Skip to content

v1.3.0

Latest

Choose a tag to compare

@karl-bullock karl-bullock released this 27 Sep 19:29
· 1 commit to main since this release
4d5f828

Embeds are back, for the hosts you choose

Version 1.1.0 started sanitising the widget's HTML, and that stripped every <iframe> along with it. It closed a real hole, but it also took away the main reason people reach for an HTML widget: a YouTube video, a map, an embedded form. This release brings embeds back, from the places you name and nowhere else.

There is a new Allowed iframe hosts box on the extension's settings page. Put one host on each line:

www.youtube.com
*.vimeo.com

An embed is kept only if it loads from a host on that list. A plain entry matches that host exactly. A *. prefix matches any subdomain, so *.vimeo.com covers player.vimeo.com but not vimeo.com by itself, and you can list both if you need both.

The box starts empty, and an empty box strips every iframe exactly as it does today. Nothing changes on your forum until you decide to allow something.

Three things the setting deliberately cannot switch off. Only http and https embeds are ever kept. Script tags, event-handler attributes and javascript: links are still removed as before. And an iframe carrying its own HTML instead of a web address is always dropped, because there would be no address to check against your list.

One thing worth knowing: the checking happens in your visitors' browsers. Treat the allowlist as a guard against pasting something you did not mean to, rather than as a security boundary. Anyone who can edit this setting is already an administrator of your forum.

After updating

Run php flarum cache:clear, so the rebuilt assets are the ones your visitors get.