A platform for community discussion. Free, open, simple.
Go to file
Jeff Wong 3189dab622 FIX: correctly remove authentication_data cookie on oauth login flow
Additionally correctly handle cookie path for authentication_data

There were two bugs that exposed an interesting case where two discourse
instances hosted across two subfolder installs in the same domain
with oauth may clash and cause strange redirection on first login:

Log in to example.com/forum1. authentication_data cookie is set with path /
On the first redirection, the current authentication_data cookie is not unset.
Log in to example.com/forum2. In this case, the authentication_data cookie
is already set from forum1 - the initial page load will incorrectly redirect
the user to the redirect URL from the already-stored cookie, to /forum1.

This removes this issue by:

* Setting the cookie for the correct path, and not having it on root
* Correctly removing the cookie on first login
2020-03-21 14:34:25 -07:00
.github/workflows Rename many `.js.es6` files to `.js` 2020-03-12 13:29:55 -04:00
.tx Add Hungarian locale (#6260) 2018-08-13 01:02:35 +02:00
app FIX: correctly remove authentication_data cookie on oauth login flow 2020-03-21 14:34:25 -07:00
bin DEV: Add docker cleanup script to d/ folder 2020-03-01 12:09:07 -08:00
config FEATURE: automatically delete replies on a topic after N days. (#9209) 2020-03-19 21:06:31 +05:30
db FEATURE: automatically delete replies on a topic after N days. (#9209) 2020-03-19 21:06:31 +05:30
docs Elastic Email can now disable the UNSUB link for Discourse installs (#8986) 2020-03-06 11:38:01 -05:00
images
lib Convert select-kit from es6 to js (#9246) 2020-03-20 12:40:32 -04:00
log
plugins FEATURE: Show votes in an "on voted" poll to the creator 2020-03-20 13:36:42 -07:00
public Revert "FIX: lower case URLs before comparing for embedding comments" 2020-01-23 20:36:05 +05:30
script FIX: Method from Telligent import script was deleted by accident 2020-03-14 22:10:40 +01:00
spec FIX: correctly remove authentication_data cookie on oauth login flow 2020-03-21 14:34:25 -07:00
test FIX: Don't fail if the test environment doesn't support Webauthn 2020-03-20 10:44:02 -04:00
vendor DEV: popperjs 2.0.6 (#9171) 2020-03-11 10:34:58 +01:00
.editorconfig
.eslintignore Support for transpiling `.js` files (#9160) 2020-03-11 09:43:55 -04:00
.eslintrc DEV: Ember linting - disallow Ember.* variable usage (#8782) 2020-02-05 10:14:42 -06:00
.git-blame-ignore-revs Convert select-kit from es6 to js (#9246) 2020-03-20 12:40:32 -04:00
.gitattributes Use proper encoding for email fixtures. 2018-02-21 17:06:35 +08:00
.gitignore REFACTOR: Restoring of backups and migration of uploads to S3 2020-01-14 11:41:35 +01:00
.prettierignore DEV: Prettify *.en_US.yml files 2019-05-20 23:21:43 +02:00
.rspec DEV: Use `--profile` and `--fail-fast` in CI only 2019-03-11 22:04:47 -04:00
.rspec_parallel DEV: Introduce parallel rspec testing 2019-04-01 11:06:47 -04:00
.rubocop.yml This rule was removed from Rubocop due to different behavior in Ruby 3. 2020-02-19 13:44:20 -05:00
.ruby-gemset.sample
.ruby-version.sample Make version the same as install docs (#8713) 2020-01-14 12:33:37 +11:00
.template-lintrc.js DEV: enforces ember-template-lint: no-html-comments (#9183) 2020-03-12 07:51:05 +01:00
.travis.yml Fix frontend tests on Travis (#8089) 2019-09-12 10:31:51 +10:00
Brewfile DEV: enable frozen string literal on all files 2019-05-13 09:31:32 +08:00
CONTRIBUTING.md
COPYRIGHT.txt
Dangerfile Rename many `.js.es6` files to `.js` 2020-03-12 13:29:55 -04:00
Gemfile DEV: Pin hashie and faraday versions for zendesk api compatibility (#9214) 2020-03-19 19:52:31 +00:00
Gemfile.lock Build(deps): Bump aws-sdk-s3 from 1.61.0 to 1.61.1 (#9216) 2020-03-20 09:43:58 -04:00
LICENSE.txt
README.md it's 2020 now, though maybe we all wish it wasn't 2020-03-12 15:54:30 -07:00
Rakefile DEV: enable frozen string literal on all files 2019-05-13 09:31:32 +08:00
adminjs
config.ru DEV: enable frozen string literal on all files 2019-05-13 09:31:32 +08:00
crowdin.yml DEV: Add configuration file for Crowdin 2020-02-12 22:45:17 +01:00
d
discourse.sublime-project DEV: Exclude i18n .yml files from Sublime Text project. (#6473) 2018-10-10 20:21:24 +08:00
jsapp
lefthook.yml Rename many `.js.es6` files to `.js` 2020-03-12 13:29:55 -04:00
package.json DEV: popperjs 2.0.6 (#9171) 2020-03-11 10:34:58 +01:00
yarn.lock DEV: popperjs 2.0.6 (#9171) 2020-03-11 10:34:58 +01:00

