• 0 Posts
  • 23 Comments
Joined 11 months ago
cake
Cake day: May 22nd, 2025

help-circle


  • … What artificial facade? Canada has a history as a country of brutal soldiers. For us the Geneva Convention is more of a checklist. We’re very polite: Surrendering Germans got a bullet to the head as a thank you.

    We had such a bad reputation the government shut down the Canadian Airborne Regiment (Our equivalent of the Marines) and pivoted us into a peacekeeping role to change perceptions.

    We have upcoming trade renegotiations, and pissing off the orange turd before they start just isn’t in the cards. We’ll support international efforts in a way that doesn’t piss off our brother to the south.



  • Canada and the US aren’t just allies, we’re tightly integrated militarily.

    It may look like two separate countries on the political stage, but behind the scenes we operate together. When Canadian personnel are already embedded in command structures in the region, it’s not realistic to expect Canada to fully denounce the conflict


    1. Fixed credential-exfiltration risk in /api/proxy/image: Previously the endpoint could:
    • accept arbitrary auth_id
    • load stored API keys
    • forward them to attacker-controlled URLs
    1. Enforced outbound host allowlist globally Previously:
    • allowlist existed
    • but outgoingFetch() didn’t enforce it
    • plugins/engines could bypass it
    1. Fixed extension store path traversal Previously a malicious store manifest could:
    • inject … paths
    • escape install directories
    • reference arbitrary files
    1. Hardened proxy IP trust Previously:
    • rate limiting trusted any X-Forwarded-For header
    • clients could spoof their IP
    1. Fixed inconsistent settings authentication Previously:
    • settings UI stored an auth token
    • but the settings modal didn’t send it when saving
    1. Implemented Improved proxy deployment support
    • Added proxy-aware behavior:
    • DEGOOG_PUBLIC_BASE_URL for canonical URLs
    • secure cookie handling when X-Forwarded-Proto=https

    Additional Improvements:

    • suggestion fetching hardened
    • DuckDuckGo suggestion parsing fixed
    • unified outbound request handling
    • install state guard properly cleaned up

    Made some other changes for my specific deployment. Very happy with your work so far. Thanks so much















  • I normally do full sized bars considering how many people we get on average. I normally buy them at Costco Business and it looks like they’re still priced the same. Prices at regular Costco are similar to what I remember of last year too.

    We probably make most of our chocolate here. In the area around where I work there are at least 4 Mondelez plants. I know Mars has a few plants in or around the GTA as well.