-
Notifications
You must be signed in to change notification settings - Fork 1
fix: add missing origin parameter for YouTube iframe API security #31
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
- Pass webViewUrl as origin parameter to resolve iframe API restrictions - Fix embed access issues when enablejsapi=1 is used
🦋 Changeset detectedLatest commit: 1d3e3d8 The changes in this PR will be included in the next version bump. This PR includes changesets to release 1 package
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
WalkthroughThis update introduces the handling of the Changes
Sequence Diagram(s)sequenceDiagram
participant Browser
participant App (web/src/App.tsx)
participant useYoutubePlayer Hook
participant YouTubePlayerCore
participant YouTube Iframe API
Browser->>App (web/src/App.tsx): Loads page with URL (may include ?origin=...)
App (web/src/App.tsx)->>useYoutubePlayer Hook: Passes playerVars (including origin)
useYoutubePlayer Hook->>YouTubePlayerCore: Initializes player with playerVars (origin included)
YouTubePlayerCore->>YouTube Iframe API: Creates player with enablejsapi=1 and origin param
YouTube Iframe API-->>YouTubePlayerCore: Validates and sets up player
Poem
📜 Recent review detailsConfiguration used: CodeRabbit UI 📒 Files selected for processing (5)
🧰 Additional context used🧬 Code Graph Analysis (1)src/utils/youtube.ts (1)
🔇 Additional comments (11)
✨ Finishing Touches
🪧 TipsChatThere are 3 ways to chat with CodeRabbit:
SupportNeed help? Create a ticket on our support page for assistance with any issues or questions. Note: Be mindful of the bot's finite context window. It's strongly recommended to break down tasks such as reading entire modules into smaller chunks. For a focused discussion, use review comments to chat about specific files and their changes, instead of using the PR comments. CodeRabbit Commands (Invoked using PR comments)
Other keywords and placeholders
CodeRabbit Configuration File (
|
Summary by CodeRabbit