// changelog

更新日志

每个版本的新增、修复与升级说明。站点通过固定 tag 升级。

All notable changes to NuxtCMS. Sites pin a tag (github:guxingbiao0507/nuxtcms#vX.Y.Z).

v1.3.2 — 2026-10-02

Docs only (sites can stay on v1.3.1).

  • Site CSS contract: the base's ~/assets/css/main.css resolves to the site's own file, which must import tailwindcss and @nuxt/ui and add @source "../../../node_modules/nuxtcms/app" so the base admin pages (Plugins, Tools, ...) are styled. All sites got that line with the v1.3 upgrade.
  • Upgrade steps in docs/*/getting-started.md.

v1.3.1 — 2026-10-02

Added

  • NUXT_SETUP_TOKEN: when set, the install wizard requires it, so the first visitor of a fresh public deployment cannot claim the admin account.
  • Extensible admin menu: app.config.ts → nuxtcms.adminNav (label / labelKey, icon, to, adminOnly, after). Sites, layers and package plugins add their own admin pages without overriding the layout.

v1.3.0 — 2026-10-02

Plugins, an official plugin hub, WordPress-grade editing and more deployment targets.

Added

  • Plugin system (Admin → Plugins, docs/zh/plugins.md):
    • runtime plugins: a JSON manifest with settings, injected head/body snippets, per-response CSP sources, webhooks on CMS events and scheduled tasks; installed online without a rebuild;
    • package plugins: Nuxt layers installed with scripts/plugin.mjs add|remove|list, recorded in nuxtcms.plugins.json and extended automatically; defineCmsPlugin(), isPluginActive(), getPluginSettings();
    • CMS events contact.created, content.published|updated|deleted, plugin.installed;
    • new plugins table (migration 0015 / pg+mysql 0003).
  • Official plugin hub client: marketplace with updates, account binding by API token, purchase with credits, license requests, per-domain licenses verified daily by the cron dispatcher (last result kept when the hub is unreachable). Hub: NUXT_PLUGIN_HUB_URL (default https://insightme.top).
  • 10 official plugins bundled in plugins/official/ (offline marketplace fallback): Baidu Tongji, Google Analytics 4, Microsoft Clarity, Tawk.to chat, custom code, WeCom / DingTalk / Feishu robots (paid), inquiry e-mails, daily search-engine push.
  • Scheduled publishing: status scheduled + publish time in the editor; the cron tick publishes due posts, pages and products, fires content.published and clears the API cache.
  • Revisions: a snapshot before every edit (newest 30 per item), history modal with preview and one-click restore (the restore itself is undoable). New revisions table (0016 / pg+mysql 0004).
  • Tools page: JSON backup export (secrets excluded) / restore by natural keys across sqlite, D1, pg and mysql; WordPress import (WXR, parsed in the browser and uploaded in batches so it stays inside edge CPU limits): posts, pages, categories, tags, dates, slugs; block comments removed.
  • Deployment targets: NUXT_DEPLOY_TARGET passes any Nitro preset through (vercel, netlify, aws-lambda, azure-functions, deno-deploy, firebase, bun...); serverless builds skip the fs cache and prerendering; DATABASE_AUTH_TOKEN for Turso / remote libSQL. Deploy guide adds a selection table incl. Alibaba Cloud FC, Tencent SCF / EdgeOne, OSS / COS static hosting.

Fixed

  • /, /zh, /us returned 404 in v1.2.0: the IndexNow key route server/routes/[key].txt.get.ts registered as /:key and captured every one-segment path. It is now a middleware that only answers /<key>.txt when the key matches.
  • /api/public/site no longer exposes private settings (tokens, secrets, SMTP, hub binding).

Upgrade

  • Apply migrations 0015_plugins.sql and 0016_revisions.sql (both idempotent) to D1, or let NUXT_DB_AUTO_MIGRATE=1 run them on node.
  • Optional: set NUXT_CRON_SECRET + the cron Worker for scheduled publishing, plugin tasks and license checks.

v1.2.0 — 2026-10-02

Engineering hardening, inspired by edge-native starters and by features proven in the *-site projects.

Added

  • Cron dispatcher POST /api/cron/dispatch (Bearer NUXT_CRON_SECRET): runs the admin "Scheduled tasks" table on its cron schedules (site timezone cronTzOffset, default +480), prunes task logs, purges expired rate-limit rows. deploy/cron-worker is a ready Worker for Pages sites; Linux/Baota can use crontab. Promoted from zbservice.
  • Contact notifications POST /api/cron/send-contact-emails: e-mails new inquiries to the contactNotifyEmail (or companyEmail) setting; progress tracked without touching contact status. Replaces seven per-site copies.
  • Search engine push POST /api/cron/push-search-engines: IndexNow (Bing/Yandex/...) and Baidu, configured by the indexNowKey / baiduPushToken settings; /{key}.txt served automatically.
  • View counter GET|POST /api/views + useViewCounter() composable, stored in the new content_views table; blog and product pages show live counts. Generalized from wxrx / zbservice hits.
  • Cloudflare Turnstile (optional): verifyTurnstileToken, assertTurnstile, useTurnstile(); the contact form uses it when NUXT_TURNSTILE_SECRET_KEY + NUXT_PUBLIC_TURNSTILE_SITE_KEY are set.
  • Persistent rate limiting: counters in the new rate_limits table, shared across Workers isolates and Node processes; falls back to memory when the table is missing.
  • Health probe GET /api/health (database round trip, driver, storage, version) for Uptime Kuma / Baota.
  • Startup environment check (server/plugins/00.env-check.ts): warns about missing or half-configured settings; NUXT_STRICT_ENV=1 fails fast in production.
  • Cloudflare Web Analytics (cookieless) via NUXT_PUBLIC_CF_ANALYTICS_TOKEN.
  • AGENTS.md / CLAUDE.md for coding agents, Vitest unit tests (pnpm test), GitHub Actions CI, runtimeConfig.public.nuxtcmsVersion.

Migrations

  • 0013_rate_limits, 0014_content_views (SQLite, idempotent), 0001/0002 for pg and mysql.

v1.1.2 — 2026-09-17

  • Default caching strategy for every site: pages public, max-age=0, s-maxage=60, stale-while-revalidate=300, /api/** and admin no-store, hashed assets and media immutable, robots/sitemap/llms one hour.

v1.1.1 — 2026-09-16

  • Locale message files that exist only in a site layer are resolved by absolute path.

v1.1.0 — 2026-09-16

  • Database dialects: SQLite / D1, PostgreSQL, MySQL behind one adapter layer.
  • API response cache with admin include / exclude path rules.
  • Media storage drivers: local, R2, Alibaba OSS, Tencent COS, S3.
  • GET / POST only API; locales zh + us (/en → /us); bilingual demo site.
  • SEO and AI GEO: per-locale SEO, multilingual sitemap with lastmod, dynamic robots.txt with AI crawler policy, llms.txt, llms-full.txt, AI summary, JSON-LD, hreflang.
  • Deployment targets: Cloudflare Pages, Workers, Node / Linux / Baota, static frontend + API.

v1.0.0 — 2026-07-13

  • Initial NuxtCMS: Nuxt 4 + Nuxt UI, Drizzle on D1, JWT admin, posts/pages/products, R2 media, i18n, SEO.