Back to the changelog

v0.60.0

July 22, 2026

Governance of external domains is now truly enforced, everywhere. When you deny a provider the block is respected — even YouTube or Google Drive — and the check covers every content type, not just embedded frames.

  • Security

    "Deny" now really blocks, even well-known providers

    If your organization denies a domain — including preapproved providers like YouTube, Vimeo, Loom or Google Docs and Drive — that content is replaced by the shield and no longer shown. Before, the block decision on well-known providers was ignored, giving a false sense of control.

  • Security

    No external content escapes the check

    The domain check no longer covers only embedded frames and PDFs, but also direct images and videos, images in Markdown content and those in HTML. An image or a video from a non-approved domain is no longer loaded by users' browsers.

  • Security

    Validated manual add, and a denied domain stays denied

    When you add a domain from the Security section, the system now rejects invalid values (IP addresses, wildcards, ports, non-text values) with a clear message, instead of accepting them silently. And re-adding a domain you had denied no longer brings it back among the approved ones automatically: it must be re-enabled explicitly, and every decision records who and when.

  • Improvement

    Security section refinements

    Domains can now be deleted from the list; add, approve and deny operations show a notice on error instead of failing silently; the shield message is translated into Italian and English and distinguishes a "pending" domain from a "denied" one; a policy change propagates faster to other open sessions.