Release 0.204
v0.204.0 — 2026-07-26
The team workspace reads inline — and the split mis-detection is fixed.
Selecting a shared page, table, note, task, event, file, folder or formula in
/team (or the hub) renders the content in the reader pane itself: a new
GET /s/<token>/view returns the presenter payload as JSON (same
authorization as the /s page, cookie or bearer), and the share presenters
moved to @mantle/web-ui/share so both apps render one implementation. No
iframe, no “opens on the brain’s own site” card. Pages arrive as
server-sanitized HTML; apps keep their AppSandbox execution sandbox.
Underneath sat the bug that produced that card: the client treated
“MANTLE_SERVER_ORIGIN configured” as “the API is cross-origin” — but the
installer sets it unconditionally, so every default one-domain deployment
read as split: redirect cards instead of content, bearer-only member
sessions, needless SSO detours. isCrossOrigin() now compares real origins,
and POST /api/team/sso with no next answers 204 + Set-Cookie — the silent
bearer→cookie upgrade existing sessions get on their next load. A genuinely
cross-origin client keeps the old top-level SSO behavior. No migrations, no
compose or config changes; e2e 31/0 across both topologies
(full entry).