Hi,
I'm exploring the possibility of converting our 100,000+ post forum from phpBB 3.3.15 to nodeBB.
I previously converted the forum from another system (WebWiz IIRC) about 9 years ago and that was a big job so I was interested to see that NodeBB has a plugin that might handle a lot of the conversion for me.
However, I note from the GitHub Repository Readme for this plugin that it only supports NodeBB version 1.12.1 which is now quite a long way behind. Also, AFAICT the phpBB Exporter may not be up with the latest phpBB version.
What would be involved in upgrading nodebb-plugin-import to support nodeBB 4.x?
Hello NodeBB Community
I started a purge for our forum with the goal of deleting spam accounts.
Started with ~40000 user accounts and realized very fast that deleting them manually will be a Sisyphus task.
Vibe coded a usercleaner plugin with filters and stuff like that.
[image: image.jpeg]
So with that filter, 70.20% of all accounts are spam.
After that was cleaned out I looked deeper into more recent accounts and was a little shocked.
I identified a set of mail hosts used for verification over and over again.
From the manage user view with 500 accounts did a little RegEx search with a browser plugin and got 381 of 500 users are from these mail hosts.
So 76.2%.
After I complete my purge, from 39133 accounts 2754 are left.
93% of accounts where spam or the other way around only 7% "good" accounts.
note: will create some feature requests since I noticed some stuff in the manage user view
I found this plugin https://github.com/NodeBB-Community/nodebb-plugin-email-blacklist but also thought, that can't be it.
These bots will just use other mail addresses.
So, how do you guys handle this? Just ignore it?
Looking forward for some input from the community.
Thanks for reading and thinking about a clean forum with me
Hi — I need help getting realtime working between our Next.js app and a self-hosted NodeBB instance.
We are not embedding the NodeBB UI. NodeBB is the community backend only. Our product UI (posts, forums, chats) lives in Next.js and talks to NodeBB over the Write API / Read API.
What already works
On first login we:
Create a NodeBB user with the Write API as admin, e.g. POST /api/v3/users with Authorization: Bearer <master token> and _uid = admin uid
Store the returned uid on our user row (Supabase: users.nodebb_id)
For later API calls we impersonate that user with the master token + _uid = stored nodebb_id
REST is fine: topics, posts, votes, bookmarks, categories, chats list/send all work.
What does not work
Realtime does not connect from the Next.js app (browser) to NodeBB Socket.IO.
We need live:
new posts / replies in the feed
likes / bookmarks
chat messages (chats.receive, unread counts)
Because the browser is a different origin than NodeBB, a direct io(nodebbOrigin) from the Next.js site is what we are trying to get right (CORS, cookies, auth).
How we tried to authenticate the socket
We create a user token server-side:
POST /api/v3/users/:uid/tokens (admin master token + _uid = admin)
Then we planned to connect from the browser with something like:
io(NODEBB_ORIGIN, {
transports: ["websocket", "polling"],
auth: { token }, // or query: { token }
});
Can someone please suggest that how we can do this thing.
So I renewed nodebb.social.After a year, I’ve been thinking about this a LOT.I want to give a federated forum a real shot. But not something like Lemmy or Piefed, where everything leans on upvotes and downvotes. @nodebb can disable that, and to me that’s a pretty critical feature.What I’d like is a general NodeBB board for general topics: art, video games, music, whatever people actually want to dig into.Politics is the tricky part.It’s not like the Threadiverse is starving for political communities. But politics also has a nasty habit of crawling into everything and taking over the room.And yeah, I know an apolitical stance is still a political stance.But I’ve lived through enough GamerGate-type scenarios to see how outrage and grievances can hijack things that are supposed to give us JOY.I’m also against memes and low-effort junk because, frankly, that stuff attracts stupidity.Deep dives, though? Absolutely.I want people to go long. Get into the weeds. Actually think about what they’re posting.I may also need somebody else who finds this project interesting enough to help run it. Maybe a co-admin. Maybe a moderator.Because I can already see how this could get overwhelming, and managing the whole thing by myself could become a pain in the ass when I’ve also got a family.Nothing is launched yet.But I’d love some insight.
