Skip to content

Mallok 0.1.0-rc.8 — panel read scope fix

Pre-release
Pre-release

Choose a tag to compare

@JasonYv JasonYv released this 01 Oct 17:09
· 22 commits to main since this release

A security release: reading plugin panel rows now requires the export scope.

Security

  • Plugin panel rows need export. The panel read was the one plugin admin route without a scope check, so any API token — a publishing-only token included — could read every inquiry, with buyers' names, addresses and messages, that the site export and the panel's CSV action already keep behind export.

Upgrade note: an API token without export now receives 403 instead of panel rows; give it export if it needs them. Signed-in admin sessions hold every scope and are unaffected. Upgrade with npx mallok upgrade --to 0.1.0-rc.8.

Also included

  • The plan for plugin API 2 (phase six of docs/IMPLEMENTATION_PLAN.md) and docs/PLUGIN_API.md §13, with its compatibility rule: version 2 only adds, and the official inquiry plugin runs unchanged. No plugin API 2 feature ships in this release.
  • Product documents agree about Nundar (a Mallok starter, theme and plugin set); Mallok's core still does no carts or payments.
  • A sturdier browser-test lock for contributors.

Candidate provenance

  • Source: ee063e9ffdd9914f1e8560d71fbf11807d1953a6
  • Artifact: mallok-0.1.0-rc.8.tgz
  • SHA-256: a1350de000a4776146d1f60b008bf55e3084cc02c6cd1070f777173e50996003
  • Local release gate: lint, typecheck, 1,064 unit/integration tests, 6 real-upgrade tests, build and bundle budgets, static build, coverage floor, 29 browser/accessibility checks and a whole-history secret scan passed; 27 exact-artifact consumer checks passed against this tarball.
  • GitHub CI and the complete release gate passed. The Linux CI tarball is byte-for-byte identical to the local one, and a clean-clone rebuild reproduced it exactly.
  • The isolated test site was upgraded from rc.7 with mallok upgrade and deployed. Pages, SEO endpoints, Atelier 2.5.1 assets, cache HIT/MISS/HEAD behaviour, credential bypass and admin boundaries behaved as intended. On the deployed site, a real token holding only content:write was refused the inquiry panel with 403 and the export scope named.

Known limitations

This is not stable 0.1. No new CPU sample was taken; the rc.5 measurements remain historical. Real inquiry email delivery, the seven-day media cleanup check, full second-site restore and production upgrade/rollback acceptance remain open. See docs/RELEASE_STATUS.md.

npm is published: mallok@0.1.0-rc.8; next and latest point to it.


安全修复版本:读取插件面板数据现在需要 export 权限,此前任何 API 令牌都能读到询盘客户信息。没有 export 权限的令牌升级后会收到 403,管理员登录会话不受影响。仍不是 0.1 稳定版;GitHub 和 npm 均已发布。