Eighth Week Site Updates
Site Updates — September 12 to September 20, 2026
Two months of Idunn! An extra-long week, and a busy one: 149 changes since the last update. (Most of them are concentrated into a single feature.)
The short version: sixteen bugs are fixed, most of them straight from your reports — character sheets that wouldn’t fill in their own skills, Remember Me that didn’t remember, search’s Load More quietly skipping results, and a long sheet name hiding the top of the sheet. We found and closed three ways private text could travel further than it should. Moderators got real tools for spam accounts. And the big one: post search now runs on a new engine.
Search Has Moved To A New Engine
For weeks we’ve been saying that searching a common word is slow, and that no amount of tuning the existing setup would fix it. This is the fix.
Since September 15 a second, purpose-built search engine has been running quietly alongside the old one — answering every search in the background, logging what it found, and being graded against what you actually saw. Over a 72-hour test it answered every single search that had been timing out, and it did it in about a second and a half at worst, against a 6-second limit that the old engine was blowing straight through (we measured queries taking about 22 seconds).
On Saturday we rebuilt the index from scratch against a fresh copy of the database (17M posts) and in the process repaired about 19,000 posts that the old indexing had been recording as blank, and which therefore could never be found at all. We then ran it live for 80 seconds against real searches. It held.
As of today, September 20, post search runs on the new engine for everyone. What you should notice:
- Searches for common words finish. Simply put, the goal is met.
- An exact phrase that matches nothing now falls back to the same words in any order, rather than dead-ending. That’s how you’d expect a search box to behave.
- Result counts are exact up to 1,000 matches and “about 2,500” above that. They’re counted against your permissions, so two people searching the same word can legitimately see different totals.
- Load More no longer skips results (more on that below).
Two caveats to be aware of. First, relevance ranking is new, and we’ve deliberately left the fine-tuning to be done against real traffic rather than guessed at in advance. Saturday’s live test already caught one case where a broad search came back stuffed with topic titles instead of posts, and we changed how results are blended because of it. If a search puts something odd at the top this week, tell us; that’s exactly the feedback we need. Second, if anything goes wrong we can switch back to the old engine with a single setting. The old search data stays in place for at least another few weeks before we decide whether to retire it.
Sixteen Bugs, Fixed
Character sheets
-
“d20 Modern sheet does not populate skills.” This turned out to be two faults, and it was much bigger than one sheet. Every Auto Fill, Clear, sort, statblock and Update CC link across nine older templates — anime, d20 Modern, D&D 4e, Iron Heroes, Mutants & Masterminds, Naruto, Star Wars, Stargate SG-1 and Starship Troopers — had been completely dead in every browser since the security rules tightened. All 117 of them. Separately, brand-new sheets never ran their first-load skill fill. Both fixed; those buttons work again.
- Fixing the links then exposed a third fault hiding behind them, in the Mutants & Masterminds skill table: Auto Fill left every skill without its key ability, Clear did nothing, and sorting by ability threw an error. Also fixed — a new M&M sheet now fills all 32 skills with their abilities.
-
Pathfinder 2e: every other skill row ignored ability changes. Change Intelligence and Arcana would update while Crafting sat at +0 — alternating rows, which is a maddening thing to report. The cause was a genuinely subtle one: a pattern-matching flag that made the check stateful, so each successful match caused the next row to be skipped. It only started happening after the move to Idunn, because sheet data now arrives in a different order. Six of six intelligence skills now update.
-
A long sheet name hid the top of the sheet. The sheet’s top clearance was hard-coded to a value smaller than the actual header, so 27–40 pixels of every sheet sat underneath it where you couldn’t scroll to it. The clearance now measures the real header and follows it as it wraps.
-
On phones and tablets, sheets showed no name at all. The name lived in a collapsible section that had no button to expand it, so below a certain width it simply vanished. It now shows at every width, trimmed to one line on narrow screens.
-
Templates still showed old values — for real this time. We reported this fixed two weeks ago. It wasn’t, and the reporter told us so. The save was announcing itself; the announcement was being sent to the wrong place for any imported sheet, and a second fault meant some of those announcements were being dropped at connection time regardless. Both are fixed now.
The editor and posting
-
Insert Clone buried everything inside the clone’s table. Inserting a clone into a post that already had content dropped its pieces in one at a time, and after the clone’s drop-cap table the cursor was left inside that table — so everything after it went in there too. Into an empty post the same clone was fine, which is why it looked situational. Clones now arrive as one piece at the end of the document.
-
Queued card draws printed a UUID instead of the deck’s name. “Ezeze: draw 1 from 66c1daf0-…” now reads “Ezeze: draw 1 from Winter”.
Search and finding things
-
Load More skipped results. Every result type was being given the same position, so if page one showed you 12 posts and 8 topics, Load More started both at their 21st result — and posts 13–20 and topics 9–20 were never shown to anyone. Paging now tracks each type’s own position.
-
Game search results showed raw markup. Snippets were being cut from the stored source of a game’s description, so they came back full of
{"type":"paragraph"...or bbcode tags. Snippets are now built from the readable text. -
Help search answered with words you never typed. Searching “chance” returned “Email Change” — 44 results deep — and “rocket” matched “rocks” in the Dungeon Generator, because search terms were being chopped to four characters and matched as prefixes, and any passing mention in a page’s body was enough to make it an answer.
