We were not hacked. The site was taken down preemptively for security measures. Are we ok? Yet to be determined fully.
Incident response on the available systems and data, show attempted XSS comments sourced from federated instances; none on Beehaw itself. Those were deleted from our Beehaw database. Additional security measures put in place to try and mitigate XSS and other Web based exploits. Changed the Content-Security-Policy to be more strict (might break some apps). Secrets for tokens and salting passwords were changed on the backend. You shouldn't need to change your password, but it can't hurt at this point.
If you're unable to login on Firefox:
* Open Beehaw website, tools -> more tools -> web developer tools
* Delete EVERYTHING for cache, cookies, indexed db, local storage, session storage
* Ctrl+F5 the page and try to login again.