Skip to content

Release 0.204

v0.204.0 — 2026-07-26

The team workspace reads inline — and the split mis-detection is fixed. Selecting a shared page, table, note, task, event, file, folder or formula in /team (or the hub) renders the content in the reader pane itself: a new GET /s/<token>/view returns the presenter payload as JSON (same authorization as the /s page, cookie or bearer), and the share presenters moved to @mantle/web-ui/share so both apps render one implementation. No iframe, no “opens on the brain’s own site” card. Pages arrive as server-sanitized HTML; apps keep their AppSandbox execution sandbox.

Underneath sat the bug that produced that card: the client treated “MANTLE_SERVER_ORIGIN configured” as “the API is cross-origin” — but the installer sets it unconditionally, so every default one-domain deployment read as split: redirect cards instead of content, bearer-only member sessions, needless SSO detours. isCrossOrigin() now compares real origins, and POST /api/team/sso with no next answers 204 + Set-Cookie — the silent bearer→cookie upgrade existing sessions get on their next load. A genuinely cross-origin client keeps the old top-level SSO behavior. No migrations, no compose or config changes; e2e 31/0 across both topologies (full entry).