On our forum, we’ve seen some recent changes to how links to sites on our domain (makecode.com) are embedded by onebox. Previously, you got a little minimal preview like this:
Was there an update made in last few days to onebox and, if so, is there a way to revert to the old behavior? As far as we are aware, we haven’t made any recent changes on our side.
Are you sure there have been no changes? I don’t know much about setting up iframing but there’s an admin setting for “Allowed onebox iframes” you might take a look at.
Thanks for taking a look! I’m fairly certain there have been no changes; I did take a look at that setting and it simply had the default value (“*”). I just tried removing that wildcard and replacing it with a single domain (YouTube) but it doesn’t seem to have had any effect on the embed.
That pxtoembed class and iframe that you screenshotted come from the oembed endpoint that we link in the embedded page:
Alright, turns out there are two iframe settings in the Security section, and my domain was still added in the other one. I’ve now removed that one and it has at least prevented the issue for now! Still not sure why this suddenly started happening…