Hide and disable Inputs with expressions#
This release added the hidden_if and disabled_if options to input configuration, allowing you to hide or disable an Input based on the values of other Inputs. It also rebuilt CloudCannon's error pages around a shared design and gave each one an error code, changed SSL certificates to generate per Site, added Google reCAPTCHA Enterprise as a captcha provider, and redesigned the emails CloudCannon sends.
It also addressed several issues, including those affecting GitLab webhooks, the Cloudinary asset picker, and the graph on the Publishing tab of a Project.
Features & Improvements
- Added the
hidden_ifanddisabled_ifoptions to input configuration, allowing you to hide or disable an Input based on an expression rather than a fixed value. Thehiddenanddisabledoptions are unchanged, and still take a boolean or the name of another key.- An Input is hidden when
hiddenis true orhidden_ifevaluates to a truthy value, and read-only whendisabledis true ordisabled_ifevaluates to a truthy value. - An Input whose expression is invalid reports the problem in the editing interface, naming the option at fault.
- Expressions support comparison, arithmetic, and logical operators, along with the
length,includes,starts_with,ends_with,lowercase,uppercase,trim,number, andstringfunctions. - An expression reads a sibling key by its name, and the Input's own value as
this. parent()reads the object containing the Input, andparent(2)the object above that.$reads the closest Structure value containing the Input, or the root of the file if the Input is not inside a Structure.get("my key")reads a key whose name is not a valid identifier, such as one containing a space or a hyphen.- For more information, please read our documentation on hiding or disabling an input with an expression.
- An Input is hidden when
_inputs:
discount_code:
type: text
hidden_if: has_discount == false
out_of_stock_reason:
type: text
disabled_if: (stock_count + ordered_stock_count) > 0{
"_inputs": {
"discount_code": {
"type": "text",
"hidden_if": "has_discount == false"
},
"out_of_stock_reason": {
"type": "text",
"disabled_if": "(stock_count + ordered_stock_count) > 0"
}
}
}- Rebuilt CloudCannon's error pages so that the pages you see in the app and error pages served on a hosted website's Custom Domain or Testing Domain share one design.
- Each page names the problem in plain language, such as Your session expired, Access is locked, or CloudCannon is down for maintenance, rather than a status number alone.
- Each page offers only the actions that apply to it. A locked account offers Email support and Log out, a maintenance page offers Check the status page, and a throttled request states how long to wait before trying again.
- Error pages on a hosted Custom Domain or Testing Domain have an Are you the site owner? section, linking you to the in-app location for resolving the error.
- Each page carries an error code, a reference for the request, and the time in UTC. Quote these when you contact support.
- Each page follows the light or dark theme of the device being viewed.
- For more information, please read our documentation on what each error code means.
- Added an Email Preferences page to your Account Settings, allowing you to request an email with a link for managing which CloudCannon emails you receive.
- Changed SSL certificates so that each Site generates its own. CloudCannon previously generated a single certificate covering every Site that shared a Base Domain, so if a Custom Domain name was not pointed at CloudCannon, it stopped certificate generation for all of them.
- SSL emails now cover one Site each, naming that Site's Custom Domain in the subject line. They previously named the shared Base Domain and listed every Site using the certificate.
- Changed the CSV export on an Inbox to generate in the background. CloudCannon prepares the file and then offers a Download CSV button, instead of holding the request open while it builds, so an Inbox with a large number of submissions no longer times out.
- Added Google reCAPTCHA Enterprise to the captcha providers you can set on an Inbox, alongside Google reCAPTCHA, hCaptcha, and Cloudflare Turnstile. It takes the ID of the reCAPTCHA key in your Google Cloud project, the project ID, and a Google Cloud API key restricted to the reCAPTCHA Enterprise API.
- Added a Minimum score field to the captcha settings on an Inbox for Google reCAPTCHA and Google reCAPTCHA Enterprise, allowing you to reject submissions that score below the threshold you set. reCAPTCHA scores each visitor from 0.0 for likely bots to 1.0 for likely people, and defaults to 0.5. Existing reCAPTCHA are set to 0 to maintain existing behavior.
- Added the Tell hCaptcha which Site key to expect setting to the captcha settings on an Inbox, allowing you to stop a form that uses a different Site Key on your hCaptcha account from submitting to that Inbox. New Inboxes will default to
true, while existing Inboxes will befalseby default for backwards compatibility. - Added an explainer to each field in the captcha settings on an Inbox, describing where the value comes from in the provider's console and what CloudCannon does with it.
