-
-
Notifications
You must be signed in to change notification settings - Fork 4.1k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. Weβll occasionally send you account related emails.
Already on GitHub? Sign in to your account
no shared audio and video embedding #10174
Comments
Because we need to re-encode the content otherwise attackers could inject malicious code and it then looks like the nextcloud server itself is the source of that code. Usually this is fixed by other services by serving user content from a different domain, but as we don't have this in Nextcloud and we serve everything from one domain it would be easier for attackers to server malicious files and do further attacks. That's also the reason, why the real untouched files are always downloaded and never shown inline, because this is the only way to work around this attack beside re-encoding. |
@rullzer @nickvergessen Correct me if I'm wrong. |
That is correct! |
sounds reasonable π€ |
Just to make it clear:
or in case of shared folder you need to embed one particular file
There is no need to make direct link on previews. |
So since #2523 and resulting #6599 we can embed link-shared images into external web sites, which is awesome π
I wonder, why this
β¦/preview
URL is only available for images, but not for audio and video files, or any other file type. Any clues?The text was updated successfully, but these errors were encountered: