[QA] §Q Inline media embeds: facade, one of each provider, TikTok portrait, post self-resize, Bluesky/Loom/Kick, toggle + cap #186
Closed
opened 2026-09-17 23:24:09 -04:00 by jared
·
1 comment
No Branch/Tag Specified
lotus
update-packages
sw-fix
read-me-update
image-path-changes
dm-calls
fix-2469
renovate/element-hq-element-call-embedded-0.x
renovate/npm-i18next-http-backend-vulnerability
renovate/npm-vite-vulnerability
dev
docs-update
more-theme
fix-257
imporve-thread-reply
revert-2402-improve-menu-congestion
mxidColor-toggle
update-sw-main-msg
v4.11.1
v4.10.5
v4.10.4
v4.10.3
v4.10.2
v4.10.1
v4.10.0
v4.9.1
v4.9.0
v4.8.1
v4.8.0
v4.7.1
v4.7.0
v4.6.0
v4.5.1
v4.5.0
v4.4.0
v4.3.2
v4.3.0
v4.2.3
v4.2.2
v4.2.1
v4.2.0
v4.1.0
v4.0.3
v4.0.0
v3.2.0
v3.1.0
v3.0.0
v2.2.6
v2.2.5
v2.2.4
v2.2.3
v2.2.2
v2.2.1
v2.2.0
v2.1.3
v2.1.2
v2.1.1
v2.1.0
v2.0.4
v2.0.3
v2.0.2
v2.0.1
v2.0.0
v1.8.2
v1.8.1
v1.8.0
v1.7.0
v1.6.1
v1.6.0
v1.5.1
v1.5.0
v1.4.0
v1.3.2
v1.3.1
v1.3.0
v1.2.1
v1.2.0
v1.1.0
v1.0.0
Labels
Clear labels
a11y
area: appearance
area: auth-session
area: build-ci
area: calls
area: desktop
area: media
area: messaging
area: mobile
area: moderation
area: navigation
area: notifications
area: settings
area: threads
bug
dependencies
docs
duplicate
enhancement
help wanted
invalid
needs-human-review
performance
planning
priority: critical
priority: high
priority: low
priority: medium
qa
question
research
security
tech-debt
ux
wontfix
Accessibility: keyboard, screen reader, contrast, motion
Client area: appearance
Client area: auth-session
Client area: build-ci
Client area: calls
Client area: desktop
Client area: media
Client area: messaging
Client area: mobile
Client area: moderation
Client area: navigation
Client area: notifications
Client area: settings
Client area: threads
Something is not working
Third-party package versions and advisories
README / LOTUS_* docs wrong or missing
This issue or pull request already exists
New feature
Need some help
Something is wrong
Re-render storms, leaks, heavy work on hot paths
Data loss, security hole, or crash on a main path
Broken feature or serious usability problem
Minor issue or polish
Wrong behaviour in an edge case or notable degradation
Manual QA: shipped, needs a human in a real environment
More information is needed
XSS, unsafe URLs, data leaks, auth/session
Code health, dead code, fragile patterns
Usability or visual inconsistency
This won't be fixed
Milestone
No items
No Milestone
Manual QA backlog
Projects
Clear projects
No projects
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: LotusGuild/cinny#186
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Migrated from
LOTUS_TESTING.md§Q on 2026-09-17 — the file is now reference-only.How to report: tick each item as it passes; on FAIL comment with what you saw vs expected, browser/OS, web (chat.lotusguild.org) vs desktop (Tauri), theme, and any browser-console errors. Screenshots for anything visual.
Checklist
The whole feature is behind Settings → General → "Inline Media Players" (default on). Everything loads from the homeserver's cached thumbnail first; the third-party player only mounts on Play. Test on the web build first, then re-check the video ones on desktop (Tauri) since the CSP differs. On any failure, grab the browser console (F12) — a blocked embed shows as a CSP
frame-srcviolation naming the host.Q1. Facade + one of each kind plays in place
Paste each of these into a room and confirm a media tile (not a plain link) with a thumbnail + play button, and that clicking Play mounts the player inline:
watchlink, a Vimeo link, a Dailymotion link, a Streamable link, a Twitch VOD/clip, a Loomsharelink.Expected: ✅ tile shows the thumbnail; no request to the third party until you press Play (check DevTools → Network); the player then plays inline. ❌ tell me any that stay a plain link, show a blank frame, or hit the network before you click.
Q2. TikTok (the tricky one) + portrait fill
vm.tiktok.com/…ortiktok.com/t/…).Expected: both resolve to a clean 9:16 player that fills the box (no big empty band on the right). The short link shows a brief spinner while it resolves via oEmbed, then plays. ❌ tell me if a short link shows only the TikTok logo/♫ and never a play button, or if the player has dead space beside it.
Q3. Post self-resize + Close / Fullscreen controls
Expected: the card grows to fit the post (no clipped/scrollbarless content, no giant empty box). A Close button (✕) collapses the player back to the thumbnail; video players also show a ⛶ Fullscreen control that works. Keyboard: Tab to the play button → it shows a visible focus ring.
Q4. New providers (unverified) + the toggle + the cap
bsky.app/profile/…/post/…, aloom.com/share/…, and a livekick.com/{channel}link. ✅ good if each plays/renders inline; ❌ if any is a broken frame (for Bluesky especially, note whether a handle URL resolves or only a DID one does — grab the console).Verified on the local dev homeserver with Playwright (URL previews enabled on the dev Synapse so the facades get their homeserver-proxied thumbnails), counting every non-local host the page contacts:
<iframe>in the timeline before any click ✓localhostmedia thumbnail of the URL preview), not the provider ✓<iframe>onwww.youtube-nocookie.com; only then is that host contacted; Fullscreen + Close controls appear ✓ (the video itself said "unavailable" because YouTube refuses embeds from a127.0.0.1origin — not a client issue)Prod CSP for the player frames (
frame-src 'self' https:) is unchanged. Closing; the Google Fonts leak is #214.