Admin GuidesContent Policy (Embed Allowlist)

Content Policy — Embed Allowlist

Who this guide is for: Owners deciding which outside websites course authors may embed in a course through the Embedded page (iframe) module type.


Overview

An iframe module shows another website inside the learner’s player — an H5P activity, a Genially, an internal intranet page. By default any secure (https://) website is allowed. The embed allowlist lets your organization narrow that to a known set of hosts, so an author cannot point learners at an arbitrary site and a page that later moves to an unapproved host stops rendering instead of loading silently.

The allowlist governs iframe modules only. YouTube / Vimeo modules always play from those two services (they have their own URL check), and SCORM, cmi5 and AICC packages are served from EmbayLMS itself.


Prerequisites

  • Owner role (the setting lives with the other tenant-relationship settings).

Step-by-step: set the allowlist

  1. Go to Settings → Content policy.
  2. Under Embed allowlist, enter one hostname per line:
    • h5p.org allows exactly that host.
    • *.genially.com allows every subdomain and genially.com itself.
    • A pasted URL is trimmed to its host (https://h5p.org/content/1 → h5p.org).
  3. Click Save. The badge above the list turns from Any https website is allowed to N allowed hosts.

To go back to the default, clear the list and save. An empty list means any https website is allowed — it is not “nothing is allowed”.


What the allowlist enforces

WhereBehaviour when the host is not allowed
Course editor — adding or editing an iframe module (module.create / module.update)The save is refused with host is not on this organization’s embed allowlist. Add it under Settings → Content policy → Embed allowlist, or use an allowed host.
Changing an existing module’s type to iframeThe stored URL is checked the same way.
Learner playerA module whose host fell off the list after it was saved shows This content can’t be shown with a pointer to the administrator — never a broken frame. It renders again as soon as the host is re-added.
REST POST /api/v1/courses/{id}/modulesCannot set an external URL at all; it creates the module shell only.
Demo seedSeeds YouTube / Vimeo and iframe samples; run it before restricting the list, or add the sample hosts.

Every change to the list is written to the audit log (tenant_config / embed_allowlist, with the before and after lists). The browser’s Content-Security-Policy (frame-src 'self' https:) remains the outer bound in all cases: http:// pages are never embedded.


Configuration reference

FieldTypeDefaultNotes
Allowed hostslist of hostname patterns, max 100empty (allow any https host)lower-cased; *. prefix = wildcard subdomain; duplicates dropped

Troubleshooting

SymptomCauseFix
Not a valid hostname: … on saveAn entry has spaces, a bare word (intranet) or a scheme with a path that could not be reduced to a hostEnter a hostname such as intranet.example.com
An author gets … is not on this organization’s embed allowlistThe list is set and the site is missingAdd the host (or its *. wildcard) and save; the author retries the save
Learners see This content can’t be shown on a module that used to workThe host was removed from the list, or the list was created after the moduleAdd the host back, or point the module at an allowed site
A YouTube module is affectedIt is not — check the module type; only Embedded page (iframe) is governed—