跳到正文
Lutong's Homepage

全新博客评论系统上线

2021-10-20 life blog web

Why not Valine?

I have used Valine for my blog’s comment for a long time. It is based on Leancloud and provides a good theme style. Recently, my blog was under attack with a Valine’s XSS attack. The EXP is:

"link": "\" /></span><img src='none' onerror='setInterval(function(){alert()},10);'/>",

For more information, please visit the attacker’s blog .

I received my email reminder two minutes after the attack and cleaned all malicious comments immediately. Since Valine seems to be out of maintenance, I took this module offline. After that, I tried my best to find an alternative comment system.

Why not Gitment?

Gitment is another comment system based on Github’s Issues APIs. However, this application asks for the read and write permissions of all my public and private repositories. It worries me a lot. Besides, both the app id and app secret are in plaintext on all my blog pages. I doubt its safety.

Now, I am using Giscus

Giscus is a new comment system I have found recently with a good look. It is a Github application and uses the Github discussion APIs. In terms of permissions, it only asks for discussion permissions of only one particular repo. Visitors need to log in to their Github account to leave a comment. It is pretty easy to load Giscus, and I think I might try it for a while.

FYI, Giscus’s homepage is here .