# Disabling oneboxes

**URL:** https://meta.discourse.org/t/disabling-oneboxes/252541
**Category:** Support
**Created:** [January 20, 2023, 10:33pm UTC](https://meta.discourse.org/t/disabling-oneboxes/252541 "2023-01-20T22:33:43Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![hellcx9rv4](https://avatars.discourse-cdn.com/v4/letter/h/8e8cbc/32.png) [@hellcx9rv4](https://meta.discourse.org/u/hellcx9rv4)
#### Post date: [January 20, 2023, 10:33pm UTC](https://meta.discourse.org/t/disabling-oneboxes/252541/1 "2023-01-20T22:33:43Z")

</div>

Hello! Discourse 3 have solution for the old security problems with Onebox? I mean options in the setting to allow generate url preview only for the trust domain like youtube, twitter, vimeo. P

Because without with setting Onebox can show origin IP, it’s gift for the ddos atackers.

Example paste this link: [https://maper.info/21TcY1.jpg](https://maper.info/21TcY1.jpg)

And where button in composer with code formatted?

---

<div class="post-metadata">

### Author: ![Stephen](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/stephen/32/95011_2.png) [@Stephen](https://meta.discourse.org/u/Stephen)
#### Post date: [January 20, 2023, 11:42pm UTC](https://meta.discourse.org/t/disabling-oneboxes/252541/2 "2023-01-20T23:42:43Z")

</div>

Disabling `enable inline onebox on all domains` will achieve exactly this. You configure approved domains via the `inline_onebox_domain_allowlist` site setting.

---

<div class="post-metadata">

### Author: ![Jagster](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jagster/32/192154_2.png) [@Jagster](https://meta.discourse.org/u/Jagster)
#### Post date: [January 22, 2023, 3:14pm UTC](https://meta.discourse.org/t/disabling-oneboxes/252541/3 "2023-01-22T15:14:40Z")

</div>

> [@hellcx9rv4](#):
>
> without with setting Onebox can show origin IP, it’s gift for the ddos atackers

That is not true, at all.

---

<div class="post-metadata">

### Author: ![pfaffman](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/pfaffman/32/120154_2.png) [@pfaffman](https://meta.discourse.org/u/pfaffman)
#### Post date: [January 23, 2023, 1:07am UTC](https://meta.discourse.org/t/disabling-oneboxes/252541/4 "2023-01-23T01:07:39Z")

</div>

> [@hellcx9rv4](#):
>
> , it’s gift for the ddos atackers.

If your community is one that attracts ddos attacks you need to do several things to keep your ip from leaking via dns, smtp, as well as one boxes and external images (which are downloaded by default).

Unless you have a history of ddos attacks then I would recommend that you worry about almost anything else.
