Skip to content

Batoi Press 2.0.0

Choose a tag to compare

@ashwinirath ashwinirath released this 01 Aug 17:06
· 4 commits to main since this release

Batoi Press 2.0.0

Batoi Press 2.0 turns the portable flat-file CMS into a governed,
automation-ready publishing system while retaining PHP 8.1 and conventional
hosting compatibility.

Highlights

  • Add a versioned JSON API and stateless Streamable HTTP MCP endpoint for
    scoped site, content, taxonomy, media, menu, search, and health reads.
  • Add revision-safe, idempotent page/post draft creation and updates plus a
    separate privileged publish operation shared with Admin.
  • Add owner-managed, hashed, expiring, revocable connection tokens and an OAuth
    resource-server boundary for established external authorization providers.
  • Integrate Batoi AIF into page/post editors with an opt-in offline provider,
    bounded context, explicit human apply/copy controls, throttling, and no
    publication authority.
  • Add professional primary/footer menu locations, stable hierarchy, dropdowns,
    nested children, mega menus, keyboard controls, mobile behavior, and static
    export parity in the default theme.
  • Add draft, in-review, approved, scheduled, published, and archived states;
    reviewer notes/history; publish/unpublish timing; and shared taxonomy counts.
  • Add TOTP MFA and recovery codes, encrypted secrets, connection/session
    step-up, session inventory/revocation, idle/absolute expiry, upload signature
    checks, browser security headers, and operator diagnostics.
  • Require Ed25519-signed release indexes and package manifests while retaining
    per-file and ZIP SHA-256 verification, backups, health checks, and rollback.

Compatibility and provider setup

Existing 1.8 content, URLs, menus, themes, installer lock, and customized
runtime configuration remain compatible as documented in
radpress/docs/v2-migration.md.

Personal connection tokens are immediately usable for controlled clients.
Normal ChatGPT/Claude end-user OAuth connection still requires an administrator
to select and configure an established OAuth 2.1 authorization provider; Press
does not implement an authorization server or weaken authentication. External
AIF providers remain disabled until an owner approves the provider, credentials,
data fields, retention, and quotas. The bundled local AIF provider requires no
network call.

Versions

  • Batoi Press: 2.0.0
  • Bundled Batoi Versatile theme: 3.0.0