Files
NewTube/assets/config.local.example.js
T
bruno 2bcc7321aa
CI / build-and-test (push) Successful in 14m58s
fix(dailymotion): Player ID obligatoire dans l'URL d'embed
Dailymotion exige désormais un Player ID (fév. 2026) : player.html?video=...
sans Player ID répond HTTP 403 'Forbidden'. L'URL correcte est
geo.dailymotion.com/player/{PLAYER_ID}.html?video=...

- helper dailymotionPlayerId()/dailymotionEmbedBase() (config window.DAILYMOTION_PLAYER_ID, repli demo x8lr5)
- /watch et /shorts utilisent le nouvel endpoint avec Player ID
- config.local.example.js documente la config
2026-09-30 21:48:06 -04:00

32 lines
1.6 KiB
JavaScript

// Local (non-versioned) config for API keys.
// Copy this file to `assets/config.local.js` and fill in your keys.
// IMPORTANT: Restrict keys in their provider consoles (HTTP referrers, APIs enabled).
//
// SECURITY NOTE: everything set here is shipped to the browser. Only put
// browser-safe, referrer-restricted keys in this file. Server-only secrets
// (TWITCH_CLIENT_SECRET, GEMINI_API_KEY, JWT_SECRET...) must be provided via
// environment variables on the backend instead — the app consumes them through
// /api/twitch-token and /api/ai/* endpoints.
// YouTube Data API v3 key (browser-safe only if properly restricted by HTTP referrer)
window.YOUTUBE_API_KEY = 'PUT_YOUR_YOUTUBE_API_KEY_HERE';
// Dailymotion Player ID (required since Feb 2026: embeds without a Player ID
// return HTTP 403 "Forbidden"). Create a Player in Dailymotion Studio
// (https://www.dailymotion.com/partner/embed/players) — ideally a vertical
// player (aspect_ratio 9:16) for Shorts — and set its ID here.
// If unset, the app falls back to a public demo player ID (x8lr5).
// window.DAILYMOTION_PLAYER_ID = 'x8lr5';
// Optional: you can also provide multiple keys (CSV) via server env YOUTUBE_API_KEYS.
// Rumble API key (optional — Rumble now works via server-side scraping)
// window.RUMBLE_API_KEY = 'PUT_YOUR_RUMBLE_API_KEY_HERE';
// Odysee: no API key is required when using the built-in proxy.
// Twitch: configured via server env (TWITCH_CLIENT_ID / TWITCH_CLIENT_SECRET).
// Gemini: configured via server env (GEMINI_API_KEY).
// You can add other browser-safe provider keys/tokens here if needed in the future.