Go to main content

Textpattern CMS support forum

You are not logged in. Register | Login | Help

#1 Yesterday 12:28:04

colak
Admin
From: Cyprus
Registered: 2004-11-20
Posts: 9,337
Website GitHub Mastodon Twitter

Referrer-Policy and youtube

Just a heads up that YouTube embedded videos no longer load when we have Header always set Referrer-Policy "strict-origin-when-cross-origin" in our Security Headers. A way around it is to make an exception:

Header always set Referrer-Policy "strict-origin-when-cross-origin"
SetEnvIf Referer "https?://(www\.)?youtube\.com" is_youtube
Header set Referrer-Policy "same-origin" env=is_youtube

Yiannis
——————————
NeMe | hblack.art | EMAP | A Sea change | Toolkit of Care
I do my best editing after I click on the submit button.

Offline

#2 Today 06:31:25

phiw13
Plugin Author
From: South-Western Japan
Registered: 2004-02-27
Posts: 3,515
Website

Re: Referrer-Policy and youtube

That is interesting. It is strange as the few YT videos we have embedded all display fine, with Referrer-Policy "strict-origin-when-cross-origin". All use the youtube-nocookie URL though, not sure if that matters.

Here is an example – does the video play (solo by Bass player Bernard Santacruz) play on your side?

PS I really should add referrerpolicy='strict-origin-when-cross-origin' to the embed cde to work around the “Error 153” I often see in feed readers

Last edited by phiw13 (Today 06:32:06)


Where is that emoji for a solar powered submarine when you need it ?
Sand space – admin theme for Textpattern
phiw13 on Codeberg

Offline

#3 Today 09:12:48

colak
Admin
From: Cyprus
Registered: 2004-11-20
Posts: 9,337
Website GitHub Mastodon Twitter

Re: Referrer-Policy and youtube

I forgot the error I got, but it was 17x I think. Searching for it, revealed that YT wants to detect the referrer of the embedded video exactly, otherwise it does not load the embed.

After adding the directive above, all is working as intended.

I also use the no-cookie url too.

Your video loads just fine from here.


Yiannis
——————————
NeMe | hblack.art | EMAP | A Sea change | Toolkit of Care
I do my best editing after I click on the submit button.

Offline

#4 Today 11:18:28

phiw13
Plugin Author
From: South-Western Japan
Registered: 2004-02-27
Posts: 3,515
Website

Re: Referrer-Policy and youtube

Thanks. That needs keeping an eye on…

This afternoon I noticed that YT now adds referrerpolicy='strict-origin-when-cross-origin' to the suggested embed coded for both youtube and youtube-nocooke URL’s. That is fairly recent I think (haven’t had to add YT videos for a while).


Where is that emoji for a solar powered submarine when you need it ?
Sand space – admin theme for Textpattern
phiw13 on Codeberg

Offline

Board footer

Powered by FluxBB