • Amazon Deep Glacier is a lot cheaper for storage (but expensive for retrieval).

    I use Archive Storage in Oracle Cloud S3 for my dr backups which is their equivalent of AWS deep glacier archive. It's quite cheap, no restore fees, inbound traffic is free and outbound traffic is only paid, when you're using more than 10TB per month. (Also first 10 GB of S3 storage is free)

  • It's not the most detailed thing, but I just use a free account on cron-job.org to send a head request every two minutes to a few services that are reachable from the internet (either just their homepage or some ping endpoint in the API) and then used the status page functionality to have a simple second status page on a third party server.

    You can do a bit more on their paid tier, but so far I didn't need that.

    On the other hand, you could try if a free tier/cheap small vps on one of the many cloud providers is sufficient for an uptime Kuma installation. Just don't use the same cloud provider as all other of your services run in.