diaspora/config/oembed_providers.yml
Jonne Haß 91c734e4fc Avoid mixed content warning through oEmbed content
- Switch dailymotion oEmbed endpoint to https
- Accept Mixcloud https URLs
- Accept dailymotion https URLs
2014-11-19 15:48:12 +01:00

21 lines
651 B
YAML

# SECURITY NOTICE! CROSS-SITE SCRIPTING!
# these endpoints may inject html code into our page
# note that 'endpoint' is the only information
# in OEmbed that we can trust. anything else may be spoofed!
daily_motion:
endpoint: "https://www.dailymotion.com/services/oembed"
urls:
- http://www.dailymotion.com/video/*
- https://www.dailymotion.com/video/*
twitter:
endpoint: "https://api.twitter.com/1/statuses/oembed.json"
urls:
- http://twitter.com/*/status/*
- https://twitter.com/*/status/*
mixcloud:
endpoint: "http://www.mixcloud.com/oembed/"
urls:
- http://www.mixcloud.com/*/*
- https://www.mixcloud.com/*/*