-
You couldn’t find a member’s blogs. Nothing on the site linked to them — profiles never mentioned blogs, and blog entries aren’t counted in the post count. Profiles now show a Blogs link, and
/users/<name>/blogsworks. The moderation staff also has better tools to find user content.
Games and storage
-
“Player View” didn’t apply to the Resources tab. A GM previewing their game as a player saw every Page, Download and Map with their own GM access — the one resource surface the original Player View work missed.
-
Non-members were told a game had no resources when it had resources they simply couldn’t see. The empty state now says resources are often member-only, without revealing whether any exist.
-
“Image falsely reports as in use and cannot be deleted.” Two images in the same thread both read “Used in Womp Rat”, so having removed one from the first post, there was no way to tell the other was still in the second. Where-used links now name the post: “Womp Rat (post #2)”.
-
Images attached to a game advertisement couldn’t be tracked down. Storage checked only posts, so an advertisement attachment read “in use” with no link to follow, and the owner had no way to find and remove it. Advertisements now link to the game’s Recruitment tab, and issue attachments to the issue.
-
“Remember Me not working.” Four different expiration timers governed a remembered sign-in, and they disagreed on how long they should last. Your session record on our side slid out to 30 days, but the cookie carrying it expired at 7 — and once the browser deletes that, there’s nothing left to renew from. So the 30-day session was unreachable and the real answer was: you get signed out after a week away. All four now agree on 30 days. Our own dashboard had been drawing this for months as a weekly sign-in spike, and we missed the significance until a weekly visitor called it out.
Three Ways Text Could Travel Too Far
All three were found by us, by auditing rather than by anything going wrong, and all three are fixed.
-
Private blocks were searchable. When a post is entirely a private block, there was nothing left for the search index to store — and an old fallback then indexed the raw post instead, hidden text and all. A search would return the post with an empty snippet, which is enough to confirm the word is in there. This affected roughly 145,000 posts. Both the reading and the writing side now refuse it.
-
A private game’s member forums were searchable by anyone while the game was recruiting. The setting is meant to say “people who have applied may read the game forums”, and it was instead granting that to any signed-in person who hadn’t applied — and a GM who turned the setting off couldn’t take it away. When we found it, no game was actually exposed, though 16 private games held draft advertisements that would have made it live the moment they published. Applicant access now means what the setting says it means.
-
The profile posts list was sending raw post bodies over the wire. The page itself only ever displayed a 150-character preview and threw the rest away, so nothing was visible in the browser, but the full body, private blocks and hidden spoilers included, was being sent to anyone who could see the post’s context. The excerpt is now cut on the server and the raw body is no longer sent at all.
Tools For Dealing With Spammers
Two spam accounts got through every signup control on September 16. Banning them stopped them from making content while we diagnosed and built better tools.
- Moderators can now remove a banned account’s content in one action — topics, posts, DMs, blogs, pages and downloads — with a preview of what will go, and a full Undo that restores exactly what was removed and nothing else. Established accounts (over 200 posts, or older than 90 days) need a community admin rather than a moderator, as a safety step.
- Blogs are now reportable, and moderators can delete a reported one. Previously a spam blog with no entries could only be reported via its owner’s profile, and even then no moderator could remove it.
As we said a couple of weeks ago, we looked at fixed limits on DMs and blog creation instead and decided against putting those limits in place. They’d catch too many of you going about your business. Giving staff a fast, reversible lever was the better trade, and we’re continuing to work on better detection methods so we can stop spammers before they annoy you.
Under The Floorboards
- Character sheet layouts became something we can actually author. The groundwork is in for sheets whose page layout is defined as data rather than baked into a template: page sizes that print correctly, layouts served and cached properly, and guards that refuse to render a layout whose fields don’t match the sheet. None of it is switched on for anyone yet; the first real use will be unifying the Pathfinder template.
- The database got its scheduled security patch, applied and verified. There was roughly 40 seconds of downtime in the middle of the night, US/Eastern time.
- A scheduling bug meant every background job was doing half its work. Both of our job servers were starting on exactly the same second after a deploy, so each pair of runs collided and one was thrown away. They now start at deliberately different offsets.
- Staff got a Background Jobs screen, which is how we noticed that the table recording job history had grown to 6.16 million rows with nothing ever cleaning it up. It now rolls up daily and prunes itself.
- The image rescue’s stranded retries are being re-run. Of the images we reported as unrecoverable, about 22,000 had failed for temporary reasons and were never retried. They’re queued now, deliberately slowly, and will work through by the end of the month.
Every Site Update So Far
-
Site Updates — Feature Freeze & the Road to Cutover, June 26 to June 30
-
This announcement
What’s Next
-
Search has changed — use it and tell us what’s wrong with it. Especially if a result that should be at the top isn’t. The ranking is deliberately provisional, and this week’s searches are what we’ll tune it against.
-
If you gave up on Auto Fill on an older sheet, try it again. Nine templates’ worth of buttons have been dead since the move and are now working.
-
If you were being signed out every week, you shouldn’t be any more. You’ll need to sign in once more for the longer session to take effect.
-
If you reported one of these sixteen, check it — and reopen the report if we missed. We got one wrong two weeks running, and the only reason it’s fixed now is that the reporter came back and said so.
Keep on weaving those myths!