Expose a way to suppress oEmbed security warnings

Created on 20 April 2018, almost 7 years ago
Updated 6 July 2023, over 1 year ago

Problem/Motivation

In #2831944-187: Implement media source plugin for remote video via oEmbed , @dawehner raised this point about the fact that Media will warn site administrators (via the status page), if they are displaying remote oEmbed resources in an iframe served from the same domain as the main Drupal site:

I'm curious whether we could somehow instead of a warning ensure that people at least checked a checkbox to know that they are doing something insecure.

Should site administrators be allowed to permanently acknowledge, and therefore suppress, this legitimate and actionable security warning? If so, how would we go about doing that?

Proposed resolution

TBD.

Remaining tasks

Discuss whether we should do this at all, and possibly implement a patch.

User interface changes

TBD.

API changes

TBD.

Data model changes

TBD.

Feature request
Status

Active

Version

11.0 🔥

Component
Media 

Last updated about 13 hours ago

Created by

🇺🇸United States phenaproxima Massachusetts

Live updates comments and jobs are added and updated live.
  • Security

    It is used for security vulnerabilities which do not need a security advisory. For example, security issues in projects which do not have security advisory coverage, or forward-porting a change already disclosed in a security advisory. See Drupal’s security advisory policy for details. Be careful publicly disclosing security vulnerabilities! Use the “Report a security vulnerability” link in the project page’s sidebar. See how to report a security issue for details.

  • Usability

    Makes Drupal easier to use. Preferred over UX, D7UX, etc.

Sign in to follow issues

Merge Requests

Comments & Activities

Not all content is available!

It's likely this issue predates Contrib.social: some issue and comment data are missing.

Production build 0.71.5 2024