v0.60.0
July 22, 2026
Governance of external domains is now truly enforced, everywhere. When you deny a provider the block is respected — even YouTube or Google Drive — and the check covers every content type, not just embedded frames.
-
Security
"Deny" now really blocks, even well-known providers
If your organization denies a domain — including preapproved providers like YouTube, Vimeo, Loom or Google Docs and Drive — that content is replaced by the shield and no longer shown. Before, the block decision on well-known providers was ignored, giving a false sense of control.
-
Security
No external content escapes the check
The domain check no longer covers only embedded frames and PDFs, but also direct images and videos, images in Markdown content and those in HTML. An image or a video from a non-approved domain is no longer loaded by users' browsers.
-
Security
Validated manual add, and a denied domain stays denied
When you add a domain from the Security section, the system now rejects invalid values (IP addresses, wildcards, ports, non-text values) with a clear message, instead of accepting them silently. And re-adding a domain you had denied no longer brings it back among the approved ones automatically: it must be re-enabled explicitly, and every decision records who and when.
-
Improvement
Security section refinements
Domains can now be deleted from the list; add, approve and deny operations show a notice on error instead of failing silently; the shield message is translated into Italian and English and distinguishes a "pending" domain from a "denied" one; a policy change propagates faster to other open sessions.