What do you use to slow down the endless spam signups?
The board already moderates the first posts but the endless signups is something I need to stop or at least slow down.
What works for you?
Hello!
There is schema.org markup duplication error reported by Google Search Console for Harmony theme.
The issue exists for specific topics
The root case might live here and here
Check this out, it'd to be fixed
Hey everyone,
I'm not sure where to post this, whether it belongs in the themes or plugins category, I'll let @baris or @julian edit it if necessary.
I've been working on a small client-side script that adds an simply immersive reading mode to NodeBB. No plugin required, just a few lines of custom JS and CSS dropped into the ACP.
I'm just sharing this here for fun : https://github.com/DroidBV8/nodebb-focus-mode
[image: input.gif]
What it does
Pressing F (or clicking the icon in the right sidebar) hides everything that isn't the content you're trying to read:
Both sidebars
Header / brand bar
Footer
Topic thumbnails and sidebar tools (reply, follow, timeline)
The content area reflows to a centered 860px column, font size bumps up slightly, and a reading progress bar appears at the top of the page.
To exit: press F again, Escape, or click the floating button that appears in the bottom-right corner.
Details
Activation effect : a subtle CRT glitch effect plays on toggle. Three CSS variables let you dial the intensity up or down without touching the keyframes:
--fm-glitch-opacity: 1; /* 0.5 = subtle | 2 = heavy */
--fm-glitch-skew: 1deg;
--fm-glitch-shift: 4px;
Keyboard : F to toggle. Ctrl+F, Cmd+F and Alt+F are ignored so you don't accidentally trigger it when searching the page.
Scroll preservation : when toggling, the layout shifts because sidebars appear/disappear. The script measures the position of the nearest visible post before and after the layout change, then compensates with scrollBy so you stay exactly where you were.
Topic-only : the button is greyed out on non-topic pages with a tooltip explaining why. Pressing F outside a topic shows a small toast instead of doing nothing silently.
Mobile: disabled entirely under 768px. No button injected, no state restored.
Theming : all colors reference Bootstrap CSS variables (--bs-body-bg, --bs-border-color, --bs-primary, etc.) so it adapts automatically to any NodeBB theme, light or dark.
State : saved in localStorage, restored on next visit. Uses try/catch so it degrades gracefully in private browsing.
Implementation notes
The script is a self-contained IIFE, hooking into the standard NodeBB client-side events:
$(window).on('action:ajaxify.end', function () { focusMode(); });
$(window).on('action:topic.loaded', function () { focusMode(); });
// etc.
The glitch effect is pure CSS @keyframes , the JS only adds/removes classes. Layout compensation is synchronous (getBoundingClientRect → scrollBy) with no setTimeout on the scroll itself, which avoids triggering NodeBB's scroll-based URL updater in a loop.
Compatibility
Tested on NodeBB 3.x with Bootstrap 5 themes. Should work on any setup using the standard sidebar components (nav.sidebar-left, nav.sidebar-right).
Since 2017, we've maintained a bug bounty program that awarded responsible disclosure of security vulnerabilities on a sliding scale of $64 to $512 based on severity.
Throughout the years we've made some unpublished changes to this bounty program, mostly related to the format (no videos, text only, allowed testing endpoints) and in some cases expanding the scope of covered plugins (e.g. 2factor, web-push).
With the rise of LLMs and the corresponding drop in ability needed to analyze and send in reports, we have been receiving a large increase in reports whose submitters have no ability to defend or support their claims, but are happy to pretend that they do.
To be fair, this has been the case ever since the beginning. We've awarded our fair share of bounties to parties running static analysis scripts that output a ton of technical jargon that say very little. The difference today is the scale of these reports is whittling away what little patience I have left.