- Redesigned the emails CloudCannon sends.
- Added a Syncing Paused filter to the Filter Bar in your Sites Browser, allowing you to list the Sites whose Syncing is paused.
- Changed the Failing to sync filter in your Sites Browser so that a Site with Syncing paused is reported as paused rather than failing.
- Changed the DAM connection forms under Org Settings to show the error your provider returned when a connection fails, instead of a generic message.
- Updated the CloudCannon API and the Settings tab of your Inbox so that it shows whether a secret key is set, rather than returning the value of that key.
Fixes
- Reverted the change from September 25, 2026: "CloudCannon now accepts a stronger authentication method than the one named in your AuthnContext setting, instead of requiring an exact match." This caused issues with existing providers, and we will follow this revert with a configurable option.
- Fixed an issue where CloudCannon returned an error for a GitLab webhook it does not act on, such as a merge request update that only changed labels, so GitLab could treat the webhook as failing.
- Fixed an issue where the graph on the Publishing tab of a Project drew one chain of Sites as several separate trees.
- Fixed an issue where the Cloudinary asset picker opened behind the rest of the interface.
- Fixed an issue where an error page could be cached and shown again later, so the reference and time it displayed could belong to an earlier request.
- Updated dependencies to patch security vulnerabilities.
Spam and file upload controls for Forms#
This release added spam, file upload, and attachment link controls to Forms, rebuilt the Single Sign-On and Git Provider pages under Org Settings around tabs, and added warnings for failed syncs or deploys to the Cards in your Sites Browser.
It also addressed several issues, including those affecting Site Mountings that use another Site's build output, Git Provider connections with a failed token refresh, and Inbox captcha providers.
Features & Improvements
- Added Spam protection settings to each Inbox Target, allowing you to stop submissions that our spam detection flags, or that match our spam blocklist, from being sent to that target. The Do not send submissions marked as spam and Do not send submissions matching our spam blocklist options are on the Targets tab of an Inbox, under Org Settings.
- Both options are off by default for most Targets, so submissions marked as spam are sent.
- When the Target is an email address, both options are locked on. CloudCannon will never forward spam to an email address, because doing so would eventually get CloudCannon emails blocked by your email provider.
- Added the Accept file uploads setting to the Inbox settings page under Org Settings, allowing you to reject any submission that carries a file.
- Added Links to attached files settings to each Inbox Target, allowing you to choose whether links for files uploaded via Form submission open in CloudCannon or in the simplified Client Sharing Site. For more information, please read our documentation on Client Sharing.
- Users who access CloudCannon via a Client Sharing password can now view files from a Form submission. This will respect the Site you select, even if an Inbox is shared by multiple Sites.
- CloudCannon will still list Sites without a Client Sharing password set, but prevent you from selecting them.
- Added support for Slack Workflow Builder URLs on Slack Inbox Targets, allowing you to start a Slack workflow with each submission instead of posting a message to a channel. CloudCannon sends the fields from each submission, and Slack matches them by name to the variables your workflow declares.
- Added tabs to the Git Provider pages under Org Settings.
- The Authentication tab shows your connected account as a Card, and displays a warning if CloudCannon cannot fetch that account.
- The Sites tab lists every Site that syncs its files from that Git Provider.
- GitHub Enterprise Server and Self-hosted GitLab keep their server configuration on a Settings tab.
- The Danger Zone tab allows you to disconnect your Git Provider.
- Added a Reconnect button to the Git Provider pages under Org Settings, allowing you to reauthorize a connected account without disconnecting it first.
- Improved warning copy for Git Provider settings forms so that failures appear beside the field that caused it.
- Added tabs to the Single Sign-On pages under Org Settings when successfully configured.
- The Details tab shows the values CloudCannon generates for your Identity Provider, and the Settings tab shows the values you configure.
- The Danger Zone tab allows you to turn off Single Sign-On for your Team Members.
- Updated the setup fields on Single Sign-On page under Org Settings.
- The setup steps now cover adding CloudCannon to your Identity Provider, entering your Identity Provider's details, and choosing what happens for new Team Members.
- The advanced fields are listed with the rest of the form rather than hidden behind a toggle.
- Updated the Site Cards in the Sites Browser to show warnings for failed syncs or deploys. A Site whose sync previously failed without a Git Provider error appeared to have synced normally.
