Skip to content

Fix: avoid innerHTML to prevent CSP violations in Video Filters - #4375

Merged
ImprovedTube2 merged 2 commits into
code-charity:masterfrom
abhijeetnardele24-hash:fix-csp-video-filters
Oct 10, 2026
Merged

ImprovedTube2 merged 2 commits into
code-charity:masterfrom
abhijeetnardele24-hash:fix-csp-video-filters

Conversation

@abhijeetnardele24-hash

Copy link
Copy Markdown
Contributor

Fixes #4374

This PR resolves the TrustedHTML / CSP violations that were causing the Video Filters feature (introduced in #4112) to fail on YouTube.

Changes:

  • Replaced the direct innerHTML string assignment in appearance.js with standard DOM API methods (document.createElementNS, setAttribute, etc.) when building the SVG <filter> and its <feConvolveMatrix> / <feComponentTransfer> children.
  • This ensures the browser safely processes the elements without triggering Content Security Policy or TrustedHTML sinks.

Tested and verified that presets (e.g. Vivid) now correctly apply the filters to the video player without throwing console errors.

Copilot AI balanced review requested due to automatic review settings October 6, 2026 13:42

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@hkzo

hkzo commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Thank you for the quick fix!
The reported error seems to be resolved on both Firefox and Chrome.

However, I found a couple of new issues:

  • After applying a filter (e.g., using a preset), turning Activate OFF does not revert/reset the video back to normal.
  • After applying a filter, clicking the filter button in the video player shows a "Filter OFF" notification, but the filter is not actually turned off. Clicking it a second time still displays "Filter OFF" and fails to toggle.

Could you please look into these issues when you have time?

@abhijeetnardele24-hash

Copy link
Copy Markdown
Contributor Author

Thank you for the quick fix! The reported error seems to be resolved on both Firefox and Chrome.

However, I found a couple of new issues:

  • After applying a filter (e.g., using a preset), turning Activate OFF does not revert/reset the video back to normal.
  • After applying a filter, clicking the filter button in the video player shows a "Filter OFF" notification, but the filter is not actually turned off. Clicking it a second time still displays "Filter OFF" and fails to toggle.

Could you please look into these issues when you have time?

Yes sure

@ImprovedTube2

Copy link
Copy Markdown
Collaborator

@DivyaRaval1909 #4376

@hkzo

hkzo commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

Thank you @abhijeetnardele24-hash for being ready to look into this! The follow-up issues have been addressed in #4376

@ImprovedTube2

Copy link
Copy Markdown
Collaborator

Merged #4376 as of @hkzo's review.

Merging #4375 with no changes for now.
Should some of your edit remain? is some of it better by chance? @abhijeetnardele24-hash

Thanks!

@ImprovedTube2
ImprovedTube2 merged commit 7d589a8 into code-charity:master Oct 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

🐞PR #4112 Video Filters fail to set innerHTML on YouTube

4 participants