The easiest thing to do is to cancel the program outright. This would be unfair to the legitimate submitters of security vulnerabilities, and open us up to exploits that we simply would not learn about prior to exploitation. None of that sounds like the direction we want to go. I've gone on the record saying that the one thing OSS devs should set up (if they're able) is a bug bounty program, and I still stand by that claim.
Our bug bounty program remains, with one important change. AI-generated vulnerability reports will be rejected outright out of principle. If you did not do the work, you do not get to take credit for it. The social contract built into this program is, and has always been, a 1:1 exchange of humans talking to humans. Analyzing NodeBB's codebase using Claude (to use an example) and finding vulnerabilities means I should be paying Anthropic the bounty, not the person prompting Claude. If you spent 10 seconds prompting an LLM and I have to spend 20 minutes verifying that your report is not real, the only person's time wasted is my own.
Some use LLMs as a translation tool, and if this is the case, we will make a good-faith effort to take a look, although we are happy to accept reports in your native language.
Some others use LLMs to structure their reports more professionally. Please just speak to us with your own voice. It is vastly preferable.
I’m going to finally start a NodeBB instance. For the past year, I debated whether it should be Piefed instead. Thing is, I own the domain nodebb.social and I got the full blessing of @julian to use it.
Welcome back to another minor release of NodeBB, at a blistering pace after the last release about three weeks ago!
Here's what changed since v4.15.0, and what you can expect to see in v4.16.0.
ActivityPub Functionality
As always, we spent quite a bit of time here improving NodeBB's AP support.
We now support sending and receiving of RFC9421 HTTP Signatures. Most of the fediverse is still on the outdated cavage-12 draft standard, so moving to the RFC is a step in the right direction
Split-domain webfinger handles now supported (from remote users)
Admins can now easily follow a hashtag globally. This means the instance itself will follow the hashtag (either via configurable relay.fedi.buzz or tags.pub), and automatically categorize content into NodeBB
Content Warnings from remote posts are now honoured, and hidden behind a <details> tag
Custom emoji handling improvements — custom emoji in usernames and topic title are now rendered faithfully!
Local admins can "bump" topics, and this shows up as an Announce, which is like a Mastodon-style boost
Chat messages can now be reported and forwarded to the remote instance
Activity sending logic was given a major overhaul so the site is more performance (aka less likely to keel over when someone moderately popular posts something)
Moderation updates
Chat messages can now be flagged
Category privilege copying is now available via the v3 API
Admins can hide topic event types
Full name can be used in ACP user search
Post edit privilege can now be granted to groups
One-click instance-wide ability to disable notification emails
Other
Tags are now case-sensitive
Postgres object cache
A bunch of security fixes, thank you all for helping keep NodeBB secure, even if we now no longer award bounties for AI-assisted reports.
NodeBB version v4.15.2
ACP Manage Users:
Filtering for users by email does not work for pending and expired email validated addresses.
Related to topic https://community.nodebb.org/topic/19488/handling-spam-accounts-best-practices
Sometimes you want to filter for all users and not just 500.
An extra view where a search patterns and filters are defined first before listing users could be an improvement.
Related to topic: https://community.nodebb.org/topic/19488/handling-spam-accounts-best-practices
Theme settings cannot be saved due to invalid page value
Description
There appears to be a bug in the Theme settings page.
When a user enables Quick Reply in their personal theme settings and clicks Save, the changes are not saved.
The browser console shows:
PUT https://******.com/api/v3/users/7/settings 400 (Bad Request)
Error: Invalid page value, must be at least 2 and no more than 15
The error is thrown from the API request when saving the Theme settings:
account-theme.715c1b1efe1112a57522.min.js
The result is that the user receives no successful save indication, and the setting remains unchanged after refreshing the page.
Expected behavior
The Theme settings should be saved successfully when clicking Save, provided that the user has selected valid settings.
