# FlowHub.org - Gists for Node-RED

**URL:** https://discourse.nodered.org/t/flowhub-org-gists-for-node-red/80215
**Category:** Share Your Projects
**Created:** [1 August 2023 11:49 UTC](https://discourse.nodered.org/t/flowhub-org-gists-for-node-red/80215 "2023-08-01T11:49:04Z")
**Posts on this page:** 1
**Showing post:** 12

<div class="post-metadata">

### Author: ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)
#### Post date: [30 January 2024 09:05 UTC](https://discourse.nodered.org/t/flowhub-org-gists-for-node-red/80215/12 "2024-01-30T09:05:26Z")

</div>

> [@gregorius](#):
>
> Is there a way to whitelist [FlowHub.org](http://FlowHub.org) for embedding in discourse?

Sorry, my security antenna's twitched at this suggestion. I can't say that it sounds like a good approach.

Generally cross-domain data embeds need to be at least treated with great caution. What might happen if you made a mistake in the code or someone hacked your site? Could end up having a significant impact on Discourse.

I've not looked at Discourse add-ins and what they can/can't do but I think that needs to be the starting point, not hacking one site into another. Resource use on Discourse might also need to be taken into account as I know that we already push the limits.

---

_[View the full topic](https://discourse.nodered.org/t/flowhub-org-gists-for-node-red/80215)._
