Uploaded image for project: 'Sakai'
  1. Sakai
  2. SAK-39969

h5p, sharestream, kaltura antisamy whitelists aren't working

    XMLWordPrintable

    Details

    • Type: Bug
    • Status: RESOLVED
    • Priority: Major
    • Resolution: Fixed
    • Affects Version/s: 12.5, 19.0
    • Fix Version/s: 12.6, 19.0
    • Component/s: Kernel
    • Labels:
      None
    • 12 status:
      Resolved
    • Test Plan:
      Hide
      • go to the lessons tool
      • click Add Content
      • click Embed Content on page
      • in the input box,"Or add a URL or "embed code", paste in either the h5p or kaltura code below
      • click save
      • The embedded video should appear on the page
      Show
      go to the lessons tool click Add Content click Embed Content on page in the input box,"Or add a URL or "embed code", paste in either the h5p or kaltura code below click save The embedded video should appear on the page

      Description

      h5p, sharestream, kaltura antisamy whitelists aren't working

      even though those sites are added to the antisamy/high-security-policy.xml whitelist, embedding their embed codes in e.g. lessons does not work

      Actually, I could not test sharestream because I don't have an account with them, but it appears as though it would be affected by the bug as well.

      it fails on https://trunk-mysql.nightly.sakaiproject.org/

       

      <iframe src="https://h5p.org/h5p/embed/617" width="1090" height="674" frameborder="0" allowfullscreen="allowfullscreen"></iframe><script src="https://h5p.org/sites/all/modules/h5p/library/js/h5p-resizer.js" charset="UTF-8"></script>
      
      <iframe id="kaltura_player" src="https://cdnapisec.kaltura.com/p/811441/sp/81144100/embedIframeJs/uiconf_id/32783592/partner_id/811441?iframeembed=true&playerId=kaltura_player&entry_id=0_zjhsoogr&flashvars[streamerType]=auto&amp;flashvars[localizationCode]=en&amp;flashvars[leadWithHTML5]=true&amp;flashvars[sideBarContainer.plugin]=true&amp;flashvars[sideBarContainer.position]=left&amp;flashvars[sideBarContainer.clickToClose]=true&amp;flashvars[chapters.plugin]=true&amp;flashvars[chapters.layout]=vertical&amp;flashvars[chapters.thumbnailRotator]=false&amp;flashvars[streamSelector.plugin]=true&amp;flashvars[EmbedPlayer.SpinnerTarget]=videoHolder&amp;flashvars[dualScreen.plugin]=true&amp;&wid=0_30b2z72n" width="400" height="285" allowfullscreen webkitallowfullscreen mozAllowFullScreen allow="autoplay; fullscreen; encrypted-media" frameborder="0" title="Kaltura Player"></iframe>
      

        Gliffy Diagrams

          Attachments

            Issue Links

              Activity

                People

                • Assignee:
                  maintenanceteam Core Team
                  Reporter:
                  austinUH Austin
                • Votes:
                  0 Vote for this issue
                  Watchers:
                  2 Start watching this issue

                  Dates

                  • Created:
                    Updated:
                    Resolved:

                    Git Source Code