Skip to main content

    Filter by idea status

    Filter by product

    4866 Ideas

    Has Miro considered supporting the oEmbed Spec Directly for Embed Content + Better Feature Parity for Embed REST API Endpoint?Open

    Hi folks! Curious if Miro has considered more directly supporting the oEmbed standard to allow for more open-ended iFrame Embed content so long as it adheres to the open oEmbed Spec. Please correct me if I’m mistaken, but my understanding is Miro currently relies on a third party platform (Embed.ly) to handle processing of iFrame embed content => generating the iFrame to embed in a Miro board given a link to some piece of content & auto-detect eg if it is a Video Player or some other type of content. Further, I think that as things stand today, the awesome new Miro Embed REST API endpoint in V2’s functionality and behavior doesn’t quite match the end-user experience of manually the “Paste iFrame Code” / “Embed iFrame Code” widget inside Miro itself. It seems like the built-in feature is more permissive => tries to “do the right thing” displaying iFrame embed content and making use of web standards like OpenGraph metadata, whereas the Embed REST API V2 Endpoint seemingly ignores / does not properly display any iframe content that has not been whitelisted as an authorized provider by Embed.ly? [Please do correct me if I’m wrong on this front!] Given that oEmbed is an open standard, and Embed.ly is a “middleman” of sorts which currently seems to be very under-resourced since the Medium acquisition, has the Miro team put any consideration into opening up their Embed capabilities a bit more to more directly rely on the open standard? Our top-of-mind concern is that it seems like Embed.ly has been struggling to keep up with the approval workflow for new oEmbed providers over the past year+, and over time there could be some conflicts of interest between A Medium Corporation and some of the loftier goals of companies like Miro to promote a diverse, open plugin ecosystem and app marketplace that is not stifled by another third party review process that is “out of band” of Miro’s own review process and standards. We ourselves have been waiting for Embed.ly to review our provider application for nearly a month now with no follow-ups or feedback about our application status. As a point of contrast:I’ve been genuinely impressed by the approach that e.g. Notion and some other companies have taken to allow for open-ended embeds, even if it has another layer of more “first-class” iframe embeds for larger common providers like YouTube, etc.  Would love to discuss more with folks on the Miro team and hear their thoughts on this matter! Understand it is a fine line, and definitely appreciate the need to safeguard users against potentially malicious iFrames or janky end-user experiences that result from non-spec-compliant iFrame code. In that way I completely get how Embed.ly solves a real problem and can be a nice “first layer of defense”/walled garden of curated “certifiably compliant” embeds. But it certainly has been frustrating to work with them so far, in stark contrast relative to the delightful and supportive experience we’ve had working with the Miro team to-date!

    MarkT
    MarkTActive Contributor

    Hide Email Addresses / Other Members for Some Team MembersOpen

    It would be incredibly useful to be able to prevent (some) team members from seeing who is a member of the same team and their email address.  Perhaps this is a new level of team membership, or some more granular permissions.At the moment, if I add a user to a team they can see all other members and their email addresses. Whilst this might be fine when using Miro in company, it is a GDPR nightmare for using Miro with public training sessions.We are a training company using Miro for public training and currently we have a TEAM called “Delegates”, which contains a PROJECT for each course event (e.g. Excel Basics - 2021-01-01).  Each PROJECT contains one BOARD per exercise in the course (eg. EX01, EX02, ...).The ideal would be to add delegates for a specific course event to the PROJECT for that event, automatically granting them access to all boards within.  The only way to do this is to add them as member of the “Delegates” TEAM for the duration of the event, which then allows them to be added to the PROJECT for the event.However, doing this means that they can view the members of the PROJECT and the whole “Delegates” TEAM, along with all email addresses.  That means they can see any delegate who is taking any course at the same time as them.  We don’t have permission to share email addresses with individuals on the same course.  We certainly do not have GDPR permission to share email addresses with everyone taking a course with us at the same time in this way!Ultimately, what we end up doing is adding delegates to all the BOARDS for each course individually, which takes a long time and poses issues if new boards are added to the course event’s project and not properly shared at board level.In addition, because adding a user permission at BOARD level drops that board into the user’s “All boards” folder, and not under a “Projects” link, it can prove very difficult for a delegate who has attended multiple courses to navigate to the correct boards for the specific course they are now attending.I have added an additional new idea for surfacing these projects even when sharing is done at board level here: https://community.miro.com/wish-list-32/collate-boards-shared-at-board-level-under-the-appropriate-project-instead-of-all-boards-3223