Improve site security with Salesforce’s CDN, upgrade your SAML single sign-on, enjoy improvements to custom domains, and more.
- Upgrade SAML Single Sign-On Framework (Release Update)
Salesforce is upgrading its SAML framework as part of regular maintenance. This update can affect integrations with third-party systems, such as integrations with SAML identity providers and SAML-enabled applications. This update applies to all SAML-based integrations, including Identity for Employees and Salesforce Customer Identity, including Experience Cloud. This update was first made available in Summer ’22. - Apply User Access Permissions to Navigation Menus Retrieved by Apex in Experience Cloud Sites (Release Update)
This update restricts users’ access to navigation menus in the Experience Cloud sites that they’re a member of. This change improves site security by enforcing existing user access permissions when you use an Apex controller in a custom component to query the NavigationLinkSet or NavigationMenuItem objects. Navigation menus that are queried using Connect APIs already enforce user access permissions and are therefore unaffected by this change. This update was first available in Winter ’23. - Use Your Certificate to Serve Your Custom Domain in Your Experience Cloud Sites
Now your custom domain can use your HTTPS certificate to serve your Experience Cloud site in Hyperforce. Previously, this feature was unavailable in Hyperforce. - Specify Trusted Domains for Clickjack Protection on Your Site
Now you can specify the third-party domains that you trust to frame your Aura or LWR site. For consistency, the labels for adding trusted domains for clickjack protection on Visualforce pages are updated. Previously, the Trusted Domains list was titled Domains, and the Add Trusted Domain button was labeled Add Domain. - Test Custom Domain Subdomains That Serve Your Site
To improve your site’s security, custom domain subdomains can no longer use cookies set by the custom domain. - Add Server Name Indication (SNI) for Requests to Custom Domains That Serve Your Experience Cloud Site
If you use Salesforce Edge Network, update your API client callers to include the SNI extension. This extension is required to provide the correct certificate for incoming custom domain requests. - IP Addresses Are No Longer Allowed for Domain Certificates That Serve Your Experience Cloud Site
If you use A records that point to IP addresses for your custom domains serving your Experience Cloud site, you can no longer view or use the IP addresses on the Certificate and Key Management page in Setup.