Reposted by ティントDIESELSAURUS 💿 Stream ‘Glow’ OUT NOW @dieselsaurus.bsky.social · 16/08/2026i love my computer (and fursuit) photos with Cyren Folf + @tynt.bsky.social at the Ninajirachi tower 1616
Reposted by ティントjosh @viciousidiot.bsky.social · 12/03/2026Warzone Joker Limner Acrylic, pencil and marker on canvas 018838
Reposted by ティントxXacidnekoXx @xxacidnekoxx.bsky.social · 19/01/2026art I made for @aurawolfie.bsky.social ✨🌊!!! 739399
Reposted by ティントCaz @timberwind.bsky.social · 11/12/2025if a gamma ray burst type event happened I would simply dodge. not worried about it 6335
ティント @tynt.bsky.social · 10/12/2025youtu.be/hCbwx2hA5mMyoutu.beStorm ShowYouTube video by Oneohtrix Point Never - Topic 010
ティント @tynt.bsky.social · 08/12/2025One clarification: While the vulnerability is present regardless of Server Actions, it technically leverages Server Functions, which is a shared component in RSC's architecture. It was the fact that other RSC features relied on Server Functions that led to every RSC app having a vulnerable endpoint 020
ティント @tynt.bsky.social · 08/12/2025Ultimately, what you will need to check varies on the framework and architecture of your app. Different frameworks have different patterns, some more idiomatic, some with more sharp edges, but all very new and unfamiliar to most engineers. 110
ティント @tynt.bsky.social · 08/12/2025So just like in any backend scenario handling untrusted input, you would perform validation and other checks, inside of that server action function. My personal opinion is that exactly what validation needs to be performed in your average React app with a Server Action, can be extremely unclear. 110
ティント @tynt.bsky.social · 08/12/2025To answer your question about the security boundary of Server Actions: The action has to be in a file marked with the directive 'use server' which indicates it will execute on the server. The client calls the function with the arguments from a separate file. These arguments are untrusted input. 100
ティント @tynt.bsky.social · 08/12/2025From a dev's perspective, those are React Server Actions. Generally, most apps built in React use a mix of client and server components, with the latter benefitting from features like streaming, which use the deserializer. This vulnerability would have been present regardless of Server Actions. 110
ティント @tynt.bsky.social · 08/12/2025Technically, you do not need to traverse to a then-able promise. There are other vectors as well susceptible to the same lack of guard check. The irony of it all is that the guard check was actually imported into the file but then never used in the code. Oops! 🫨 120
ティント @tynt.bsky.social · 08/12/2025The deserializer in Flight, React's protocol for client/server communication, was missing a guard check. This allowed attackers to craft and send a malicious "chunk" object that allows for prototype pollution, ultimately resulting in a call to a then-able promise that will execute code. 110
Reposted by ティントLupo D'inverno @lupodinverno.bsky.social · 01/12/2025charging for a bit commission for @phira.bsky.social 210842
ティント @tynt.bsky.social · 26/10/2025one of the all time songs. my soul is tuning in every time it plays. 110
Reposted by ティントJasmine 🦊 📡 @radarindicated.bsky.social · 03/09/2024flying in july #furryartist #furry #planedragon 61630451