512f6de6de
* feat: allow passwords longer than 73 characters Context: A bcrypt/blowfish limitation means that password length is capped at 72 characters. We can get around this without compromising on security by hashing all incoming passwords with SHA512, and then sending that to bcrypt. https://dropbox.tech/security/how-dropbox-securely-stores-your-passwords * feat: add additional test for passwords > 73 chars * fix: remove 'password-too-long' error message and all invocations * test: added test to show that a super long password won't bring down NodeBB * fix: remove debug log * Revert "fix: remove 'password-too-long' error message and all invocations" This reverts commit 1e312bf7ef7e119fa0f1bd3517d756ca013d5e79. * fix: added back password length checks, but at 512 chars As processing a large string still uses a lot of memory |
4 years ago | |
---|---|---|
.github | 4 years ago | |
.tx | 4 years ago | |
build | 7 years ago | |
install | 4 years ago | |
logs | 11 years ago | |
public | 4 years ago | |
src | 4 years ago | |
test | 4 years ago | |
.codeclimate.yml | 6 years ago | |
.editorconfig | 10 years ago | |
.eslintignore | 4 years ago | |
.eslintrc | 5 years ago | |
.gitattributes | 10 years ago | |
.gitignore | 4 years ago | |
.jsbeautifyrc | 11 years ago | |
.jshintrc | 6 years ago | |
.mocharc.yml | 5 years ago | |
CHANGELOG.md | 4 years ago | |
Dockerfile | 5 years ago | |
Gruntfile.js | 5 years ago | |
LICENSE | 12 years ago | |
README.md | 4 years ago | |
app.js | 5 years ago | |
commitlint.config.js | 4 years ago | |
docker-compose.yml | 5 years ago | |
loader.js | 4 years ago | |
nodebb | 7 years ago | |
nodebb.bat | 6 years ago | |
renovate.json | 4 years ago | |
require-main.js | 6 years ago |
README.md
NodeBB Forum Software is powered by Node.js and supports either Redis, MongoDB, or a PostgreSQL database. It utilizes web sockets for instant interactions and real-time notifications. NodeBB has many modern features out of the box such as social network integration and streaming discussions, while still making sure to be compatible with older browsers.
Additional functionality is enabled through the use of third-party plugins.
- Demo
- Developer Community
- Documentation & Installation Instructions
- Help translate NodeBB
- NodeBB Blog
- Premium Hosting for NodeBB
- Follow us on Twitter
- Like us on Facebook
Screenshots
NodeBB's theming engine is highly flexible and does not restrict your design choices. Check out some themed installs in these screenshots below:
Our minimalist "Persona" theme gets you going right away, no coding experience required.
How can I follow along/contribute?
- If you are a developer, feel free to check out the source and submit pull requests. We also have a wide array of plugins which would be a great starting point for learning the codebase.
- If you are a designer, NodeBB needs themes! NodeBB's theming system allows extension of the base templates as well as styling via LESS or CSS. NodeBB's base theme utilizes Bootstrap 3 but themes can choose to use a different framework altogether.
- If you know languages other than English you can help us translate NodeBB. We use Transifex for internationalization.
- Please don't forget to like, follow, and star our repo! Join our growing community to keep up to date with the latest NodeBB development.
Requirements
NodeBB requires the following software to be installed:
- A version of Node.js at least 12 or greater (installation/upgrade instructions)
- MongoDB, version 2.6 or greater or Redis, version 2.8.9 or greater
- nginx, version 1.3.13 or greater (only if intending to use nginx to proxy requests to a NodeBB)
Installation
Please refer to platform-specific installation documentation
Securing NodeBB
It is important to ensure that your NodeBB and database servers are secured. Bear these points in mind:
- While some distributions set up Redis with a more restrictive configuration, Redis by default listens to all interfaces, which is especially dangerous when a server is open to the public. Some suggestions:
- Set
bind_address
to127.0.0.1
so as to restrict access to the local machine only - Use
requirepass
to secure Redis behind a password (preferably a long one) - Familiarise yourself with Redis Security
- Set
- Use
iptables
to secure your server from unintended open ports. In Ubuntu,ufw
provides a friendlier interface to working withiptables
.- e.g. If your NodeBB is proxied, no ports should be open except 80 (and possibly 22, for SSH access)
Upgrading NodeBB
Detailed upgrade instructions are listed in Upgrading NodeBB
License
NodeBB is licensed under the GNU General Public License v3 (GPL-3) (http://www.gnu.org/copyleft/gpl.html).
Interested in a sublicense agreement for use of NodeBB in a non-free/restrictive environment? Contact us at sales@nodebb.org.