Releases: fobstack/mallok
Release list
Mallok 0.1.0-rc.9 — fixes from building a real site
Defects found building a real site on rc.7 and rc.8, fixed.
Fixed
mallok publishputs every language of a bundle into one translation group. A bundle withoutmallok.jsonwas saved one language at a time and each got a group of its own, so the pages had no hreflang and no language switcher, whilemallok buildgrouped the same files correctly.- The home page receives
recent.<kind>for every kind the theme lists, notarticlealone. A theme's product section never appeared on a served site. The Worker andmallok buildnow use one rule: the kinds the site enables and the theme gives a list layout, the ten newest of each. - A generated site type-checks its text imports. The package declares
*.liquid,*.css,*.sqland*.mdmodules, so a site with its own theme or a plugin migration passesnpm run typecheck. .dev.vars.examplecarriesMALLOK_SETUP_KEY, without which the wizard refuses to create the administrator of a local site.mallok publish . --with-settingsworks from a project root. Onlycontent/is read, so the package's own template content innode_modulesis no longer published as a page of the site, andsite.jsonis applied before the site's kinds are read.- A publish dry run no longer applies
site.json. - The admin shows a revoked API token as revoked; revoking used to look like a button that did nothing.
- Reloading an admin route no longer answers 503 when the browser sends cache validators (seen under
wrangler dev).
Added
escapeHtmlandrenderTextTemplateare exported frommallok/worker, so a plugin that lives in a site can build its own HTML and email. A rendered text template is not HTML-escaped; seedocs/PLUGIN_API.md §7.6.POST /contentreturnstranslationGroup, andGET /contentaccepts aslugfilter.
Upgrade notes
- Bundles already split into several translation groups are not merged by publishing again: an existing item keeps its group. Delete the extra languages and publish the bundle again.
- A static build's home page lists ten items per kind, not twelve, and a kind without a list layout gets no
recentgroup. A served site always showed ten. - A site with its own
text-modules.d.tsshould delete it. WithskipLibCheck: falsethe two copies are reported as duplicate identifiers; with the template'sskipLibCheck: truenothing is reported. - Deploy after upgrading, before you publish. A newer CLI against a site still running an older release falls back to one group per language.
Upgrade with npx mallok upgrade --to 0.1.0-rc.9.
Candidate provenance
- Source:
8772a77e812336082416bdda9f0e4f393eb4234f - Artifact:
mallok-0.1.0-rc.9.tgz - SHA-256:
ab2f2993d769cb8f16be30b923501507e3ae790b3a206d19626fae8715891b0a - Local release gate: lint, typecheck, 1,097 unit/integration tests, 6 real-upgrade tests, build and bundle budgets, static build, coverage floor, 31 browser/accessibility checks and a whole-history secret scan passed; 29 exact-artifact consumer checks passed against this tarball.
- GitHub CI and the complete release gate passed. The Linux CI tarball is byte-for-byte identical to the local one, and a clean-clone rebuild reproduced it exactly.
- The isolated test site was upgraded from rc.8 with
mallok upgradeand deployed. Checked on the deployed site: the home pages in both languages show the product section with its three products; a two-language bundle withoutmallok.json, published with the real CLI, landed in one translation group with hreflang on both pages, and publishing it again reported both unchanged; reloading an admin route with cache validators answered 200. Pages, SEO endpoints, cache HIT/MISS/HEAD behaviour, credential bypass and admin boundaries behaved as intended.
Known limitations
This is not stable 0.1. No new CPU sample was taken; the rc.5 measurements remain historical, and the home page now runs one statement per listed kind. Real inquiry email delivery, the seven-day media cleanup check, full second-site restore and production upgrade/rollback acceptance remain open. See docs/RELEASE_STATUS.md.
npm is published: mallok@0.1.0-rc.9; next and latest point to it.
修复在 rc.7、rc.8 上搭建真实站点时发现的问题:多语言文章包发布后归入同一个翻译组、首页为主题列出的每种内容类型提供最近内容、生成的站点能通过类型检查并在本地认领、可以从项目根目录发布、dry run 不再写入设置,以及两个后台修复。升级前请看上面的四条升级说明。仍不是 0.1 稳定版;GitHub 和 npm 均已发布。
Mallok 0.1.0-rc.8 — panel read scope fix
A security release: reading plugin panel rows now requires the export scope.
