Skip to content

v1.0.60-beta.3

Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 26 Aug 13:02
Immutable release. Only release title and notes can be modified.
9d5f120

Added

  • Drive sync batch 2 (#1086) — Five synchronized enhancements aligned with closed-source MR 28427926 / 28769810 / 28967420 / 28972632:
    • drive quota + quota apps (#573): drive quota queries enterprise storage (org/app/space levels); drive quota apps lists application storage usage with pagination and sorting
    • drive task get + copy/move auto-polling (#543, #496): unified drive task get --type <export|import|copy|move> --id <taskId> queries async task status via query_task (drive MCP); drive copy/move now auto-poll query_task when server returns taskId and print normalized TaskResult JSON on completion
    • drive export (#593): universal export command supporting all doc types (adoc/axls/appt) with auto-format detection, progressive-backoff polling, and optional --async mode; drive export get queries export task status
    • publish set password/expire-days (#584): drive publish set accepts --password (4-char alphanumeric, empty to clear) and --expire-days (N=days, 0=permanent); client-side validation of --permission/--password/--expire-days runs before the confirmation gate
    • doc-whiteboard.md (#571): added skills/mono/references/products/doc/doc-whiteboard.md documenting whiteboard card insertion, deletion, and post-insert verification workflow

Changed

  • Download host trust policy — retires the static DingTalk/OSS download
    host allowlist, the dial-time public-IP refusal, and the IP-literal
    refusal from both the shared local download path (drive +download,
    drive +version-download, doc/minutes artifact downloads) and the chat
    message-resource path (chat +messages-resource-download,
    --download-resources). Download URLs only require HTTPS without userinfo
    and accept non-default HTTPS ports, because every dimension of a
    dedicated-deployment storage endpoint — custom domain, port, and network
    location — is decided by the customer deployment and cannot be enumerated
    or configured client-side. Verified on a dedicated deployment whose
    storage domain resolves to a customer-intranet address. Downloads align
    with the official GUI client, which applies no client-side SSRF
    interception: download URLs only ever come from authenticated service
    responses (no command accepts a user-supplied URL), TLS hostname
    verification pins the connection to the requested host, redirects are
    re-validated per hop, and service credential headers are stripped once a
    redirect leaves the original origin.

  • Upload host trust unchanged — upload target URLs (drive +upload,
    minutes audio upload) keep the pre-existing public DingTalk/OSS trusted
    host requirement through a dedicated upload validator, so removing the
    download allowlist does not widen where local file bytes can be sent;
    the validator also keeps the pre-existing default-port-only HTTPS rule
    (DingTalk/OSS upload endpoints always serve on 443, so non-default ports
    accepted for dedicated-deployment downloads stay anomalous for uploads).
    Download credential headers are issued together with the download URL by
    the same authenticated service response and follow it as-is on the first
    request; redirects leaving the original host still strip them.

  • report entry submit requires recipients — dws report entry submit(及废弃别名 dws report create)的 --to-user-ids 从可选提升为必填:无接收人的日志提交在服务端仍返回成功,但日志对任何接收人都不可见。openAPI create_report 的 toUserIds 参数保持可选不动,规则仅在 dws CLI 侧收紧——Cobra required 拦截未传场景,RunE 内对空值/纯分隔符(如 --to-user-ids ",")同样 fail-closed 拒绝。修复 #85724185。

Removed

  • Education and college vendor extensions removed — removes dws edu-contact, dws edu-group, dws edu-app, dws edu-familygroup, and dws college-contact from the CLI, Schema, bundled Skills, and open-edition MCP endpoint registry. Future DWS packages no longer expose these five command surfaces.

Fixed

  • Pull request CI scheduling — stops metadata-only auto-merge enable and disable events from restarting the complete admission graph for an unchanged commit, while the base-owned Reviewer Router continues to enforce merge authority.

  • Command typo guidance — returns a validation error with up to three nearest command suggestions and the parent --help entry instead of printing the full command list.

  • Document shortcut reliability — adds bounded pagination for document and template listings, supports verified paragraph or heading insertion before a reference block, tolerates service-only Markdown layout normalization during write verification, and resolves and verifies the default “My Documents” import target.

