I find that students don’t notice the course introduction video embedded in the upper right corner of my course About pages. So I’d like to make it prominently displayed in the main body of the course description. However, when I add the below YouTube-recommended embedding code to the About page HTML, it doesn’t show up. Any idea why it doesn’t show up?
The problem was the content would be renderd clean_dangerous_html however when I changed with HTML, the iframe was shown.
I am not 100% sure this the correct fix, you could the follow the PR I linked above until we get a review.
Excellent find! I will apply this to my fork of edx-platform that has the other fixes I’m waiting on.
I suspect this may not be an acceptable fix for everyone, because I can imagine that perhaps some platforms are treating their instructors as untrusted, and thus don’t want them inserting HTML that may be dangerous to students…(although if that’s true I’m wondering whether normal HTML units are similarly filtered?). However on our platform the instructors are treated as trusted, and thus we’re not worried about them injecting malicious HTML.
I was exactly thinking about that and I am not sure as wel whether, there is a census if this would be classfied as okay (i.e. convience role over secuirty) or not (security is more important than convenience).
I will try to bring this topic up to relevant stackholder, or lets see how the review goes.
So I noticed the pull request got rejected, but I decided to go ahead and try this anyway. Long story short, after a couple weeks I noticed that my capability to generate grade reports had broken, and I couldn’t figure our why, since I didn’t think I had done any new major or breaking changes to the platform! I only figured this out by reverting my repository back to the version before this change, and then reports started working again.
So a warning to others, don’t attempt to use this patch as-is!
I guess in the future it will require the more complicated change to clean_dangerous_html which I don’t know how to do. @ghassan do you know how to do that? If so, I can test it on Nutmeg (which I’ll be upgrading to Olive soon.)