Skip to content

docs(release): publish v1.11.11 release notes - #464

Merged
seakee merged 1 commit into
mainfrom
release/v1.11.11
Jul 31, 2026
Merged

docs(release): publish v1.11.11 release notes#464
seakee merged 1 commit into
mainfrom
release/v1.11.11

Conversation

@seakee

@seakee seakee commented Jul 31, 2026

Copy link
Copy Markdown
Owner

Summary

Prepare the v1.11.11 patch-release records for the merged Manager Server plugin resource authorization fix. This PR adds the bilingual, tag-pinned release notes and the reviewed Telegram notification body before the release tag is created.

Scope

  • Frontend panel
  • Manager Server
  • CPA panel mode
  • Full Docker mode
  • Native packages / release
  • Docs / Wiki
  • CI / build / tooling

Changes

  • Add Chinese and English v1.11.11 release notes covering the Manager Server plugin resource authorization fix, affected versions, scope, and upgrade guidance.
  • Add the validated Telegram HTML release post, including the external contributor acknowledgement.

User Impact

Users receive clear upgrade guidance for the security fix: unauthenticated plugin resource requests can no longer be elevated with the saved CPA Management Key, while plugin caller-auth and public-resource behavior remain compatible.

Compatibility / Runtime Notes

  • CPA panel mode: Unchanged and unaffected.
  • Manager Server mode: The previously merged fix uses the saved CPA Management Key only after valid CPAMP admin authentication.
  • Full Docker / native packages: Upgrade includes the fix; no configuration or database migration is required.

Data / Security Notes

This documents a security fix for the Manager Server plugin resource proxy. No secrets, credentials, or tokens are added to the release files, logs, or PR body. The release notes advise users with formerly untrusted exposure to inspect relevant logs and rotate plugin-side secrets only where warranted.

Risk / Rollback

Risk level: Low

Rollback notes:

This is a release-notes-only PR. Before tagging, it can be reverted normally. Do not roll back the merged authorization fix on externally reachable Manager Server deployments.

Verification

  • Type check
  • Lint
  • Tests
  • Build
  • Manual UI check
  • Docs/link check
  • Not applicable, docs-only

Commands / evidence:

Release range: v1.11.10..842eec791377ddcbea5cd639bc065eaa4801d656
Range statistics: 2 commits, 2 files changed, +65 / -14
git diff --check v1.11.10..main: PASS
PR #463 checks: Scope, PR Template, Manager Server, Manager Server SQLite (Windows), and Docker Build: PASS
PR #463 Frontend and Native Control checks: expected scope skips
Release-note language links are tag-pinned to v1.11.11 paths.
Telegram HTML uses only allowed tags and is 486 characters.

Screenshots / Recordings

N/A — release documentation and notification copy only.

Docs

  • README / README_CN updated for user-visible capabilities
  • Matching docs manual and navigation updated
  • Demo fixtures, screenshots, and deep links reviewed
  • Release notes needed
  • Not needed — explanation included below

Docs decision:

This PR adds the required Chinese and English release records plus the Telegram post. No separate user-guide or UI documentation change is needed for this backend security fix.

Related

Refs #462, #463

@seakee
seakee merged commit ac2bd06 into main Jul 31, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant