Home Artists Posts Import Register

Content

You'll need to create an account to view patron content.

https://satinminions.com/signUp

Note that your username will be displayed if you post a comment when you are logged in (anonymous comments are still allowed when logged out).  There is a visual difference between logged in usernames and pseudonymous usernames. 

From your profile page ( https://satinminions.com/myProfile ) click "Connect with Patreon" to uh.. do that.  Follow along and it should just work.  If you choose to change pledge amounts there is a "[Refresh]" link next to the tier in your profile.

After you verify your email, you can choose to receive email notifications.  If you change your mind, the unsubscribe link in the notification emails works instantly.

Anyone can now "like" comments.  It just for fun, it makes a number go up.  It's limited by IP and time.  The total number of likes your comments have received is shown in your profile. 

-----------

Some security stuff: 

* Passwords are hashed appropriately

* Logins are flood protected

* Throwaway emails are blocked.  This is because anyone can check those and reset your password.  Just use a real email.  If you're concerned about me having your email, know that patreon already gives me your email.  You're worth more to me as a happy patron than as an angry spam recipient :)

* Usernames are restricted to characters you can type on a normal keyboard.  Mainly to prevent page breaking unicode shenanigans.  

* Emails are starred out, even for me on the admin panel, to reduce the possibility of information leaks.  

* When you do a password reset, it does not confirm or deny the existence of that account.  This makes it slightly more difficult to recover if you've forgotten what email you used, but it prevents bad actors from probing the account list.

* Password resets are flood protected

* There's a javascript accessible cookie that contains your username.  This is just for the user interface and is not used for security.

* Most critical actions are protected with csrf tokens

* I'm pretty sure I've handled the weird cloudflare caching stuff but in case I haven't and you see weird stuff or someone else's profile, just calmly tell me the problem and I'll fix it.

Comments

satin

I have identified a bug where patron status of some accounts is not being read correctly, working on a fix.

seredin

Easy peasy

satin

Should be working now. I refreshed everyone's status and the values make a lot more sense. Everyone left at "free" status doesn't have a patreon ID connected, so if that's you just try again.

Anonymous

email confirmation does not work for me. is it necessary to confirm the email?

Anonymous

Redundant to create another account just to view your work when we already view thru an account on Patreon.

satin

It's only necessary if you want to do password recovery or get notifications. Did you not get the email or did the link not work?

Anonymous

didn't get an email, nothing in the spam folder either. if you want to check, my account name on your site is `ibuprofen` as well. notifications would be nice, will they still be available through patreon as well?

satin

I have tweaked the outgoing mail address and dns settings, so try the "resend verification email" link in a few minutes.

satin

To an extent I agree, but it's necessary for technical and (sadly) political reasons. Technically, it's easier to host content on my site since there are no restrictions on javascript, layout, tags, whatever. On the political side, I could write a whole blog post about this but basically patreon has always been shifty and coy about adult content. A while ago they made me delete all publicly facing posts that contained nudity. They've had some high profile unjustified bans. It's just better to put work into my own site than someone else's.

satin

I have addressed bugs relating to resetting passwords, the form not showing results and the password change itself not working.

Anonymous

RSS feed seems to be slightly broken: the preview picture has a wrong link?