Opened 11 months ago

Last modified 3 weeks ago

#28783 new defect

Incomplete Content-Security-Policy blocks video on "Set up Relays" page

Reported by: darkspirit Owned by: hiro
Priority: Medium Milestone:
Component: Webpages/Website Version:
Severity: Normal Keywords:
Cc: traumschule, ggus, steph Actual Points:
Parent ID: Points:
Reviewer: Sponsor:


Affected page:

Problem: "No video with supported format and MIME type found"
The video's URL is and forbidden by CSP.

Solution: Change

Content-Security-Policy: default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'



Content-Security-Policy: default-src 'self'; style-src 'self' 'unsafe-inline'; media-src 'self'

or even to

Content-Security-Policy: default-src 'self'; style-src 'self' 'unsafe-inline'; media-src 'self'; frame-ancestors 'self'; block-all-mixed-content; disown-opener; plugin-types application/pdf; base-uri 'self'

Child Tickets

Change History (3)

comment:1 Changed 3 months ago by pili

Cc: ggus added

ggus: do you think we should move this to the community portal?
hiro: is it possible to embed video in lektor?

Otherwise we should close as wontfix

comment:2 Changed 2 months ago by ggus

The video is nice, if we upload to youtube, we can link somewhere in relay-operations/community resources.

comment:3 Changed 3 weeks ago by pili

Cc: steph added

Who can upload these videos to our youtube account?

Note: See TracTickets for help on using tickets.