From a1b76650fb7085f6682a52a2a351554971e96efa Mon Sep 17 00:00:00 2001 From: Matthew Wright Date: Thu, 8 Oct 2026 12:10:30 -0400 Subject: [PATCH 1/2] add external image markdown toggle --- salt/soc/defaults.yaml | 1 + salt/soc/soc_soc.yaml | 5 +++++ 2 files changed, 6 insertions(+) diff --git a/salt/soc/defaults.yaml b/salt/soc/defaults.yaml index 4eeae5579..c93e8d87a 100644 --- a/salt/soc/defaults.yaml +++ b/salt/soc/defaults.yaml @@ -1821,6 +1821,7 @@ soc: cacheExpirationMs: 300000 casesEnabled: true detectionsEnabled: true + allowExternalMarkdownImages: false inactiveTools: ['toolUnused'] exportNodeId: tools: diff --git a/salt/soc/soc_soc.yaml b/salt/soc/soc_soc.yaml index a98cbb908..11ded60aa 100644 --- a/salt/soc/soc_soc.yaml +++ b/salt/soc/soc_soc.yaml @@ -1155,6 +1155,11 @@ soc: description: Set to true to enable the Detections module in SOC. global: True forcedType: bool + allowExternalMarkdownImages: + description: Set to true to let user-written Markdown, such as case descriptions and comments, load images from other servers. Loading an image sends a request to its server, so leave this disabled unless needed; Onion AI output never loads external images. + global: True + advanced: True + forcedType: bool inactiveTools: description: List of external tools to remove from the SOC UI. global: True From de63f95ab09f9845c0d7ba2c6ede62c437b48732 Mon Sep 17 00:00:00 2001 From: Matthew Wright Date: Thu, 8 Oct 2026 12:38:13 -0400 Subject: [PATCH 2/2] turn off advanced --- salt/soc/soc_soc.yaml | 1 - 1 file changed, 1 deletion(-) diff --git a/salt/soc/soc_soc.yaml b/salt/soc/soc_soc.yaml index 11ded60aa..0d544aab6 100644 --- a/salt/soc/soc_soc.yaml +++ b/salt/soc/soc_soc.yaml @@ -1158,7 +1158,6 @@ soc: allowExternalMarkdownImages: description: Set to true to let user-written Markdown, such as case descriptions and comments, load images from other servers. Loading an image sends a request to its server, so leave this disabled unless needed; Onion AI output never loads external images. global: True - advanced: True forcedType: bool inactiveTools: description: List of external tools to remove from the SOC UI.