julian
Co-Founder (NodeBB) | Husband 🤷♂️ and Dad 🙉 to three | Rock Climber 🧗♂️ | Foodie 🥙 | Conductor 🎵 | Saxophonist 🎷
✅ Small teams craft better code.
🇨🇦 Made in Canada
🗨️ Federating NodeBB with funding from NLNet ♥️🇪🇺
It is possible for NodeBBs to talk with each other. In fact, not only can two NodeBB forums see and share conversations, you can also connect with other websites that can federate.
This article is part of the NodeBB Answers category, where you can learn more about setting up, maintaining, and using your NodeBB forum. [...]
How does it work?
Under the hood, NodeBB uses a protocol called ActivityPub to exchange messages and activities between different websites and apps. Each user, category, topic, and post is able to be retrieved via this protocol, and users can follow each other in order to start seeing updates from another website.
How do I find other users and categories?You can search for them in the search bar and search pages. Users and categories are identified by their username or handle, which looks something like @handle@website.com.
For example, I (@julian) can be found by searching for @julian@community.nodebb.org, and this category (@answers) can be found by searching for @answers@community.nodebb.org.
From there, you can follow users (or watch/track categories) to start the flow of new content to you. It's like subscribing to a newsletter. You'll start getting the new stuff, but you won't be able to see the old stuff unless you already know about it.
Okay, I started following some people, where do I see their posts?Content from outside of the forum is all found inside the "World" page, accessible via /world. As new content comes in, it'll be shown in the feed-style timeline. Any remote categories you've started following will also show up in the sidebar for easy access.
Once you've found some categories from outside of the forum (aka "remote categories"), you can browse back to them from the /world page. If you've watched/tracked the category, you can access them from the sidebar. Otherwise you'll have to search for them from the remote category search bar within this page.
Once you're in a remote category, you can start a new topic via the "New Topic" button just like a regular category on your forum, and your topic will be sent to the remote category for syndication.
Remember to follow the rules of other communities, as they may not match rules on your forum.
Up until today, when you queried a NodeBB user or category's outbox, you would receive an empty OrderedCollection. This was done because the property's inclusion in the actor object was required, but it was not immediately apparent in 2024 how many people utilised this property. Thus it was easier to just send the empty outbox and pursue more urgent functionality.
While sending that empty outbox has not broken any implementations, but it has come to my attention that a few (read: more than 1) other implementors already do, or plans to, read from an actor outbox for backfill purposes.
The upcoming NodeBB v4.10.0 will contain an outbox populated by the contributions by that user or category.
Here's how that works...[...]
For both users and categories, a standard OrderedCollection is returned, with first, last, prev, and next properties for navigation.
For users:
- A combined set of the user's activity is returned in the form of activities (
Create,Like, etc.) — these activities include the user's posts, votes (both up and down), and shares. - Unlike other collections, this one uses a cursor. You can pass
?before=or?after=values in the query string to retrieve items 20 at a time.
For categories:
- A set of posts curated by this category is shown. It can contain both posts local to the instance, and remote posts from outside of the instance.
- All posts are wrapped in the
Announceactivity. If the post is local, it is anAnnounce(Create(Note/Article)), if it is a remote post, then it is just anAnnounce(Object)by reference. - This collection is paged like other collections served by NodeBB.
It is possible that this implementation serves data in an unexpected manner. If this is the case, please reply here to contact me directly so it can be fixed.
I used my best judgement for what to include in the outboxes, as well as using Piefed as a reference implementation. @rimu@piefed.social, I notice that Piefed's community outboxes serve up Announce(Create(Page)) even if the Page is not local to the instance. I was under the assumption that remote content couldn't (shouldn't?) be expanded in this manner because you cannot guarantee the integrity of the data, and so announcing the object by reference is preferred. Just wondering your thoughts on that.
We are publishing a notice today to bring to attention an unintentional breaking change that could affect some users of NodeBB.
v4.5.0 contained an update to src/request.js that calls a DNS resolver to ensure that the destination address is not a reserved IP address (e.g. 192.168..., 127.0..)
This change was introduced in order to close off any potential for Server-Side Request Forgery for any calls made within the NodeBB codebase. [...]
In the vast majority of installations, this has no unintended effects. In some installations, custom plugins or themes may call URLs that resolve to an internal address on purpose (e.g. to query an internal database or similar.) In those situations, the call will now fail as of v4.5.0.
In those situations, you will need to update the plugin to add the domain to the allow list by calling the filter:request.init hook:
plugin.json
{
...
"hooks": [
...
{ "hook": "filter:request.init", "method": "allowInternalHostname" },
...
]
...
