Skip to content

[Enhancement] Do not leak po token in videoplayback requests to clients #4841

@MMaster

Description

@MMaster

po token is leaked to clients in videoplayback request URLs.
I'm not entirely sure if it can be abused, but since pot is identifiable info it may be better to not leak it to clients watching videos on invidious instance.

Describe the solution you'd like
Rewrite the URL internally to add pot without exposing it to clients eg in video_playback route.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementImprovement of an existing feature

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions