Inline media embeds: remaining providers (low priority) #200
Open
opened 2026-09-17 23:24:15 -04:00 by jared
·
0 comments
No Branch/Tag Specified
lotus
update-packages
sw-fix
read-me-update
image-path-changes
dm-calls
fix-2469
renovate/element-hq-element-call-embedded-0.x
renovate/npm-i18next-http-backend-vulnerability
renovate/npm-vite-vulnerability
dev
docs-update
more-theme
fix-257
imporve-thread-reply
revert-2402-improve-menu-congestion
mxidColor-toggle
update-sw-main-msg
v4.11.1
v4.10.5
v4.10.4
v4.10.3
v4.10.2
v4.10.1
v4.10.0
v4.9.1
v4.9.0
v4.8.1
v4.8.0
v4.7.1
v4.7.0
v4.6.0
v4.5.1
v4.5.0
v4.4.0
v4.3.2
v4.3.0
v4.2.3
v4.2.2
v4.2.1
v4.2.0
v4.1.0
v4.0.3
v4.0.0
v3.2.0
v3.1.0
v3.0.0
v2.2.6
v2.2.5
v2.2.4
v2.2.3
v2.2.2
v2.2.1
v2.2.0
v2.1.3
v2.1.2
v2.1.1
v2.1.0
v2.0.4
v2.0.3
v2.0.2
v2.0.1
v2.0.0
v1.8.2
v1.8.1
v1.8.0
v1.7.0
v1.6.1
v1.6.0
v1.5.1
v1.5.0
v1.4.0
v1.3.2
v1.3.1
v1.3.0
v1.2.1
v1.2.0
v1.1.0
v1.0.0
Labels
Clear labels
a11y
area: appearance
area: auth-session
area: build-ci
area: calls
area: desktop
area: media
area: messaging
area: mobile
area: moderation
area: navigation
area: notifications
area: settings
area: threads
bug
dependencies
docs
duplicate
enhancement
help wanted
invalid
needs-human-review
performance
planning
priority: critical
priority: high
priority: low
priority: medium
qa
question
research
security
tech-debt
ux
wontfix
Accessibility: keyboard, screen reader, contrast, motion
Client area: appearance
Client area: auth-session
Client area: build-ci
Client area: calls
Client area: desktop
Client area: media
Client area: messaging
Client area: mobile
Client area: moderation
Client area: navigation
Client area: notifications
Client area: settings
Client area: threads
Something is not working
Third-party package versions and advisories
README / LOTUS_* docs wrong or missing
This issue or pull request already exists
New feature
Need some help
Something is wrong
Re-render storms, leaks, heavy work on hot paths
Data loss, security hole, or crash on a main path
Broken feature or serious usability problem
Minor issue or polish
Wrong behaviour in an edge case or notable degradation
Manual QA: shipped, needs a human in a real environment
More information is needed
XSS, unsafe URLs, data leaks, auth/session
Code health, dead code, fragile patterns
Usability or visual inconsistency
This won't be fixed
Milestone
No items
No Milestone
Features 2026-Q4
Projects
Clear projects
No projects
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: LotusGuild/cinny#200
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Migrated from
LOTUS_TODO.mdon 2026-09-17 (the file is now reference-only).[ ] Inline media embeds — remaining providers (LOW PRIORITY)
The inline embed system (
videoEmbed.ts) covers 18 providers (16 + Mixcloud/Deezer); three more were deliberately deferred (verified against 2026 docs by review agents):album/trackitem ids that aren't in the page URL (bandcamp.com/oembedis the resolver; mirror theTikTokEmbedCardon-click oEmbed pattern). CSPframe-src:bandcamp.com. Classifykind: 'audio'.on.soundcloud.comshort links — thew.soundcloudwidget resolver does not follow the redirect; needs the same on-click oEmbed resolve (soundcloud.com/oembed, CORS-enabled) to get the canonical URL. (Canonicalsoundcloud.com/{user}/{track}links already work.)event/{id}(live events) +ondemand/…— event embed host isvimeo.com(notplayer.vimeo.com, so it needs a new CSPframe-srchost); on-demand is paywalled and doesn't embed for non-purchasers. Low ROI — only do the event case ifvimeo.comis widened for another reason.Also open (from the quality review): a real
