EmDash 1.1: publishing calendar, richer embeds and faster sites EmDash 1.1, the first release since the CMS's 1.0 launch, adds a publishing calendar, isolated HTML/CSS/JavaScript blocks, Microsoft Entra ID sign-in and an experimental way for browser-based AI agents to search a public EmDash site. The calendar brings published entries, scheduled entries and scheduled updates together across every visible collection and locale, caps a month at 1,000 loaded entries, and was contributed in pull request #3680 by @khoinguyenpham04. Cloudflare sites must update matching core packages together with `pnpm up --latest emdash @emdash-cms/cloudflare`, while Node.js deployments can omit the Cloudflare package. Blog https://emdashcms.com/blog EmDash 1.1: publishing calendar, richer embeds and faster sites Plan scheduled content in the new publishing calendar, build richer Portable Text pages, add Microsoft sign-in and make public sites more reliable. EmDash 1.1 is the first release since the 1.0 launch https://emdashcms.com/blog/emdash-1-0 , and it’s packed with useful additions for editors. It gives editorial teams a publishing calendar, adds safer ways to build rich content with HTML, CSS, JavaScript and embedded pages, and makes images easier to add and edit. It also adds Microsoft Entra ID sign-in and an experimental way for browser-based AI agents to search a public EmDash site. The release includes a a large number of fixes across core, the admin, Cloudflare support and plugin tooling. Highlights include: For a Cloudflare site, update the matching core packages together and rebuild: pnpm up --latest emdash or if you are using Cloudflare pnpm up --latest emdash @emdash-cms/cloudflare Add any EmDash plugin packages used by the site to the same pnpm up command. Node.js deployments can leave out @emdash-cms/cloudflare . As with any EmDash update, it’s a good idea to back up your site before upgrading. See Update EmDash https://docs.emdashcms.com/deployment/updating/ for the complete deployment and verification sequence. Plan and manage publishing from a calendar The new publishing calendar https://docs.emdashcms.com/guides/working-with-content/ review-the-publishing-calendar brings published entries, scheduled entries and scheduled updates together across every visible collection and locale. Contributors and higher roles can open Calendar from the sidebar or command palette; the dashboard's Scheduled count links there too. Month shows a calendar grid, while Agenda groups entries by day. Entries use the site's time zone, with browser-local times shown when they differ. Filters narrow the view by collection, locale and state, and the view, month, filters and selected entry stay in the URL so the same calendar can be bookmarked or shared. Selecting an entry opens a detail panel with its state, publication timeline, collection, locale, translations and bylines. People who can publish the entry can reschedule it, remove its schedule or publish an overdue entry immediately. Narrow screens open in Agenda view and use a date picker for the month view. A month is capped at 1,000 loaded entries; when the cap is reached, the calendar marks the days it could not load. The calendar was contributed in 3680 https://github.com/emdash-cms/emdash/pull/3680 . Thanks @khoinguyenpham04 https://github.com/khoinguyenpham04 for building it. Build richer stories in the editor HTML, CSS and JavaScript in isolated blocks HTML blocks now have HTML , CSS , JS and Preview tabs. New blocks created in the admin or through /html in visual editing render in an isolated iframe by default. Their scripts can run, but the frame has an opaque origin: it cannot read the site's cookies, storage or pages, and the site's styles do not enter the frame. Choose Inline from the block menu when sanitized HTML should remain part of the page instead. Existing HTML blocks, and blocks created through imports, REST or MCP, remain inline unless they explicitly set isolated: true . Anyone who can edit content can add JavaScript that runs for visitors after the entry is published, so sites should keep normal editorial trust and review controls in place. Sites using EmDash's PortableText component get the new rendering automatically. A site with a custom htmlBlock renderer must pass isolated blocks to HtmlBlock from emdash/ui , or render them in an iframe whose sandbox omits allow-same-origin . Astro's built-in content security policy blocks the styles, scripts and automatic height inside isolated blocks; see Add HTML, CSS and JavaScript https://docs.emdashcms.com/guides/working-with-content/ add-html-css-and-javascript before enabling both features together. This work shipped in 3687 https://github.com/emdash-cms/emdash/pull/3687 . Built-in iframe blocks Type /iframe to embed a page from another site. Paste an embed code or an HTTPS URL into the Code tab; YouTube and Vimeo links are converted to their players, and Preview loads the embedded page when asked. On the public site, Iframe from emdash/ui renders the block as a responsive, lazy-loading, sandboxed iframe with a strict referrer policy. If a plugin already defines an iframe block, the editor and public renderer continue to prefer the plugin's block. Sites using Astro's content security policy need to allow the intended hosts in frame-src . The full compatibility notes are in 3688 https://github.com/emdash-cms/emdash/pull/3688 and the iframe block documentation https://docs.emdashcms.com/guides/working-with-content/ embed-a-page-from-another-site . Faster image authoring Images can now be dropped into the Portable Text editor or pasted from the clipboard. They upload through the Media Library and land between the surrounding blocks, with an in-place preview while the upload runs and a useful message if it fails 3594 https://github.com/emdash-cms/emdash/pull/3594 . Selecting an image now opens one toolbar for replacement, alt text, alignment, links, settings and deletion. Captions are edited directly below the image, and the alt-text control makes it clear when a real description is present 3657 https://github.com/emdash-cms/emdash/pull/3657 . Sign in with Microsoft Entra ID Editors can now sign in with a Microsoft Entra ID work or school account. Register a web application in Entra, add the callback URL documented in the authentication guide https://docs.emdashcms.com/guides/authentication/ microsoft , and configure the provider: js import { microsoft } from "emdash/auth/providers/microsoft"; emdash { authProviders: microsoft } ; Set EMDASH OAUTH MICROSOFT CLIENT ID , EMDASH OAUTH MICROSOFT CLIENT SECRET and EMDASH OAUTH MICROSOFT TENANT ID . EmDash also accepts the unprefixed forms. The provider stays disabled until all three are present. A directory tenant ID gives EmDash a stronger basis for deciding whether the returned address is verified. With common , organizations or consumers , addresses are not treated as verified by default, so read the verification and account-linking rules before enabling self-signup. The provider was contributed in 3254 https://github.com/emdash-cms/emdash/pull/3254 . Thanks @danielmlr https://github.com/danielmlr . Let browser agents search published content The new experimental WebMcpSearch component registers a read-only search site tool in browsers that support WebMCP. It uses EmDash's public search API and returns titles, absolute URLs and plain-text excerpts from published, search-enabled collections. Unsupported browsers do nothing, and no search query runs until an agent calls the tool. python --- import WebMcpSearch from "emdash/ui/webmcp-search"; ---