master
Measured on real domains over real certificates, Remark42 on one registrable domain and the host page on another, with a control cookie behind every blocked column so a run that blocks nothing cannot report a pass. Three results the manual did not carry. Safari blocks third-party cookies out of the box, so AUTH_SAME_SITE=none on its own has already stopped working there, which makes the old recipe broken today and not deprecated later. Firefox reaches a working session by a weaker route than Chrome and Safari do: it accepts the server's attribute-less cookie, and because that cookie is HttpOnly the browser then forbids the widget's script from replacing it, so the session rides on an ordinary unpartitioned third-party cookie even with the header flag on. And Firefox's block-all setting discards partitioned cookies too, so no configuration survives it. Two parameter descriptions were wrong in ways that matter here. AUTH_SAME_SITE default emits no SameSite attribute rather than Lax, which is precisely what lets the widget's own cookie land on Chrome and Safari. And AUTH_TTL_COOKIE does not govern the cookie that carries the session under the header flag, since the frontend hardcodes 200h to mirror the default.
Fill the instance URL into the embedded frontend at serve time, and stop pinning compressor output in tests (#2198)
Fill the instance URL into the embedded frontend at serve time, and stop pinning compressor output in tests (#2198)
Fill the instance URL into the embedded frontend at serve time, and stop pinning compressor output in tests (#2198)
Remark42

Remark42 is a self-hosted, lightweight and simple (yet functional) comment engine, which doesn't spy on users. It can be embedded into blogs, articles, or any other place where readers add comments.
- Social login via Google, Facebook, Microsoft, GitHub, Apple, Yandex, Patreon, Discord, Telegram and custom OAuth2 providers
- Login via email
- Optional anonymous access
- Multi-level nested comments with both tree and plain presentations
- Import from Disqus and WordPress
- Markdown support with friendly formatter toolbar
- Moderator can remove comments and block users
- Voting, pinning and verification system
- Sortable comments
- Images upload with drag-and-drop
- Extractor for recent comments, cross-post
- RSS for all comments and each post
- Telegram, Slack, Webhook and email notifications for Admins (get notified for each new comment)
- Email and Telegram notifications for users (get notified when someone responds to your comment)
- Export data to JSON with automatic backups
- No external databases, everything embedded in a single data file
- Fully dockerized and can be deployed in a single command
- Self-contained executable can be deployed directly to Linux, Windows and macOS
- Clean, lightweight and customizable UI with white and dark themes
- Multi-site mode from a single instance
- Integration with automatic SSL (direct and via nginx-le)
- Privacy focused
Demo site available with all authentication methods, including email auth and anonymous access.
All remark42 documentation is available by the link.
Contribution
In order to start and work on the project locally in development mode check our contribution documentation for backend and frontend.
If you are interested in adding a new localization please check these docs.
Related projects
Languages
Go
69.4%
TypeScript
22.8%
CSS
3.2%
HTML
1.3%
JavaScript
1.3%
Other
2%
