Skip to content
Snippets Groups Projects
Closed Youtube Video on landing page blocked by CSP
  • View options
  • Youtube Video on landing page blocked by CSP

  • View options
  • Closed Issue created by Peter Tönnies

    Summary

    To protect us from inline script injection, have introduced CSP rules that are respected by the browser. As a result, the browser may only open content that is shared by us.

    On the CSP whitelist are currently:

    Steps to reproduce

    • Visit landing page
    • Click on the offered video

    What is the current bug behavior?

    Thus, the Youtube video on the home page https://foodsharing.de not be displayed.

    What is the expected correct behavior?

    Should be shown

    Relevant error messages and/or screenshots

    Technical data from Sentry:

    Possible fixes

    The following options could be available:

    1. Whitelist Youtube via the CSP rules
    2. Load the video into our server. Traffic? Video is only loaded if it is also clicked.
    3. Video is not embedded, but only opened a new tab in Youtube.
    Edited by Christian Walgenbach

    Linked items 0

  • Link items together to show that they're related or that one is blocking others.

    Activity

    • All activity
    • Comments only
    • History only
    • Newest first
    • Oldest first
    Loading Loading Loading Loading Loading Loading Loading Loading Loading Loading