# Embed HTML5 player for MP3 file

**URL:** https://meta.discourse.org/t/embed-html5-player-for-mp3-file/158970
**Category:** Support
**Created:** [July 27, 2020, 5:06pm UTC](https://meta.discourse.org/t/embed-html5-player-for-mp3-file/158970 "2020-07-27T17:06:42Z")
**Posts on this page:** 1
**Showing post:** 2

<div class="post-metadata">

### Author: ![Overgrow](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/overgrow/32/478189_2.png) [@Overgrow](https://meta.discourse.org/u/Overgrow)
#### Post date: [July 27, 2020, 5:14pm UTC](https://meta.discourse.org/t/embed-html5-player-for-mp3-file/158970/2 "2020-07-27T17:14:35Z")

</div>

CSP maybe?

> [@Mitigate XSS Attacks with Content Security Policy](https://meta.discourse.org/t/mitigate-xss-attacks-with-content-security-policy/104243):
>
> bookmark This guide explains how to use Content Security Policy (CSP) to mitigate Cross-Site Scripting (XSS) attacks in Discourse. It covers CSP basics, configuration, and best practices. person_raising_hand Required user level: Administrator Summary Content Security Policy (CSP) is a crucial security feature in Discourse that helps protect against Cross-Site Scripting (XSS) and other injection attacks. This guide covers the basics of CSP, how it’s implemented in Discourse, and how to c…

Are you pasting it into post or …?

---

_[View the full topic](https://meta.discourse.org/t/embed-html5-player-for-mp3-file/158970)._
