Skip to content

Commit 919203d

Browse files
committed
update docs
1 parent 6c79335 commit 919203d

4 files changed

Lines changed: 61 additions & 4 deletions

File tree

‎docs/introduction.md‎

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -36,7 +36,7 @@ Docmost has support for Spaces. You can create Spaces for different teams, proje
3636
- ZIP archive import
3737
- Notion import
3838
- Confluence import (Enterprise)
39-
- DOCX import (Enterprise)
39+
- PDF & DOCX import (Enterprise)
4040
- **Print to PDF**: Generate PDF versions of pages using the browser print dialog.
4141
- **@ Mentions**: Mention team members and link to pages directly in the editor.
4242
- **Markdown Shortcuts**: Type Markdown syntax directly in the editor and it converts to rich text automatically.
@@ -54,8 +54,9 @@ Docmost has support for Spaces. You can create Spaces for different teams, proje
5454
## Enterprise Edition Features
5555
- **SSO** (SAML 2.0 / OIDC) — Integrate Microsoft Entra ID, Okta, OneLogin, and more.
5656
- **LDAP** — Authenticate users against your LDAP directory.
57+
- **SCIM provisioning** — Automate user and group provisioning, updates, and deactivation through your identity provider.
5758
- **MFA** (TOTP) — Multi-factor authentication with authenticator apps.
58-
- **AI** — AI-powered writing assistance (Ask AI) and AI-powered search (AI Answers). Use cloud models or local LLMs.
59+
- **AI** — AI Chat, AI-powered writing assistance (Ask AI), AI-powered search (AI Answers), and MCP. Use cloud models or local LLMs.
5960
- **API** — REST API with personal API keys and admin key management.
6061
- **Full-text search in attachments** — Search content inside PDF and DOCX file attachments.
6162
- **Resolve comments** — Mark comment threads as resolved.
@@ -64,6 +65,8 @@ Docmost has support for Spaces. You can create Spaces for different teams, proje
6465
- **DOCX importer** — Import Microsoft Word documents.
6566
- **PDF importer** — Import PDF files into pages.
6667
- **Templates** — Create and reuse page templates across your workspace.
68+
- **Page-level Permissions** — Control access with granular view and edit permissions on individual pages and spaces.
69+
- **Page Verification & Approval Workflow** — Review, verify, and approve content to ensure documentation stays accurate and up to date.
6770
- **Priority support** — Direct email support.
6871
- You can generate a free trial license key at [https://customers.docmost.com](https://customers.docmost.com).
6972
- [<a href="mailto:sales@docmost.com?subject=Docmost Enterprise Edition.">Purchase enterprise edition</a>].

‎docs/self-hosting/configuration/index.md‎

Lines changed: 31 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -29,7 +29,7 @@ MAIL_FROM_NAME=Docmost
2929
```
3030

3131
## File Storage
32-
Docmost supports both local storage and S3-compatible storage drivers. The default driver is `local storage`.
32+
Docmost supports local storage, S3-compatible storage, and Azure Blob Storage drivers. The default driver is `local storage`.
3333
```shell
3434
STORAGE_DRIVER=local
3535
```
@@ -49,6 +49,16 @@ AWS_S3_FORCE_PATH_STYLE=
4949

5050
Being S3-compatible means Docmost can work with AWS S3, Backblaze, Wasabi, DigitalOcean Spaces, Minio, and other S3-compatible providers.
5151

52+
### Using Azure Blob Storage
53+
If you wish to use Azure Blob Storage, you have to add the below environment variables:
54+
55+
```shell
56+
STORAGE_DRIVER=azure
57+
AZURE_STORAGE_ACCOUNT_NAME=
58+
AZURE_STORAGE_ACCOUNT_KEY=
59+
AZURE_STORAGE_CONTAINER=
60+
```
61+
5262

5363
### File upload size limit
5464
The maximum file size that can be uploaded on the editor.
@@ -129,6 +139,26 @@ TYPESENSE_URL=http://localhost:8108
129139
TYPESENSE_LOCALE=en
130140
```
131141

