|
1 | 1 | # Changelog |
2 | 2 |
|
| 3 | +## 1.2.0 |
| 4 | + |
| 5 | +### Changes |
| 6 | + |
| 7 | +- remove obsolete services and those which no longer support anonymous oembed from the suggestedAllowlist and suggestedEndpoints, to ensure they do not become a security risk in the future |
| 8 | +- update the fast-xml-parser dependency |
| 9 | + |
| 10 | +### Adds |
| 11 | + |
| 12 | +- add x.com endpoint |
| 13 | + |
3 | 14 | ## 1.1.4 (2024-08-07) |
4 | 15 |
|
5 | 16 | - Followup to 1.1.3: also hardcode the YouTube oembed endpoint for sharing URLs (`youtu.be`). |
|
33 | 44 | - Updates `cheerio` to the 1.0.0-rc version series to address a security vulnerability. |
34 | 45 |
|
35 | 46 | ## 1.0.0 |
| 47 | + |
36 | 48 | renamed the `whitelist` and `suggestedWhitelist` properties to `allowlist` and `suggestedAllowlist`, respectively. Also introduced support for `options.headers`. |
37 | 49 |
|
38 | 50 | ## 0.1.23 |
| 51 | + |
39 | 52 | workaround for YouTube bug in which video pages contain `http:` recommendations for oembed URLs, but an `http:` request is rejected with a 403 error. Force `https:` for YouTube. |
40 | 53 |
|
41 | 54 | ## 0.1.22 |
| 55 | + |
42 | 56 | fixed URL parsing bugs impacting use of preconfigured endpoints that already contain some query string parameters. |
43 | 57 |
|
44 | 58 | ## 0.1.21 |
| 59 | + |
45 | 60 | Updated links and information in the README. |
46 | 61 |
|
47 | 62 | ## 0.1.20 |
| 63 | + |
48 | 64 | fixed a nuisance error that was appearing when Facebook was present but `window` was not the default object. |
49 | 65 |
|
50 | 66 | ## 0.1.19 |
| 67 | + |
51 | 68 | unnecessary Facebook API logic was running on non-Facebook embeds due to a syntax mistake in 0.1.17. |
52 | 69 |
|
53 | 70 | ## 0.1.18 |
| 71 | + |
54 | 72 | report HTTP errors properly rather than attempting to parse a nonexistent JSON body. Also, always try/catch when parsing JSON and report the exception as the callback error if necessary. |
55 | 73 |
|
56 | 74 | ## 0.1.17 |
| 75 | + |
57 | 76 | Facebook oembed filter works regardless of whether Facebook's API has been initialized yet or not. |
58 | 77 |
|
59 | 78 | ## 0.1.16 |
| 79 | + |
60 | 80 | Built in filter that handles Facebook oembed responses. |
61 | 81 |
|
62 | 82 | ## 0.1.15 |
| 83 | + |
63 | 84 | allowlisted `facebook.com`, which has extensive oembed these days. |
64 | 85 |
|
65 | 86 | ## 0.1.14 |
| 87 | + |
66 | 88 | bumped `cheerio` dependency to fix deprecation warnings. No behavior changes. |
67 | 89 |
|
68 | 90 | ## 0.1.13 |
| 91 | + |
69 | 92 | relative URLs work with discovery. Thanks to Alejandro Torrado. |
70 | 93 |
|
71 | 94 | ## 0.1.12 |
| 95 | + |
72 | 96 | (unchanged, npm publishing issue) |
73 | 97 |
|
74 | 98 | ## 0.1.11 |
| 99 | + |
75 | 100 | don't crash when evaluating allowlists if `parsed.hostname` somehow manages not to be set. |
76 | 101 |
|
77 | 102 | ## 0.1.10 |
| 103 | + |
78 | 104 | user agent string to please Facebook. Thanks to `equinox7`. |
79 | 105 |
|
80 | 106 | ## 0.1.9 |
| 107 | + |
81 | 108 | the new `endpoints` option allows you to configure custom oembed API endpoints for services that don't advertise an endpoint or advertise it incorrectly. |
82 | 109 |
|
83 | 110 | ## 0.1.7-0.1.8 |
| 111 | + |
84 | 112 | support SoundCloud. Added it to the suggested allowlist and added tolerance for their incorrect JSON content type. |
85 | 113 |
|
86 | 114 | ## 0.1.6 |
| 115 | + |
87 | 116 | security improvement: |
88 | 117 | reject all URLs that are not `http:` or `https:` completely, right up front. This means you don't have to protect against these obvious hacks in your `before` and `after` handlers. |
89 | 118 |
|
90 | 119 | ## 0.1.5 |
| 120 | + |
91 | 121 | packaging issues, no changes. |
92 | 122 |
|
93 | 123 | ## 0.1.4 |
| 124 | + |
94 | 125 | if the URL leads to a page with no oembed metadata, look for a `link rel="canonical"` tag and try that URL instead. Don't pursue this more than one step. |
95 | 126 |
|
96 | 127 | Also, specify a user agent so that certain hosts don't give us watered-down HTML. |
97 | 128 |
|
98 | 129 | ## 0.1.3 |
| 130 | + |
99 | 131 | added `youtu.be` to the suggested allowlist. |
0 commit comments