Mallok 0.1.0-rc.8 — panel read scope fix
Pre-releaseA security release: reading plugin panel rows now requires the export scope.
Security
- Plugin panel rows need
export. The panel read was the one plugin admin route without a scope check, so any API token — a publishing-only token included — could read every inquiry, with buyers' names, addresses and messages, that the site export and the panel's CSV action already keep behindexport.
Upgrade note: an API token without export now receives 403 instead of panel rows; give it export if it needs them. Signed-in admin sessions hold every scope and are unaffected. Upgrade with npx mallok upgrade --to 0.1.0-rc.8.
Also included
- The plan for plugin API 2 (phase six of
docs/IMPLEMENTATION_PLAN.md) anddocs/PLUGIN_API.md §13, with its compatibility rule: version 2 only adds, and the officialinquiryplugin runs unchanged. No plugin API 2 feature ships in this release. - Product documents agree about Nundar (a Mallok starter, theme and plugin set); Mallok's core still does no carts or payments.
- A sturdier browser-test lock for contributors.
Candidate provenance
- Source:
ee063e9ffdd9914f1e8560d71fbf11807d1953a6 - Artifact:
mallok-0.1.0-rc.8.tgz - SHA-256:
a1350de000a4776146d1f60b008bf55e3084cc02c6cd1070f777173e50996003 - Local release gate: lint, typecheck, 1,064 unit/integration tests, 6 real-upgrade tests, build and bundle budgets, static build, coverage floor, 29 browser/accessibility checks and a whole-history secret scan passed; 27 exact-artifact consumer checks passed against this tarball.
- GitHub CI and the complete release gate passed. The Linux CI tarball is byte-for-byte identical to the local one, and a clean-clone rebuild reproduced it exactly.
- The isolated test site was upgraded from rc.7 with
mallok upgradeand deployed. Pages, SEO endpoints, Atelier 2.5.1 assets, cache HIT/MISS/HEAD behaviour, credential bypass and admin boundaries behaved as intended. On the deployed site, a real token holding onlycontent:writewas refused the inquiry panel with 403 and theexportscope named.
Known limitations
This is not stable 0.1. No new CPU sample was taken; the rc.5 measurements remain historical. Real inquiry email delivery, the seven-day media cleanup check, full second-site restore and production upgrade/rollback acceptance remain open. See docs/RELEASE_STATUS.md.
npm is published: mallok@0.1.0-rc.8; next and latest point to it.
安全修复版本:读取插件面板数据现在需要 export 权限,此前任何 API 令牌都能读到询盘客户信息。没有 export 权限的令牌升级后会收到 403,管理员登录会话不受影响。仍不是 0.1 稳定版;GitHub 和 npm 均已发布。