142+
## Iframe embedding
143+
Docmost blocks other origins from embedding your instance in an `<iframe>` by default.
144+
145+
**Public shared pages (`/share/...`) are exempt and can always be embedded from any origin**, regardless of the settings below.
146+
147+
### Allow embedding from any origin
148+
149+
```shell
150+
IFRAME_EMBED_ALLOWED=true
151+
```
152+
153+
When `IFRAME_EMBED_ALLOWED=true` and no allowlist is provided, Docmost emits no framing header, so any origin can embed it.
154+
155+
### Allow embedding from specific origins
156+
157+
```shell
158+
IFRAME_EMBED_ALLOWED=true
159+
IFRAME_ALLOWED_ORIGINS=https://intranet.example.com,https://portal.example.com
160+
```
161+
132162
## Telemetry
133163
We anonymously collect the active version, user count, page count, space and workspace count.
134164
To disable telemetry:

‎docs/self-hosting/environment-variables.md‎

Lines changed: 24 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -47,6 +47,15 @@ To configure your application, set the following environment variables. These va
4747
| `AWS_S3_ENDPOINT` | | The endpoint URL for your S3 service (optional). |
4848
| `AWS_S3_FORCE_PATH_STYLE` | `true` | Force the request to use path-style addressing (optional). |
4949

50+
### Using Azure Blob Storage
51+
52+
| Variable | Example | Description |
53+
| ------------------------------ | ------- | ---------------------------------------------------------- |
54+
| `STORAGE_DRIVER` | `azure` | The storage driver to use for file storage. |
55+
| `AZURE_STORAGE_ACCOUNT_NAME` | | Your Azure Storage account name. |
56+
| `AZURE_STORAGE_ACCOUNT_KEY` | | Your Azure Storage account key. |
57+
| `AZURE_STORAGE_CONTAINER` | | The name of your blob container. |
58+
5059

5160
### Storage file upload limits
5261

@@ -109,6 +118,21 @@ The default Draw.io embed url is `https://embed.diagrams.net`.
109118
| `TYPESENSE_API_KEY` | `your_api_key_here` | Your Typesense API key with read/write permissions. Required when `SEARCH_DRIVER=typesense`. (Enterprise) |
110119
| `TYPESENSE_LOCALE` | `en` | The locale for text analysis and search. Default is `en`. Examples: `en`, `es`, `fr`, `de`, `ja`, `zh`, `ko`, etc. See [Typesense supported languages](https://typesense.org/docs/latest/api/search.html#supported-languages) for full list. (Enterprise) |
111120

121+
## Security
122+
123+
### Iframe embedding
124+
125+
By default, Docmost blocks other origins from embedding your instance in an `<iframe>`. This protects users against clickjacking attacks where a malicious site loads Docmost in a hidden frame and tricks signed-in users into clicking destructive actions. Out of the box, Docmost responds with `X-Frame-Options: SAMEORIGIN`, so only pages served from your own Docmost origin can iframe Docmost content.
126+
127+
Public shared pages (`/share/...`) are exempt from this restriction and can always be embedded from any origin. Shares are public, read-only content with no authenticated actions, so they have no clickjacking surface.
128+
129+
If you legitimately need to embed the rest of Docmost (the app itself) inside another tool, for example an intranet portal or LMS, use the variables below.
130+
131+
| Variable | Example | Description |
132+
|--------------------------|-----------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
133+
| `IFRAME_EMBED_ALLOWED` | `false` | Master switch for external iframe embedding. Defaults to `false`, which emits `X-Frame-Options: SAMEORIGIN`. Set to `true` to permit external embedding. |
134+
| `IFRAME_ALLOWED_ORIGINS` | `https://intranet.example.com,https://portal.example.com` | Optional comma-separated allowlist. Only consulted when `IFRAME_EMBED_ALLOWED=true`. When provided, Docmost emits `Content-Security-Policy: frame-ancestors 'self' <origins>` instead of `X-Frame-Options`. When empty, embedding is allowed from any origin. |
135+
112136
## Telemetry
113137
We anonymously collect the active version, user count, page count, space and workspace count.
114138

‎docs/self-hosting/installation/index.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -121,7 +121,7 @@ Replace `STRONG_DB_PASSWORD` in the `POSTGRES_PASSWORD` environment variable wit
121121
Update the `DATABASE_URL` default `STRONG_DB_PASSWORD` value with your chosen Postgres password.
122122

123123
To configure Emails or File storage driver, see the [Configuration](/self-hosting/configuration) doc.
124-
The default File storage driver is `local storage`. You don't have to do anything unless you wish to use S3 storage.
124+
The default File storage driver is `local storage`. You don't have to do anything unless you wish to use [S3](/self-hosting/configuration#using-s3-compatible-storage) or [Azure Blob Storage](/self-hosting/configuration#using-azure-blob-storage).
125125

126126
### Start the Services
127127

0 commit comments

Comments
 (0)