Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
@thelevicole/youtube-to-html5-loader
Advanced tools
A javascript library to load YoutTube videos as HTML5 emebed elements.
First you need to include the library in your project, this can be achieved via NPM or jsDeliver.
npm i @thelevicole/youtube-to-html5-loader
import YouTubeToHtml5 from '@thelevicole/youtube-to-html5-loader'
<script src="https://cdn.jsdelivr.net/npm/@thelevicole/youtube-to-html5-loader@5/dist/YouTubeToHtml5.js"></script>
First setup your HTML something like:
<video data-yt2html5="YOUTUBE_URL_OR_ID_GOES_HERE"></video>
And then simply initiate the library with:
new YouTubeToHtml5();
There are a number of options that can be passed to the constructor these are:
Option | Description | Type | Default |
---|---|---|---|
endpoint | This is the API url thats used for retrieving data. More information to come. | string | https://yt2html5.com/?id= |
selector | The DOM selector used for finding video elements. | string | video[data-yt2html5] |
attribute | This is the attribute where your YouTube id/url is stored on the element. | string | data-yt2html5 |
formats | Filter the API results by specific formats. For example [ '1080p', '720p' ] will only allow 1080p and 720p formats. An asterix will allow all streaming formats. | `string | array` |
autoload | Whether or not to load all videos on library init. | boolean | true |
withAudio | Whether or not to only load streams with audio. | boolean | true |
withVideo | Whether or not to only load streams with video. | boolean | true |
This package uses a man-in-the-middle server (yt2html.com) to handle the API requests. This can cause issues as YouTube often blocks the host causing the library to not work. A solution to this is to host your own man-in-the-middle server and change the libraries API endpoint.
Simply modify the libraries global endpoint with the below snippet. Make sure to place before any YouTubeToHtml5()
initiations.
YouTubeToHtml5.defaultOptions.endpoint = 'http://myserver.com/?id=';
The server source can be found here: thelevicole/youtube-to-html5-server
The library has a hook mechanism for filters and actions. If you've worked with WordPress before you'll be familiar with this concept.
Note: You'll need to disable auto loading when using any hooks. First create an instance, then bind your hooks and finally call the
.load()
method.
Modify and return values.
You might want to modify the request URL on each element load. You can do this with the request.url
filter. For example:
const controller = new YouTubeToHtml5({
autoload: false
});
controller.addFilter('request.url', function(url) {
return `${url}&cache_bust=${(new Date()).getTime()}`;
});
controller.load();
Run code every time the action is called.
const controller = new YouTubeToHtml5({
autoload: false
});
controller.addAction('load.before', function(element, data) {
element.classList.add('is-loading');
});
controller.load();
const controller = new YouTubeToHtml5({
autoload: false
});
controller.addAction('load.after', function(element, data) {
element.classList.remove('is-loading');
});
controller.load();
const controller = new YouTubeToHtml5({
autoload: false
});
controller.addAction('load.success', function(element, data) {
element.classList.addClass('is-playable');
});
controller.load();
const controller = new YouTubeToHtml5({
autoload: false
});
controller.addAction('load.failed', function(element, data) {
element.classList.add('is-unplayable');
});
controller.load();
The library now includes a simply jQuery plugin which can be used like so...
$('video[data-yt2html5]').youtubeToHtml5();
The .youtubeToHtml5()
plugin returns the YouTubeToHtml5
class instance so adding hooks etc is just as described above...
const controller = $('video[data-yt2html5]').youtubeToHtml5({
autoload: false
});
controller.addAction('load.failed', function(element, data) {
element.classList.add('is-unplayable');
});
controller.load();
Below is a list of varying YouTube url patterns, which include http/s and www/non-www.
youtube.com/watch?v=ScMzIvxBSi4
youtube.com/watch?vi=ScMzIvxBSi4
youtube.com/v/ScMzIvxBSi4
youtube.com/vi/ScMzIvxBSi4
youtube.com/?v=ScMzIvxBSi4
youtube.com/?vi=ScMzIvxBSi4
youtu.be/ScMzIvxBSi4
youtube.com/embed/ScMzIvxBSi4
youtube.com/v/ScMzIvxBSi4
youtube.com/watch?v=ScMzIvxBSi4&wtv=wtv
youtube.com/watch?dev=inprogress&v=ScMzIvxBSi4&feature=related
m.youtube.com/watch?v=ScMzIvxBSi4
youtube-nocookie.com/embed/ScMzIvxBSi4
FAQs
A javascript library to load YoutTube videos as HTML5 emebed elements.
We found that @thelevicole/youtube-to-html5-loader demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.