onError/error-state fallback for iframes that fail to load (deleted post / region lock / X login-wall) — cross-origin frames don't fireonErrorreliably, so this needs a load-timeout heuristic; the Close button + badge link are the current escape hatch.✅ Steam detailed embed (2026-07, 2-agent review) —
ef82650c.store.steampowered.comcontent URLs get rich cards: app pages → OG capsule header + click-to-play facade → Steam's official/widget/{id}store iframe (live region-aware price / discount % / Buy on Steam, gated byinlineMediaEmbeds); news/announcement → banner + headline + body-preview card; bundle/sub/dlc → OG store card.getSteamTarget/steamWidgetEmbedUrlinvideoEmbed.ts(+tests). Grounded in prod CSP (frame-src https:allows the widget with no infra change; images via homeservermxc; NO client-side Steam API —connect-src+ Steam CORS both block it, which is the honest ceiling: no review scores/genres/screenshots client-side). Needs on-device QA: the live widget iframe height/fit (can't render headlessly) — verify the price/Buy stay visible on desktop-wide and phone.✅ GIF previews now animate + Mixcloud/Deezer embeds (2026-07, 2-agent review) —
4154cae5. Reported live: amedia.giphy.comlink "shows the gif's image but doesn't play it." Root cause: Synapse's/thumbnailendpoint flattens animated GIFs to a still first frame, and every preview image went through it.GifCard(Giphy/Tenor) + the generic OG card now request the original via/download(mxcUrlToHttpwith no width/height) when the preview is a GIF (og:image:type === 'image/gif'or a.gifpathname). Guarded:shouldServeGifOriginal()keeps the frozen thumbnail past a 10 MBmatrix:image:sizecap, and the generic card's eager<img>gained theloading="lazy"it was the only preview image missing. Also added Mixcloud + Deezer audio embeds, and fixed Deezer podcasts (they live at/show/<id>, not/podcast/<id>— the latter 404s on Deezer's own oEmbed; verified against the live API). Needs on-device QA: confirm a large GIF still animates and doesn't stall the timeline.✅ Embed bug hunt (2026-07, 3 survey agents + 2-agent review) —
f2673eff. Core posture verified sound (iframe sandbox,useIframeAutoHeightpostMessage origin+source trust, no XSS/dangerouslySetInnerHTML,rel="noreferrer"on all 21 links, oEmbed no-SSRF, the whole facade→iframe/abort/observer lifecycle). Fixed: Twitch/Kick/SoundCloud/Streamable reserved-path over-match (utility pages rendered as broken players), Vimeo hash over-capture ([0-9a-f]{6,}), Spotify/Steam/Discord/IMDbog:imagenow viamxcUrlToHttp(was a broken rawmxc://<img>+ a pre-click 3p-request facade bypass),wideclass follows the og:url-resolved embed, Twitter host alignment (mobile.twitter.com//statuses/), URL de-dupe.Deferred / surfaced from the hunt (not fixed — decide before doing):
allow-popups-to-escape-sandboxand/orclipboard-writefromEMBED_SANDBOX/allow=on embed iframes — real hardening against a compromised provider (phishing popup / clipboard hijack), but risks breaking a legit provider popup/copy on the trusted major providers we embed. Low marginal value; not shipped blindly.encodeURIComponentthe Bluesky authority + Apple Music path/search interpolated into the embedsrc(not currently exploitable — host is fixed and value comes fromURL.pathname; React escapes the attribute).LotusDenoiseFeature(ClientNonUIFeatures.tsx) has awindowmessagelistener with no origin/source check → any frame/window can post{type:'lotus-denoise-status', error}and pop a forged "System" toast (text only, no XSS). Validateevent.source.extractEmbedHeightgeneric.heightfallback accepts any allowed-origin message;TweetEmbedtheme is a one-timematchMediasnapshot (no live theme switch); host-normalization gaps (vt.tiktok.commissesStackOnMobile,m.instagram.com,www.youtu.be).