README.md

Discourse is the 100% open source discussion platform built for the next decade of the Internet. Use it as a:

  • mailing list
  • discussion forum
  • long-form chat room

To learn more about the philosophy and goals of the project, visit discourse.org.

Screenshots

Boing Boing

Mobile

Browse lots more notable Discourse instances.

Development

To get your environment setup, follow the community setup guide for your operating system.

  1. If you're on macOS, try the macOS development guide.
  2. If you're on Ubuntu, try the Ubuntu development guide.
  3. If you're on Windows, try the Windows 10 development guide.

If you're familiar with how Rails works and are comfortable setting up your own environment, you can also try out the Discourse Advanced Developer Guide, which is aimed primarily at Ubuntu and macOS environments.

Before you get started, ensure you have the following minimum versions: Ruby 2.6+, PostgreSQL 10+, Redis 4.0+. If you're having trouble, please see our TROUBLESHOOTING GUIDE first!

Setting up Discourse

If you want to set up a Discourse forum for production use, see our Discourse Install Guide.

If you're looking for business class hosting, see discourse.org/buy.

Requirements

Discourse is built for the next 10 years of the Internet, so our requirements are high.

Discourse supports the latest, stable releases of all major browsers and platforms:

Browsers Tablets Phones
Apple Safari iPadOS iOS
Google Chrome Android Android
Microsoft Edge
Mozilla Firefox

Built With

  • Ruby on Rails — Our back end API is a Rails app. It responds to requests RESTfully in JSON.
  • Ember.js — Our front end is an Ember.js app that communicates with the Rails API.
  • PostgreSQL — Our main data store is in Postgres.
  • Redis — We use Redis as a cache and for transient data.

Plus lots of Ruby Gems, a complete list of which is at /master/Gemfile.

Contributing

Build Status

Discourse is 100% free and open source. We encourage and support an active, healthy community that accepts contributions from the public including you!

Before contributing to Discourse:

  1. Please read the complete mission statements on discourse.org. Yes we actually believe this stuff; you should too.
  2. Read and sign the Electronic Discourse Forums Contribution License Agreement.
  3. Dig into CONTRIBUTING.MD, which covers submitting bugs, requesting new features, preparing your code for a pull request, etc.
  4. Always strive to collaborate with mutual respect.
  5. Not sure what to work on? We've got some ideas.

We look forward to seeing your pull requests!

Security

We take security very seriously at Discourse; all our code is 100% open source and peer reviewed. Please read our security guide for an overview of security measures in Discourse, or if you wish to report a security issue.

The Discourse Team

The original Discourse code contributors can be found in AUTHORS.MD. For a complete list of the many individuals that contributed to the design and implementation of Discourse, please refer to the official Discourse blog and GitHub's list of contributors.

Copyright 2014 - 2020 Civilized Discourse Construction Kit, Inc.

Licensed under the GNU General Public License Version 2.0 (or later); you may not use this work except in compliance with the License. You may obtain a copy of the License in the LICENSE file, or at:

https://www.gnu.org/licenses/old-licenses/gpl-2.0.txt

Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.

Discourse logo and “Discourse Forum” ®, Civilized Discourse Construction Kit, Inc.

Dedication

Discourse is built with love, Internet style.