Security
- Plugin panel rows need
export. The panel read was the one plugin admin route without a scope check, so any API token — a publishing-only token included — could read every inquiry, with buyers' names, addresses and messages, that the site export and the panel's CSV action already keep behindexport.
Upgrade note: an API token without export now receives 403 instead of panel rows; give it export if it needs them. Signed-in admin sessions hold every scope and are unaffected. Upgrade with npx mallok upgrade --to 0.1.0-rc.8.
Also included
- The plan for plugin API 2 (phase six of
docs/IMPLEMENTATION_PLAN.md) anddocs/PLUGIN_API.md §13, with its compatibility rule: version 2 only adds, and the officialinquiryplugin runs unchanged. No plugin API 2 feature ships in this release. - Product documents agree about Nundar (a Mallok starter, theme and plugin set); Mallok's core still does no carts or payments.
- A sturdier browser-test lock for contributors.
Candidate provenance
- Source:
ee063e9ffdd9914f1e8560d71fbf11807d1953a6 - Artifact:
mallok-0.1.0-rc.8.tgz - SHA-256:
a1350de000a4776146d1f60b008bf55e3084cc02c6cd1070f777173e50996003 - Local release gate: lint, typecheck, 1,064 unit/integration tests, 6 real-upgrade tests, build and bundle budgets, static build, coverage floor, 29 browser/accessibility checks and a whole-history secret scan passed; 27 exact-artifact consumer checks passed against this tarball.
- GitHub CI and the complete release gate passed. The Linux CI tarball is byte-for-byte identical to the local one, and a clean-clone rebuild reproduced it exactly.
- The isolated test site was upgraded from rc.7 with
mallok upgradeand deployed. Pages, SEO endpoints, Atelier 2.5.1 assets, cache HIT/MISS/HEAD behaviour, credential bypass and admin boundaries behaved as intended. On the deployed site, a real token holding onlycontent:writewas refused the inquiry panel with 403 and theexportscope named.
Known limitations
This is not stable 0.1. No new CPU sample was taken; the rc.5 measurements remain historical. Real inquiry email delivery, the seven-day media cleanup check, full second-site restore and production upgrade/rollback acceptance remain open. See docs/RELEASE_STATUS.md.
npm is published: mallok@0.1.0-rc.8; next and latest point to it.
安全修复版本:读取插件面板数据现在需要 export 权限,此前任何 API 令牌都能读到询盘客户信息。没有 export 权限的令牌升级后会收到 403,管理员登录会话不受影响。仍不是 0.1 稳定版;GitHub 和 npm 均已发布。
Mallok 0.1.0-rc.7 — fixes and B2B CMS positioning
The second public preview candidate: fixes found since rc.6 and the Cloudflare-native CMS positioning for multilingual B2B websites.
What's changed
- Atelier 2.5.1. The homepage carousel checks every control before it changes the page and falls back to the no-JavaScript layout, so a template missing one keeps a readable hero instead of hiding every slide but the first. The version moved from 2.5.0 so that browsers holding rc.6's immutable 2.5.0 script fetch the fix.
- Theme asset guard.
pnpm testfails when an official theme asset changes without a new theme version;pnpm themes:recordrecords a bumped one and refuses to record changed assets under an unchanged version. - Export downloads retry up to three times with a growing delay, on the CLI and in the browser. Refusals the site would repeat still fail immediately.
- Slug field normalises its value on blur and before saving, and says what it changed, instead of returning a 400 after the fact.
prototypeandconstructorare accepted as article slugs and no longer make the whole site unexportable.- English-first setup and inquiry guide; npm, GitHub and README describe Mallok as the Cloudflare-native CMS for multilingual B2B websites, and the npm keywords drop
headless-cms.
