Skip to content

Commit 9e92146

Browse files
authored
mergeback (#5415)
* allow oembetter to be released (#5412) * release oembetter 1.2.0 (#5413) * release oembetter 1.2.0 * left commit
1 parent e9b0ab0 commit 9e92146

2 files changed

Lines changed: 33 additions & 1 deletion

File tree

‎packages/oembetter/CHANGELOG.md‎

Lines changed: 32 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,16 @@
11
# Changelog
22

3+
## 1.2.0
4+
5+
### Changes
6+
7+
- remove obsolete services and those which no longer support anonymous oembed from the suggestedAllowlist and suggestedEndpoints, to ensure they do not become a security risk in the future
8+
- update the fast-xml-parser dependency
9+
10+
### Adds
11+
12+
- add x.com endpoint
13+
314
## 1.1.4 (2024-08-07)
415

516
- Followup to 1.1.3: also hardcode the YouTube oembed endpoint for sharing URLs (`youtu.be`).
@@ -33,67 +44,88 @@
3344
- Updates `cheerio` to the 1.0.0-rc version series to address a security vulnerability.
3445

3546
## 1.0.0
47+
3648
renamed the `whitelist` and `suggestedWhitelist` properties to `allowlist` and `suggestedAllowlist`, respectively. Also introduced support for `options.headers`.
3749

3850
## 0.1.23
51+
3952
workaround for YouTube bug in which video pages contain `http:` recommendations for oembed URLs, but an `http:` request is rejected with a 403 error. Force `https:` for YouTube.
4053

4154
## 0.1.22
55+
4256
fixed URL parsing bugs impacting use of preconfigured endpoints that already contain some query string parameters.
4357

4458
## 0.1.21
59+
4560
Updated links and information in the README.
4661

4762
## 0.1.20
63+
4864
fixed a nuisance error that was appearing when Facebook was present but `window` was not the default object.
4965

5066
## 0.1.19
67+
5168
unnecessary Facebook API logic was running on non-Facebook embeds due to a syntax mistake in 0.1.17.
5269

5370
## 0.1.18
71+
5472
report HTTP errors properly rather than attempting to parse a nonexistent JSON body. Also, always try/catch when parsing JSON and report the exception as the callback error if necessary.
5573

5674
## 0.1.17
75+
5776
Facebook oembed filter works regardless of whether Facebook's API has been initialized yet or not.
5877

5978
## 0.1.16
79+
6080
Built in filter that handles Facebook oembed responses.
6181

6282
## 0.1.15
83+
6384
allowlisted `facebook.com`, which has extensive oembed these days.
6485

6586
## 0.1.14
87+
6688
bumped `cheerio` dependency to fix deprecation warnings. No behavior changes.
6789

6890
## 0.1.13
91+
6992
relative URLs work with discovery. Thanks to Alejandro Torrado.
7093

7194
## 0.1.12
95+
7296
(unchanged, npm publishing issue)
7397

7498
## 0.1.11
99+
75100
don't crash when evaluating allowlists if `parsed.hostname` somehow manages not to be set.
76101

77102
## 0.1.10
103+
78104
user agent string to please Facebook. Thanks to `equinox7`.
79105

80106
## 0.1.9
107+
81108
the new `endpoints` option allows you to configure custom oembed API endpoints for services that don't advertise an endpoint or advertise it incorrectly.
82109

83110
## 0.1.7-0.1.8
111+
84112
support SoundCloud. Added it to the suggested allowlist and added tolerance for their incorrect JSON content type.
85113

86114
## 0.1.6
115+
87116
security improvement:
88117
reject all URLs that are not `http:` or `https:` completely, right up front. This means you don't have to protect against these obvious hacks in your `before` and `after` handlers.
89118

90119
## 0.1.5
120+
91121
packaging issues, no changes.
92122

93123
## 0.1.4
124+
94125
if the URL leads to a page with no oembed metadata, look for a `link rel="canonical"` tag and try that URL instead. Don't pursue this more than one step.
95126

96127
Also, specify a user agent so that certain hosts don't give us watered-down HTML.
97128

98129
## 0.1.3
130+
99131
added `youtu.be` to the suggested allowlist.

‎packages/oembetter/package.json‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
{
22
"name": "oembetter",
3-
"version": "1.1.4",
3+
"version": "1.2.0",
44
"description": "A modern oembed client. Allows you to register filters to improve or supply oembed support for sites that don't normally have it. You can also supply a allowlist of services you trust to prevent XSS attacks.",
55
"main": "index.js",
66
"scripts": {

0 commit comments

Comments
 (0)