}
library.js or similar
const plugin = module.exports;
plugin.allowInternalHostname = async ({ allowed }) => {
allowed.add('example.org');
return { allowed };
});
Hi everybody,
With spring around the corner (it is currently a balmy 5°C here right now), it's time to get crackin' on a new release of NodeBB!
We focused on a lot of user experience updates this time around, along with tweaking the new /world page that was introduced in v4.9.0. In the backend, lots of optimizations were implemented, which make federation processing (and day-to-day maintenance) faster.
Here's what you can expect from v4.10.0...[...]
:globe_with_meridians: Updates to the/world page
The /world page got a makeover in v4.9.0, showcasing a more timeline-based feel. It more accurately represents the breadth of content available on the open social web, such as microblogging, in addition to long-form text (blogs), media-focused items, and everything in between.
We focused on UX updates to this page:
- New sorts are available: You can now view just local content, as well as all known content.
- The default sort continues to be "your followers", but also includes local content now as well, because you are also tracking those categories!
- Guests were barred from
/worldin v4.9.0, but this is now opened up again. Their view of the/worldpage shows only local posts. - The
/worldpage can now be set as a default home page. - Duplicate items were showing up when scrolling down
/world(especially on very active timelines) - Uploaded images were showing up in the thumbnail/card headers, even if they were embedded in the post itself. The header is now restricted to topic thumbnails (and post attachments, which only occur with remote posts)
- Posts are now height-restricted, so long posts don't take up an inordinate amount of space. A "show more" button is available to expand posts in-timeline.
- The "quick create" editor at the top of this page now also lets you choose a category to post to. Administrators can update the default value as desired. It defaults to World/Uncategorized.
Alt text was always supported in NodeBB, but this was not federated outward to remote instances. This is now supported for uploaded images and externally-linked images. Topic thumbnails do not support alt text at this time.
:arrow_upper_left: Soft redirects of remote contentUsers unfamiliar with NodeBB were often surprised to see their content cached by NodeBB, despite this being how federation works. In order to reduce surprise, any guest navigating directly to a remote post or remote user will be soft-redirected out to the original source. This goes hand-in-hand with the topic-restriction feature in v4.9.0.
:computer: ActivityPub Outboxes publishedFor ActivityPub developers, we now publish outboxes as of this version.
:frame_with_picture: More profile pics!@baris improved the avatar handling code so that NodeBB now remembers your last three used avatars, allowing you to toggle between them. You will no longer need to upload new pictures if you want to switch between previously-used avatars!
Follow counts better synchronized@panos@catodon.rocks reported awhile back that follow counts in user pages were off. The logic was updated and should be back in sync with the real values once you follow/unfollow a user.
Stoked to see BSD Cafe has a new site... Running NodeBB ![]()
Considering they don't run just anything, we're in good company! Their other instances run Mastodon (of course) and snac2, arguably one of the most lightweight ActivityPub services.[...]
Designed as a hybrid space, it functions as a classic discussion forum with persistent threads while also supporting ActivityPub federation, enabling cross-platform interactions without algorithmic curation. The project is built on NodeBB and aims to serve as a social hub for BSD and open-source communities, allowing users to engage in long-form discussions while participating in the broader decentralized social web.
Since 2017, we've maintained a bug bounty program that awarded responsible disclosure of security vulnerabilities on a sliding scale of $64 to $512 based on severity.
Throughout the years we've made some unpublished changes to this bounty program, mostly related to the format (no videos, text only, allowed testing endpoints) and in some cases expanding the scope of covered plugins (e.g. 2factor, web-push).
With the rise of LLMs and the corresponding drop in ability needed to analyze and send in reports, we have been receiving a large increase in reports whose submitters have no ability to defend or support their claims, but are happy to pretend that they do. [...]
To be fair, this has been the case ever since the beginning. We've awarded our fair share of bounties to parties running static analysis scripts that output a ton of technical jargon that say very little. The difference today is the scale of these reports is whittling away what little patience I have left.
The easiest thing to do is to cancel the program outright. This would be unfair to the legitimate submitters of security vulnerabilities, and open us up to exploits that we simply would not learn about prior to exploitation. None of that sounds like the direction we want to go. I've gone on the record saying that the one thing OSS devs should set up (if they're able) is a bug bounty program, and I still stand by that claim.
Our bug bounty program remains, with one important change. AI-generated vulnerability reports will be rejected outright out of principle. If you did not do the work, you do not get to take credit for it. The social contract built into this program is, and has always been, a 1:1 exchange of humans talking to humans. Analyzing NodeBB's codebase using Claude (to use an example) and finding vulnerabilities means I should be paying Anthropic the bounty, not the person prompting Claude. If you spent 10 seconds prompting an LLM and I have to spend 20 minutes verifying that your report is not real, the only person's time wasted is my own.
