// changelog
更新日志
每个版本的新增、修复与升级说明。站点通过固定 tag 升级。
All notable changes to NuxtCMS. Sites pin a tag (github:guxingbiao0507/nuxtcms#vX.Y.Z).
v1.3.2 — 2026-10-02
Docs only (sites can stay on v1.3.1).
- Site CSS contract: the base's
~/assets/css/main.cssresolves to the site's own file, which must importtailwindcssand@nuxt/uiand add@source "../../../node_modules/nuxtcms/app"so the base admin pages (Plugins, Tools, ...) are styled. All sites got that line with the v1.3 upgrade. - Upgrade steps in docs/*/getting-started.md.
v1.3.1 — 2026-10-02
Added
NUXT_SETUP_TOKEN: when set, the install wizard requires it, so the first visitor of a fresh public deployment cannot claim the admin account.- Extensible admin menu:
app.config.ts→nuxtcms.adminNav(label / labelKey, icon, to, adminOnly, after). Sites, layers and package plugins add their own admin pages without overriding the layout.
v1.3.0 — 2026-10-02
Plugins, an official plugin hub, WordPress-grade editing and more deployment targets.
Added
- Plugin system (Admin → Plugins, docs/zh/plugins.md):
- runtime plugins: a JSON manifest with settings, injected head/body snippets, per-response CSP sources, webhooks on CMS events and scheduled tasks; installed online without a rebuild;
- package plugins: Nuxt layers installed with
scripts/plugin.mjs add|remove|list, recorded innuxtcms.plugins.jsonand extended automatically;defineCmsPlugin(),isPluginActive(),getPluginSettings(); - CMS events
contact.created,content.published|updated|deleted,plugin.installed; - new
pluginstable (migration 0015 / pg+mysql 0003).
- Official plugin hub client: marketplace with updates, account binding by API token, purchase
with credits, license requests, per-domain licenses verified daily by the cron dispatcher (last
result kept when the hub is unreachable). Hub:
NUXT_PLUGIN_HUB_URL(default https://insightme.top). - 10 official plugins bundled in
plugins/official/(offline marketplace fallback): Baidu Tongji, Google Analytics 4, Microsoft Clarity, Tawk.to chat, custom code, WeCom / DingTalk / Feishu robots (paid), inquiry e-mails, daily search-engine push. - Scheduled publishing: status
scheduled+ publish time in the editor; the cron tick publishes due posts, pages and products, firescontent.publishedand clears the API cache. - Revisions: a snapshot before every edit (newest 30 per item), history modal with preview and
one-click restore (the restore itself is undoable). New
revisionstable (0016 / pg+mysql 0004). - Tools page: JSON backup export (secrets excluded) / restore by natural keys across sqlite, D1, pg and mysql; WordPress import (WXR, parsed in the browser and uploaded in batches so it stays inside edge CPU limits): posts, pages, categories, tags, dates, slugs; block comments removed.
- Deployment targets:
NUXT_DEPLOY_TARGETpasses any Nitro preset through (vercel, netlify, aws-lambda, azure-functions, deno-deploy, firebase, bun...); serverless builds skip the fs cache and prerendering;DATABASE_AUTH_TOKENfor Turso / remote libSQL. Deploy guide adds a selection table incl. Alibaba Cloud FC, Tencent SCF / EdgeOne, OSS / COS static hosting.
Fixed
/,/zh,/usreturned 404 in v1.2.0: the IndexNow key routeserver/routes/[key].txt.get.tsregistered as/:keyand captured every one-segment path. It is now a middleware that only answers/<key>.txtwhen the key matches./api/public/siteno longer exposes private settings (tokens, secrets, SMTP, hub binding).
Upgrade
- Apply migrations
0015_plugins.sqland0016_revisions.sql(both idempotent) to D1, or letNUXT_DB_AUTO_MIGRATE=1run them on node. - Optional: set
NUXT_CRON_SECRET+ the cron Worker for scheduled publishing, plugin tasks and license checks.
v1.2.0 — 2026-10-02
Engineering hardening, inspired by edge-native starters and by features proven in the *-site projects.
Added
- Cron dispatcher
POST /api/cron/dispatch(BearerNUXT_CRON_SECRET): runs the admin "Scheduled tasks" table on its cron schedules (site timezonecronTzOffset, default +480), prunes task logs, purges expired rate-limit rows.deploy/cron-workeris a ready Worker for Pages sites; Linux/Baota can use crontab. Promoted from zbservice. - Contact notifications
POST /api/cron/send-contact-emails: e-mails new inquiries to thecontactNotifyEmail(orcompanyEmail) setting; progress tracked without touching contact status. Replaces seven per-site copies. - Search engine push
POST /api/cron/push-search-engines: IndexNow (Bing/Yandex/...) and Baidu, configured by theindexNowKey/baiduPushTokensettings;/{key}.txtserved automatically. - View counter
GET|POST /api/views+useViewCounter()composable, stored in the newcontent_viewstable; blog and product pages show live counts. Generalized from wxrx / zbservice hits. - Cloudflare Turnstile (optional):
verifyTurnstileToken,assertTurnstile,useTurnstile(); the contact form uses it whenNUXT_TURNSTILE_SECRET_KEY+NUXT_PUBLIC_TURNSTILE_SITE_KEYare set. - Persistent rate limiting: counters in the new
rate_limitstable, shared across Workers isolates and Node processes; falls back to memory when the table is missing. - Health probe
GET /api/health(database round trip, driver, storage, version) for Uptime Kuma / Baota. - Startup environment check (
server/plugins/00.env-check.ts): warns about missing or half-configured settings;NUXT_STRICT_ENV=1fails fast in production. - Cloudflare Web Analytics (cookieless) via
NUXT_PUBLIC_CF_ANALYTICS_TOKEN. AGENTS.md/CLAUDE.mdfor coding agents, Vitest unit tests (pnpm test), GitHub Actions CI,runtimeConfig.public.nuxtcmsVersion.
Migrations
0013_rate_limits,0014_content_views(SQLite, idempotent),0001/0002for pg and mysql.
v1.1.2 — 2026-09-17
- Default caching strategy for every site: pages
public, max-age=0, s-maxage=60, stale-while-revalidate=300,/api/**and adminno-store, hashed assets and media immutable, robots/sitemap/llms one hour.
v1.1.1 — 2026-09-16
- Locale message files that exist only in a site layer are resolved by absolute path.
v1.1.0 — 2026-09-16
- Database dialects: SQLite / D1, PostgreSQL, MySQL behind one adapter layer.
- API response cache with admin include / exclude path rules.
- Media storage drivers: local, R2, Alibaba OSS, Tencent COS, S3.
- GET / POST only API; locales zh + us (
/en→/us); bilingual demo site. - SEO and AI GEO: per-locale SEO, multilingual sitemap with lastmod, dynamic robots.txt with AI crawler policy, llms.txt, llms-full.txt, AI summary, JSON-LD, hreflang.
- Deployment targets: Cloudflare Pages, Workers, Node / Linux / Baota, static frontend + API.
v1.0.0 — 2026-07-13
- Initial NuxtCMS: Nuxt 4 + Nuxt UI, Drizzle on D1, JWT admin, posts/pages/products, R2 media, i18n, SEO.