ep_embedmedia_tweaks
v0.1.2
Published
Fork of ep_embedmedia with stricter sanitization and additional UI/UX improvements for Etherpad.
Maintainers
Readme
ep_embedmedia_tweaks
Privacy and usability-focused media embeds for Etherpad. This package is a maintained fork of ep_embedmedia with stricter input validation, privacy-enhanced YouTube handling, and updated editor integration.
Features
- Toolbar dialog for inserting media embeds
- Direct URL support for YouTube and Vimeo
- Automatic conversion of YouTube URLs to
youtube-nocookie.com - Sanitized iframe input for other HTTP(S) providers
- Sandboxed iframe output with scripts and unsupported markup removed
- Persistent embed attributes during collaborative editing
Installation
From the Etherpad directory:
pnpm run plugins i ep_embedmedia_tweaksRestart Etherpad after installation. This release supports Etherpad 3.3.2 and later 3.x releases on Node.js 20 or newer.
Usage
Choose the video toolbar button and provide one of the following:
- a YouTube URL;
- a Vimeo URL; or
- complete iframe markup from another HTTP(S) provider.
Direct URL conversion is intentionally limited to YouTube and Vimeo. Other providers must supply iframe markup, which is filtered through the plugin's allowlist-based sanitizer before insertion.
Embedding third-party content still allows that provider to receive browser requests. Review permitted providers and their privacy policies for your deployment.
Export support
This plugin does not register Etherpad export hooks. Embed attributes remain available to normal content collection, but specialized HTML or document-export rendering is outside the supported surface.
Development
pnpm install --frozen-lockfile
pnpm test
pnpm lintThis project contains code derived from ep_embedmedia and Google Caja's HTML sanitizer. Original and modified code is licensed under the Apache License 2.0; see LICENSE.md and NOTICE.md.