Actual behavior
The save request fails with HTTP 400 Bad Request because NodeBB reports an invalid page value.
It seems that an invalid page value may be present in the user's existing settings, even though the corresponding value is not necessarily visible or editable in the Theme settings UI.
Environment
NodeBB: 4.15.2
Theme: Harmony
Browser: Chrome
API: /api/v3/users/:uid/settings
This also prevents users from saving other personal Theme settings, including Quick Reply.
Some astute users of this site might've noticed that I turned on nodebb-plugin-reactions. That plugin allowed local users to react to other posts with emoji, but this lacked integration with federated services.
Additionally, titles and user display names containing emoji were often either stripped or reduced to their bare shortcode equivalent (e.g. :blobcat:).
As of the upcoming NodeBB v4.16.0, you will be able to natively see remote users' custom emoji in their display names, as well as send and receive emoji reactions in NodeBB. This is all handled by the Reactions plugin, which you can install yourself by running npm i @nodebb/nodebb-plugin-reactions@latest
More information below...
We implemented FEP-c0e0: Emoji reactions, which was put together by @[email protected] in order to document existing behaviour for Emoji Reactions in other software, namely Misskey, Pleroma, and Fedibird.
NodeBB handles both the explicit EmojiReact activity, and the fallback Like activity (with content/tag set as appropriate), and will show the reaction in the frontend UI.
[image: A screenshot showing a blobcat and an applause emoji reaction]
Likewise, sending emoji reactions is identical to before, with the same emoji selector as before:
[image: An emoji selector element]
... with the new addition that NodeBB will federate these emoji reactions out. Note that Emoji reactions are not supported in the Mastodon+forks side of the fediverse. You can send them out, but they won't receive them.
If you're worried about compatibility, switch the activity type in the plugin options to Like:
[image: image.jpeg]
Finally, as mentioned at the top, this is available only in the latest develop or upcoming v4.16.0. Installing the latest reactions plugin on top of stable v4.15.x will not magically grant you access to federated emoji reactions
Hello,
just noticed that if a user deletes an account, there seems to be a missing text for the placeholder for the former nickname.
[image: 2026-08-30_16-14.png]
Hello @baris and @julian , during standard updates I used to run git fetch and then upgrade using the latest-version command. This time, however, git fetch asked me for my GitHub username and password, so I couldn’t complete the update. What could be the reason for this?
[image: image.jpeg]
After upgrading to 4.15.1, Chrome DevTools always shows Manifest: found icon with no valid size for icons under 192x192 (36, 48, 72, 96, 144px).
In src/controllers/index.js, Controllers.manifest always pushes icons for sizes [36, 48, 72, 96, 144, 192, 512], regardless of whether a custom touch icon is configured. Chrome considers icons smaller than 192x192 as "no valid size" for PWA purposes.
This was introduced in commit 75a6dff (feat: send fallback brand icons in manifest).
4.15.0
Enters the site.
Clicks login.
Logs in with username and password.
Arrives at a page of a topic that was deleted a long time ago.
What's the story? What's this reference?
@omega said:
In my simple mind I would have thought hCaptcha might provide a decent holdout against bots, am I too understand it had negligible effect even when combined with all the other mitigations?
In our case we still have a decent amount of spam accounts that try to get through.
I have a suspicion how tho but I will need to investigate.
This is kind of by design, since emails that are not validated yet are not considered to belong to any user(they are not saved in email:uid & email:sorted so search doesn't find them.
So, to summarise the above, my experience suggests that the following files should be added to the nitro-porter.zip file for download:
compose.yml
composer.json
.docker/run/php/Dockerfile
@DownPW Very cool and most excellent fun.
For me the funny thing is this looks very similar to a minimal theme concept I graphically worked up 6 years ago!
I can't remember if I posted it but here is a jpeg for whatever it's worth.
[image: example-minimal-theme-nodebb.jpg]