Problem/Motivation
When an oEmbed provider is disabled on a Media bundle, Media continues to render the provider's content. Media fails to check if the provider is still allowed. Since the list of enabled oEmbed providers is effectively an iFrame whitelist, this should be documented and disclosed to site builders as it is a security risk.
Proposed resolution
- Add language to README.md
- Add a warning atop the 'Allowed Providers' config page
- Add a warning in the 'Media Source Configuration' fieldset on Media bundles where the Media source is 'Remote video'
Remaining tasks
Write patch
User interface changes
Warnings added as described above.
API changes
None
Data model changes
None
Release notes snippet
None
| Comment | File | Size | Author |
|---|---|---|---|
| #4 | oembed_providers-disabled_provider_warning-3129135-4.patch | 3.38 KB | chris burge |
Comments
Comment #2
chris burge commentedPatch attached
Comment #4
chris burge commentedUpdated patch with
disabledProviderSecurityWarningbeing static.Comment #5
chris burge commentedComment #7
chris burge commented