Content Policy — Embed Allowlist
Who this guide is for: Owners deciding which outside websites course authors may embed in a course through the Embedded page (iframe) module type.
Overview
An iframe module shows another website inside the learner’s player — an H5P activity, a Genially, an internal intranet page. By default any secure (https://) website is allowed. The embed allowlist lets your organization narrow that to a known set of hosts, so an author cannot point learners at an arbitrary site and a page that later moves to an unapproved host stops rendering instead of loading silently.
The allowlist governs iframe modules only. YouTube / Vimeo modules always play from those two services (they have their own URL check), and SCORM, cmi5 and AICC packages are served from EmbayLMS itself.
Prerequisites
- Owner role (the setting lives with the other tenant-relationship settings).
Step-by-step: set the allowlist
- Go to Settings → Content policy.
- Under Embed allowlist, enter one hostname per line:
h5p.orgallows exactly that host.*.genially.comallows every subdomain andgenially.comitself.- A pasted URL is trimmed to its host (
https://h5p.org/content/1→h5p.org).
- Click Save. The badge above the list turns from Any https website is allowed to N allowed hosts.
To go back to the default, clear the list and save. An empty list means any https website is allowed — it is not “nothing is allowed”.
What the allowlist enforces
| Where | Behaviour when the host is not allowed |
|---|---|
Course editor — adding or editing an iframe module (module.create / module.update) | The save is refused with host is not on this organization’s embed allowlist. Add it under Settings → Content policy → Embed allowlist, or use an allowed host. |
| Changing an existing module’s type to iframe | The stored URL is checked the same way. |
| Learner player | A module whose host fell off the list after it was saved shows This content can’t be shown with a pointer to the administrator — never a broken frame. It renders again as soon as the host is re-added. |
REST POST /api/v1/courses/{id}/modules | Cannot set an external URL at all; it creates the module shell only. |
| Demo seed | Seeds YouTube / Vimeo and iframe samples; run it before restricting the list, or add the sample hosts. |
Every change to the list is written to the audit log (tenant_config / embed_allowlist, with the before and after lists). The browser’s Content-Security-Policy (frame-src 'self' https:) remains the outer bound in all cases: http:// pages are never embedded.
Configuration reference
| Field | Type | Default | Notes |
|---|---|---|---|
| Allowed hosts | list of hostname patterns, max 100 | empty (allow any https host) | lower-cased; *. prefix = wildcard subdomain; duplicates dropped |
Troubleshooting
| Symptom | Cause | Fix |
|---|---|---|
| Not a valid hostname: … on save | An entry has spaces, a bare word (intranet) or a scheme with a path that could not be reduced to a host | Enter a hostname such as intranet.example.com |
| An author gets … is not on this organization’s embed allowlist | The list is set and the site is missing | Add the host (or its *. wildcard) and save; the author retries the save |
| Learners see This content can’t be shown on a module that used to work | The host was removed from the list, or the list was created after the module | Add the host back, or point the module at an allowed site |
| A YouTube module is affected | It is not — check the module type; only Embedded page (iframe) is governed | — |