Skip to content

Commit e9b3bac

Browse files
authored
PRO-9467: remove defunct and nonpublic oembed providers and improve developer control to ensure security in the future (no risk exists today) (#5400)
* PRO-9467: remove defunct and nonpublic oembed providers and improve developer control to ensure security in the future (no risk exists today) * allow newer twitter domain * infogr.am still around * facebook no longer does oembed
1 parent 7ab9961 commit e9b3bac

3 files changed

Lines changed: 42 additions & 40 deletions

File tree

‎.changeset/wild-forks-fetch.md‎

Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
---
2+
"apostrophe": minor
3+
---
4+
5+
apostrophe and oembetter have been updated to eliminate a number of services that formerly supported
6+
oembed for the general public, but no longer do so. While there is no security risk today, removing
7+
these ensures that if these domains are ever allowed to lapse, they do not become an XSS
8+
attack vector in the future.
9+
10+
Because oembed responses are not always iframes, it is important that this list be maintained
11+
over time. In addition, developers always have the option to prune it on their own by setting
12+
the new minimumAllowlist and minimumEndpoints options of the @apostrophecms/oembed module.
13+
14+
Thanks to [Sainithin0309](https://github.com/Sainithin0309) for pointing out the potential
15+
long-term security concern.

‎packages/apostrophe/modules/@apostrophecms/oembed/index.js‎

Lines changed: 18 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -16,10 +16,13 @@ const cheerio = require('cheerio');
1616
// widely trusted sites are already allowlisted.
1717
//
1818
// Your `allowlist` option is concatenated with `oembetter`'s standard
19-
// allowlist, plus wufoo.com, infogr.am, and slideshare.net.
19+
// allowlist, plus wufoo.com, infogr.am and slideshare.net.
2020
//
2121
// Your `endpoints` option is concatenated with `oembetter`'s standard
2222
// endpoints list.
23+
//
24+
// If you wish to completely override the behavior, set
25+
// `minimumAllowlist` and `minimumEndpoints` instead.
2326

2427
module.exports = {
2528
options: {
@@ -42,28 +45,30 @@ module.exports = {
4245
// Don't permit oembed of untrusted sites, which could
4346
// lead to XSS attacks
4447

45-
self.oembetter.allowlist(self.oembetter.suggestedAllowlist.concat(
46-
self.options.allowlist || [],
47-
[
48-
'wufoo.com',
49-
'infogr.am',
50-
'slideshare.net'
51-
])
52-
);
48+
const minimumAllowlist = self.options.minimumAllowlist || [
49+
...self.oembetter.suggestedAllowlist,
50+
'wufoo.com',
51+
'infogr.am',
52+
'slideshare.net'
53+
];
54+
55+
self.oembetter.allowlist(minimumAllowlist.concat(self.options.allowlist || []));
56+
57+
const minimumEndpoints = self.options.minimumEndpoints || self.oembetter.suggestedEndpoints;
5358
self.oembetter.endpoints(
54-
self.oembetter.suggestedEndpoints.concat(self.options.endpoints || [])
59+
minimumEndpoints.concat(self.options.endpoints || [])
5560
);
5661
},
5762

5863
// Enhances oembetter to support services better or to support services
59-
// that have no oembed support by default. Called by `afterConstruct`.
60-
// Extend this method to add additional `oembetter` filters.
64+
// that have no oembed support by default.
65+
//
66+
// Extend or override this method to change or add oembetter filters.
6167

6268
enhanceOembetter() {
6369
require('./lib/youtube.js')(self, self.oembetter);
6470
require('./lib/vimeo.js')(self, self.oembetter);
6571
require('./lib/wufoo.js')(self, self.oembetter);
66-
require('./lib/infogram.js')(self, self.oembetter);
6772
},
6873

6974
// This method fetches the specified URL, determines its best embedded

‎packages/oembetter/index.js‎

Lines changed: 9 additions & 27 deletions
Original file line numberDiff line numberDiff line change
@@ -187,41 +187,15 @@ module.exports = function(options) {
187187
self.suggestedAllowlist = [
188188
'youtube.com',
189189
'youtu.be',
190-
'blip.tv',
191190
'dailymotion.com',
192191
'flickr.com',
193-
'hulu.com',
194-
'nfb.ca',
195-
'qik.com',
196-
'revision3.com',
197-
'scribd.com',
198-
'viddler.com',
199192
'vimeo.com',
200-
'youtube.com',
201-
'dotsub.com',
202-
'yfrog.com',
203-
'photobucket.com',
204193
'soundcloud.com',
205-
'instagram.com',
206194
'twitter.com',
207-
'facebook.com'
195+
'x.com'
208196
];
209197

210198
self.suggestedEndpoints = [
211-
{
212-
domain: 'instagram.com',
213-
endpoint: 'http://api.instagram.com/oembed'
214-
},
215-
{
216-
domain: 'facebook.com',
217-
path: /\/videos\//,
218-
endpoint: 'https://www.facebook.com/plugins/video/oembed.json/'
219-
},
220-
{
221-
domain: 'facebook.com',
222-
path: /\/posts\//,
223-
endpoint: 'https://www.facebook.com/plugins/post/oembed.json/'
224-
},
225199
{
226200
domain: 'vimeo.com',
227201
endpoint: 'https://vimeo.com/api/oembed.json'
@@ -233,6 +207,14 @@ module.exports = function(options) {
233207
{
234208
domain: 'youtu.be',
235209
endpoint: 'https://www.youtube.com/oembed'
210+
},
211+
{
212+
domain: 'twitter.com',
213+
endpoint: 'https://publish.twitter.com/oembed'
214+
},
215+
{
216+
domain: 'x.com',
217+
endpoint: 'https://publish.twitter.com/oembed'
236218
}
237219
];
238220

0 commit comments

Comments
 (0)