- Added a deploy row to the Cards in your Sites Browser for Sites that deploy their build output, showing when the Site last deployed, or that its last deploy failed.
- Updated the Body field on a Pull Request to a Markdown Input by default, with a toolbar for bold, italic, links, formatting, blockquotes, and bulleted and numbered lists.
- Added the full input configuration to the
_inputskey inpull_request_templates, allowing you to configure the Title and Body inputs in a Pull Request Template the same way you configure any other input. For more information, please read our documentation on configuring a Pull Request Template. - Updated the Source Editor to accept an autocomplete suggestion in your Configuration File when you press the Tab key.
- Updated the Invite Team Members modal on the Team page to allow you to add someone to more than one Permission Group on any Subscription Plan.
- Changed the Inbox and Inbox Target update endpoints in the CloudCannon API so that every field is optional, allowing you to send only the fields you want to change.
- Added
allow_uploadsto the fields you can set on an Inbox through the CloudCannon API, and removedmonthly_quota.
Fixes
- Fixed an issue where, when Team Members had already authenticated by another method, signing in through Single Sign-On would fail. CloudCannon now accepts a stronger authentication method than the one named in your AuthnContext setting, instead of requiring an exact match.
- Fixed an issue where the Name ID Format field in your Single Sign-On settings accepted values other than email address.
- Fixed an issue where a Team Member who signs in through Single Sign-On could not delete their account or their Organization, as CloudCannon would ask for a password they did not have.
- Fixed an issue where a Site Mounting that uses another Site's build output was rejected on the Team Plan. Build output mounts are now accepted on any plan that includes advanced Site Mountings.
- Fixed an issue where an Inbox accepted an unrecognized captcha provider through the CloudCannon API, which then never ran.
- Fixed an issue where failed sync warnings on Sites in your Sites Browser would display the date of the last successful sync, so a Site that had been failing for days could appear to have failed moments ago.
- Fixed an issue causing the graph on the Publishing tab of a Project to overflow.
- Fixed an issue where, after an access token failed to refresh, CloudCannon would not automatically retry a Git Provider connection, so the connection went stale until someone reconnected it. CloudCannon now retries a failed refresh, waiting longer after each failure.
- Fixed an issue where CloudCannon allowed Team Members who did not have write permissions to edit the content of fields on the Git Provider pages under Org Settings, but did not allow them to save those changes. The Self-hosted GitLab server settings are now read-only for those team members, and the Danger Zone tab is hidden.
- Fixed an issue where the GitHub Enterprise Server and Self-hosted GitLab setup forms appeared editable on Subscription Plans that did not support those features. These pages now appear disabled with the upgrade prompt at the top of the page.
- Fixed an issue where CloudCannon reverted a searchable dropdown field to its placeholder text after a search, instead of showing the option you had selected.
- Updated dependencies to patch security vulnerabilities.
Improvements to Pull Request creation#
This release improved Pull Requests by adding Markdown formatting to the Pull Request body and a shortcut to edit your Pull Request templates in Configuration Mode.
It also addressed several issues, including those affecting line breaks in Pull Request descriptions, dropdown menus, and Editable Regions on Nuxt Sites.
Features & Improvements
- Changed the default Input for the body of a Pull Request to a Markdown Input, allowing you to format your Pull Request description without writing Markdown syntax by hand. The toolbar has controls for bold, italics, links, paragraph and heading formats, blockquotes, bulleted lists, numbered lists, and removing formatting.
- Added an Edit Pull Request Templates button to the Publishing page, allowing you to configure your Pull Request templates without opening your CloudCannon Configuration File in the Source Editor. This button is visible when Configuration Mode is on. For more information, please read our documentation on configuring a Pull Request template.
- Improved the configuration options for Pull Request templates in Configuration Mode.
- The
_inputskey acceptstitleandbodyentries only, which matches the fields available on a Pull Request. - The
titleandbodyentries under_inputsaccept the full range of Input configuration options. - The
bodykey uses a Markdown Input, and thetemplate_pathkey is available when you add a new template.
- The
Fixes
- Fixed an issue where pressing Shift + Enter in the body of a Pull Request showed a literal
<br />in the Pull Request description, rather than a line break. - Fixed an issue where clicking away from an open dropdown menu cleared the name of the selected option, leaving the menu looking empty.
- Fixed an issue where client-side hydration on Nuxt Sites stopped some Editable Regions from working in the Visual Editor.
- Updated dependencies to patch security vulnerabilities.