If you're an instance admin please double-check the CSP headers you've set in nginx if you have any, because you might be bricking the embedding functionality.


@Gargron On #Friendica we use a local proxy feature for OEmbed, so that it's on the same domain as the node.


Where aHR0cHM6Ly90d2l0dGVyLmNvbS9ldmVyeWRheWxvdWllL3N0YXR1cy85Mzg4MDc1MzA1MTU0MTUwNDA= simply is the base64 encode of the target URL.

@Gargron i've been using this forever:

add_header Content-Security-Policy "style-src 'self' 'unsafe-inline'; script-src 'self'; object-src 'self'; img-src data: https:; media-src data: https:; connect-src 'self' wss://; upgrade-insecure-requests";

@vahnj @Gargron is this settings ok to allow embedded Youtube ? I can't find the right setting to allow that...