  • Fork pull-request admission — keeps the read-only Reviewer Router identity check fail-closed while allowing external contributors' CI to use the reviewed public App slug when GitHub withholds repository variables.

  • Markdown append chunking rewritten around safe split positions — long markdown is now split so that every chunk is a complete, self-contained top-level block sequence, which is what update_document mode=append requires: the server inserts a brand new structure per call and cannot continue the previous one. Split points are chosen strictly by how much they change the rendered document — fully safe boundaries (blank lines, block starts that interrupt a paragraph) before boundaries that need repair (a table's rows now carry a re-emitted header and delimiter row; a fenced code block is closed and reopened with its original marker and info string) before boundaries that merely restructure (long paragraphs, list items) before a hard character cut. Within a tier the latest boundary in the window wins, since all chunks land in the same document. Every boundary that changes the rendered structure is reported in a new degradations field instead of being applied silently.

  • Fixed markdown chunking dropping a newline — the previous splitter rebuilt block text from lines and lost one \n whenever the content's last line began a heading, table or code fence, so "para\n# Title" was written as "para# Title" and the heading stopped being a heading. Roughly one in five randomly generated documents was affected. The new splitter slices by offset and never rebuilds text, making content preservation structural.

  • Fixed oversized tables and code blocks being cut mid-cell and mid-fence — the hard-split path never received the block type, so it cut at arbitrary character boundaries despite claiming to preserve table and code block integrity.

  • Fixed readback verification comparing against content the server never receives — doc +create / doc +update verified the readback against the raw input, so any repaired boundary (and, previously, any paragraph split) failed verification on large documents. Verification now compares against the document the chunk plan says the server should hold.

  • Unified four markdown write paths onto one splitter — doc create / doc update, doc +create / doc +update and doc +checkpoint-update now share helpers.SplitMarkdownForAppend and one limit constant (30000 runes), replacing two independent implementations plus one path that never chunked at all. doc +checkpoint-update accepts @file and stdin content, so oversized input was reachable there while the equivalent doc +update chunked. doc +doc-append takes --text from argv only and now rejects oversized input with a pointer to doc +update rather than sending one oversized call.

  • doc update --index now fails closed when the content requires chunking — each chunk creates an unpredictable number of blocks, so the insertion point for later chunks is unknowable; the flag was previously accepted and silently ignored.

  • Reviewer Router recovery — keeps exact App-owned PRs that are behind main retriable when GitHub reports the protected merge denial as Resource not accessible by integration, while preserving every other 403 as a hard failure.

  • Reviewer Router merge authority — moves fail-closed writer-rule and auto-merge ownership validation into the trusted base-owned Router before App credentials are read, preparing metadata-only auto-merge changes to stop restarting the full CI suite without weakening protected-main admission or exact-SHA cache production.

  • Reviewer Router merge recovery — retries exact App-owned merge intents through a SHA-bound synchronous merge after GitHub has enforced approval and nine GitHub Actions source-bound required checks.

Security

  • DWS OpenAPI escape hatch (Aone #84603971) — Preserves the existing dws api <METHOD> <PATH> command, five HTTP methods, flags and defaults, App Token cache, new/legacy host token injection, raw successful JSON, and paginated page arrays. Adds --params/--data @file, single-file streaming --file [field=]path multipart requests, camelCase pagination fields, and official open.dingtalk.com/llms.txt discovery guidance in the misc and mono Skills. Resolves Client ID and Client Secret only as a complete flag, environment, or app-config pair; one-shot Raw API flag/environment credentials remain ephemeral, while successful custom-app OAuth login persists its exact pair. Migrates plaintext and legacy client-secret:<clientID> values to appsecret:<clientID> after the canonical reference is durably stored, and fails closed on conflicting values. Dry-run no longer requires credentials and still performs no Keychain, deferred-file, or network access. Pagination now fails closed instead of returning partial pages, and rejects ambiguous continuation request keys. Non-2xx OpenAPI errors expose top-level code and request ID details without treating a successful payload's business code field as an error. Security tightening rejects HTTP, non-443 ports, cross-origin or HTTPS-downgrade redirects, sanitizes server-provided download filenames, bounds JSON/error bodies, and atomically streams binary downloads through a temporary file.