Eye for Craft CMS

Configuration

Settings

Settings → Plugins → Eye, admins only. The presentation settings are safe for anyone who administers the site; the proxy section is a separate decision and the screen says so.

SettingConfig keyDefaultWhat it does
Register stylesheetregisterCsstrueLoads Eye's small stylesheet when an embed renders. Off to style embeds entirely yourself
Register runtimeregisterJstrueLoads the front-end script. Without it, click-to-load, auto height and the load timeout stop working; ratio and fixed embeds are unaffected
—defaultOptions[]Embed options every new embed starts from. Config file only
Privacy modeprivacyModetrueUses a provider's cookie-less option where it has one — youtube-nocookie.com, Vimeo's dnt=1
Auto-embed URLs on saveautoembedfalseTurns a bare URL on its own line in a rich-text field into an embed when the element is saved. For imports, feeds and the Element API; the editors already do this at paste time
Check whether URLs allow framingcheckFramabilitytrueReads X-Frame-Options and frame-ancestors when an embed is saved
Framability cache durationframabilityCacheDuration86400Seconds a verdict is kept. An Unreachable verdict is kept for 5 minutes at most
Enable the proxyproxyEnabledfalseLets proxy and inline modes fetch anything at all. See Proxy & inline modes
Allowed hostsallowedHosts[]The only hosts Eye will fetch: example.com, or *.example.com for its subdomains and the apex
Strip scripts from proxied HTMLproxyStripScriptstrueThe default for an embed's Scripts option
Proxy cache durationproxyCacheDuration900Seconds a fetched page is reused. Embeds can override it. The proxy route never caches for less than 60 outside devMode
Proxy timeoutproxyTimeout10Seconds to wait for a page, 1–120
Proxy response limitproxyMaxBytes2097152The largest page Eye will read, in bytes (2 MB). Minimum 1024
Proxy redirect limitproxyMaxRedirects3Redirects to follow, 0–10. Every hop is re-checked
Proxy user agentproxyUserAgentMozilla/5.0 (compatible; CraftEye/5.0; +https://github.com/justinholtweb/craft-eye)How Eye identifies itself. Never the reader's
HTML Purifier configpurifierConfignullA file in config/htmlpurifier/, without .json, used to clean inline content. Its options are layered over Eye's own

No setting is required. A blank allowlist with the proxy on is allowed, and does nothing.

config/eye.php

Like any Craft plugin's settings, these can be set in a config file, which wins over the settings screen. Create config/eye.php:

<?php

use craft\helpers\App;

return [
    'defaultOptions' => [
        'loading' => 'click',
        'rememberConsent' => true,
    ],
    'proxyEnabled' => App::parseBooleanEnv('$EYE_PROXY') ?? false,
    'allowedHosts' => [
        'prices.supplier.example',
        '*.docs.example.com',
    ],
];

This is also the only place to set defaultOptions. When an embed is made from a recognised URL, the provider's own mode, ratio, allow tokens and consent text still apply on top of them.

Embed options

The same options are used by library embeds, Embed field values, reference tags, Twig and defaultOptions. A reference tag may set only the ones marked Tag.

KeyDefaultNotes
moderatioTagratio, fixed, auto, proxy, inline. A tag cannot switch to proxy or inline
ratio16:9Tagw:h; 16x9, 16/9 and 1.7778 also work
height480TagPixels, for fixed
minHeight240TagStarting height for auto and proxy
maxHeight0TagCeiling for auto height, past which the frame scrolls. 0 is none
width100%TagOne CSS length. A bare number means pixels
aligncenterTagleft, center, right, wide, full
classNameTagExtra classes on the wrapper
idThe wrapper's DOM id. Generated when blank
captionTagShown under the frame
titleTagThe iframe's accessible name. Derived when blank
loadinglazyTaglazy, eager, click
rootMargin200pxHow far ahead of the viewport a lazy embed is prepared
showLoadertrueTagA spinner while the frame loads
timeout8000TagMilliseconds to wait for load before showing the fallback. 0 waits forever
fallbackMarkup shown when the frame fails. Always purified. Blank gives a link card
showFallbackLinktrueTagWhether the fallback offers to open the URL
consentTitleTagClick-to-load card heading
consentTextTagClick-to-load card text. Providers supply one
consentButtonLabelTagClick-to-load button
posterUrlImage behind the consent card. http(s) only
rememberConsentfalseTagRemember the reader's choice in localStorage
sandboxnullArray of allow-* tokens. null omits the attribute; [] is the strictest sandbox
allow[]Permissions-Policy features, such as autoplay, fullscreen, clipboard-write
allowFullscreentrueAdds fullscreen to allow
referrerPolicystrict-origin-when-cross-originAny standard referrer policy
scrollingautoauto, yes, no
scrollToTopfalseTagScroll back to the frame's top when in-frame navigation changes its height
autoHeightSelectorMeasure this selector instead of the document. Same-origin only
params[]Extra query parameters on the frame's src
extractProxy and inline: keep only what this selector matches
removeProxy and inline: drop what these selectors match
injectCssProxy and inline: CSS added to the page
stripScriptsnullnull uses proxyStripScripts
linkTargetblankProxy: blank, self, parent
cacheDurationnullProxy and inline: seconds. null uses proxyCacheDuration

Unknown sandbox and allow tokens are dropped rather than passed through: a typo'd token is silently ignored by the browser, and you would never find out your sandbox had a hole in it.

Permissions

  • View embeds — the Eye → Embeds section
    • Create and edit embeds — saving, and creating an embed by pasting a URL in CKEditor
    • Delete embeds

Console

php craft eye/embeds/list                          # the library, with framing status
php craft eye/embeds/check                         # re-probe embeds not checked in the last day
php craft eye/embeds/check --force                 # re-probe all of them
php craft eye/embeds/check --failOnProblem         # exit non-zero if any refuses framing or is unreachable
php craft eye/embeds/inspect <url>                 # what Eye makes of a URL; saves nothing
php craft eye/embeds/create <url>                  # add a URL to the library, print its tag
php craft eye/embeds/clear-caches                  # forget cached proxy pages and framing verdicts

check skips proxy and inline embeds: the browser never frames them, so a framing header says nothing about whether they work.