Candidate provenance
- Source:
0af520bf87c81fa3814a3abb3361ca93fa87e457 - Artifact:
mallok-0.1.0-rc.7.tgz - SHA-256:
45813a782d00a2d4984334b8ecb18df21f0c6a2d2694a33652c7b1846dd648a9 - Local release gate: lint, typecheck, 1,061 unit/integration tests, 6 real-upgrade tests, build and bundle budgets, static build, coverage floor, 29 browser/accessibility checks and a whole-history secret scan passed; 27 exact-artifact consumer checks passed against this tarball.
- GitHub CI and the complete release gate passed. The Linux CI tarball is byte-for-byte identical to the local one, and a clean-clone rebuild reproduced it exactly.
- The existing isolated test site was upgraded from rc.6 with
mallok upgrade(typecheck, tests, build and deploy dry-run passed) and deployed. English/Chinese pages, SEO endpoints and/theme/atelier/2.5.1/assets returned HTTP 200 with the served carousel matching this artifact; MISS→HIT and HEAD cache hits, credential bypass, the themed 404 and admin 401/404 boundaries behaved as intended.
Known limitations
This is not stable 0.1. The rc.5 CPU measurements are historical, not rc.7 benchmarks, and no new CPU sample was taken. Real inquiry email delivery, the seven-day media cleanup check, full second-site restore and production upgrade/rollback acceptance remain open. The test site holds verification content rather than a curated demo. See docs/RELEASE_STATUS.md.
npm is published: mallok@0.1.0-rc.7; next and latest point to it. Create a site with npx mallok@0.1.0-rc.7 create my-site (add --no-deploy for local validation only), or upgrade with npx mallok upgrade --to 0.1.0-rc.7.
Mallok 第二个公开预览候选版:包含 rc.6 之后的修复,以及面向多语言 B2B 网站的 Cloudflare 原生 CMS 定位。Atelier 升级到 2.5.1,确保老访客也能拿到轮播修复。仍不是 0.1 稳定版,未完成的验收见发布状态文档;GitHub 和 npm 均已发布。
Mallok 0.1.0-rc.6 — Atelier preview
Mallok's first public preview candidate: a Cloudflare-native website framework with Markdown content, a web admin, Liquid themes, and plugins.
What's included
- Atelier 2.5 with responsive industrial imagery and a bilingual, accessible three-story homepage carousel.
- Manual selectors, arrows, keyboard and touch navigation; native navigation remains available without JavaScript.
- A declared homepage-only script (2,616 bytes); content pages remain script-free.
- English-first documentation and Chinese translations.
- Generated-site smoke checks stop the complete Wrangler process tree instead of leaving subprocesses behind.
Candidate provenance
- Source:
563b366e6e66d535c260543e4c91147269ea2395 - Artifact:
mallok-0.1.0-rc.6.tgz - SHA-256:
aed30e5e2dd828a246665895a1da51696c48b5176a41328c32a147c0f640d3ff - Local checks: lint, typecheck, build, 1,034 unit/integration tests and 27 exact-artifact consumer checks passed. Browser checks cover keyboard, touch, no-JavaScript navigation and accessibility.
- GitHub CI and the complete release gate passed.
- The exact artifact was deployed to the existing isolated test site. English/Chinese pages and new assets returned HTTP 200; public/HEAD cache hits and credential bypass retained the intended cache policy.
Known limitations
This is not stable 0.1. The rc.5 CPU measurements are historical, not rc.6 benchmarks. Real inquiry email delivery, natural seven-day media cleanup, full second-site restore and production upgrade/rollback acceptance remain open. The test site contains verification content rather than a curated public demo. See docs/RELEASE_STATUS.md for details.
npm is published: mallok@0.1.0-rc.6. Create a site with npx mallok@0.1.0-rc.6 create my-site (add --no-deploy for local validation only). The registry integrity matches the attached tarball. The attached tarball is the selected candidate, not a guarantee that every stable-release gate is complete.
这是 Mallok 的首个公开预览候选版,包含 Atelier 2.5、新的三图轮播与中英文文档。尚未完成稳定版全部验收;GitHub 和 npm 均已发布;这仍是候选版,请以发布状态文档为准。