* **New Features**
* Added a Resource Policy editor for each input, supporting trusted hostnames and private network ranges.
* Resource URLs now retain their source input and use authenticated links where supported.
* Resource caching is scoped to the policy authorizing access.
* **Bug Fixes**
* Invalid or unsupported resource values are safely discarded.
* Redirects and destination addresses are rechecked against the applicable policy.
* **Breaking Changes**
* Private DNS destinations require approved hosts and networks; private IP literals require an approved network.
* Input and alias names must be non-empty and globally unique.
New Features
Added target-specific bouquet filtering with whitelist and blacklist modes for Live, VOD, and Series groups.
Added an in-context bouquet editor with search, selection controls, status indicators, reset, and streaming previews.
Targets are managed by name, with saved selections available through the Source Editor.
Improved stream alias resolution and provider failover behavior.
Bug Fixes
Existing playlists are preserved when refreshes produce no usable items.
Empty playlists are no longer published.
Configuration changes now recover more safely from persistence failures.
Documentation
Updated feature and configuration documentation and added translations.
* Fix M3U alias credential rewriting on provider fallback
Rewrite opaque authentication query parameters when stream allocation
switches from the primary M3U provider to an alias.
Support unambiguous cross-key mappings such as token to api_key while
preserving unrelated query parameters and rejecting ambiguous mappings.
Add regression coverage for URL rewriting and provider allocation.