Some use LLMs as a translation tool, and if this is the case, we will make a good-faith effort to take a look, although we are happy to accept reports in your native language.
Some others use LLMs to structure their reports more professionally. Please just speak to us with your own voice. It is vastly preferable.
Hi everybody — late last week we released v4.11.0, which contains the following changes:
ActivityPub Specific Fixes :rotating_light: AP analytics and error pagesNew pages have been added to the control panel to display analytics (send/receive counts) and error counts. There is also a new error page that will show error received within the last 24 hours, and their respective payloads. This will aid in debugging federation issues.
:writing_hand: Article vs. Note distinction updatedPrior to this version, NodeBB would determine whether a federated object was an Article or Note based on content length. This was confusing for end users, and was originally added before NodeBB supported title-less topics.
The revised distinction is much simpler. If it has a title, it's an Article. If it doesn't, it's a Note.
- Threadiverse software publishes
Deleteobjects wrapped in anAnnounceactivity. This is how content is moderated across the threadiverse. NodeBB now supports this, although it has not been extensively tested at this time. - There was an interoperability issue with Mitra that was identified and fixed.
- When group actors post content directly, the category info is shown in the user icon. It used to error out and show "Guest".
- Optimized the outbound federation of content so the front-end is more responsive. A bunch of back-end optimizations to reduce the number of calculations needed.
- Emojis now supported in DMs to remote users.
A new option has been added to the "Notifications" sub-section of the user control panel.

This option will allow you to visibly hide read notifications from the notifications dropdown, which reduces visual clutter.
Tinycon customizationsAdmins can now customize the notification badge shown in the browser tab icon. We use the Tinycon library for this, and the colour values can be customized now:

With temperatures reaching well into the 30s (in celsius of course
) in the Toronto area, we're all firmly in summer mode :swimmer: :beach_with_umbrella: , but that won't stop us from forging on ahead with new features and fixes for NodeBB!
There are improvements across ActivityPub federation, administrative tooling, and security hardening. Our ActivityPub integration receives bug fixes including duplicate handling, configurable rate limiting, and better error reporting, alongside new hooks for remote user lifecycle events. The registration queue and invitations are reorganized into a dedicated UI with a new "Reject All" bulk action and improved notification handling. Security reports have been coming in consistently throughout the month with valid security reports (though almost all AI discovered and generated). This led to stricter privilege checks on post diffs, crossposts, and GDPR exports, plus protection against username enumeration. The NodeBB team strongly encourages upgrading to v4.14.0 for the latest security fixes and federation improvements. The release also includes a new tx() translation helper, Benchpress escaping improvements, and a first-run categories onboarding modal for fresh installations.
Here are the high level changes you can expect to see when you upgrade from v4.13.0 to v4.14.0... [...]
:globe_with_meridians: Federation Regression Fixes!Around v4.12.0 or so, a number of regressions were unintentionally introduced as part of security fixes that severely hampered federation — especially with Lemmy-based instances and relays. We've resolved those regressions and Relay/Lemmy federation should resume within 24 hours after upgrading.
The public key fetch rate limiter logic was simplified and updated (due to it being faulty and not really working in the first place), streamlined some duplicate logic with Like/Dislike activities, improved the AP Errors reporting page in the ACP, added a parent traversal depth guard, fixed an issue where updates to scheduled topics were accidentally being federated out, and about a hundred other smaller bugs :slightly_smiling_face:
:ballot_box_with_check: Registration Queue updatesThe registration queue was moved out of the ACP, and invitations are also managed in this page now. A "reject all" button was added to allow admins to quickly reject every queued registrant in one fell swoop.
🔒 Privilege & Security Fixes- Post diff access — Check topics:read privilege when loading post diffs
- Crossposts — Added source category privilege check to crossposts
- GDPR export — Prevented global moderators from performing GDPR data exports
- Nids ownership — Don't mark nids as read/unread that you don't own
- Upload privileges — Prevent uploading thumbnails without upload:image privilege; replaced extension-based MIME validation with content
sniffing - Username enumeration — Use dummy lockout key for non-existent users to prevent enumeration
- Category disabled flag — Check category disabled flag on getRaw
We use Benchpress as our templating engine. We updated our integration for security and performance. @baris put together a thorough write-up for that one here.
Miscellaneous- First-run modal — New categories onboarding modal for fresh installations
- Dashboard warnings — Added localhost and URL mismatch warnings to admin dashboard notices
- Push notifications should work on Safari/iOS devices now (via the web-push plugin)
