升级 NotionNext 4.9.3 → 4.10.10(修复线上 Notion 取数失败) - #4
Conversation
Guard category/tag getStaticPaths when Notion option data is missing or not an array.
Co-authored-by: yun <eatthesun0319@gmail> Co-authored-by: tangly1024 <mail@tangly1024.com>
Sync endspace with upstream cloud-oc/endspace theme branch. Closes notionnext-org#4083.
Bumps [notion-utils](https://github.com/NotionX/react-notion-x) from 7.11.1 to 7.12.1. - [Release notes](https://github.com/NotionX/react-notion-x/releases) - [Commits](NotionX/react-notion-x@v7.11.1...v7.12.1) --- updated-dependencies: - dependency-name: notion-utils dependency-version: 7.12.1 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: tangly1024 <mail@tangly1024.com>
Co-authored-by: tangly1024 <mail@tangly1024.com>
Bumps [next](https://github.com/vercel/next.js) from 15.5.23 to 15.5.24. - [Release notes](https://github.com/vercel/next.js/releases) - [Commits](vercel/next.js@v15.5.23...v15.5.24) --- updated-dependencies: - dependency-name: next dependency-version: 15.5.24 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…-org#4480) Bumps [@supabase/supabase-js](https://github.com/supabase/supabase-js/tree/HEAD/packages/core/supabase-js) from 2.112.3 to 2.112.4. - [Release notes](https://github.com/supabase/supabase-js/releases) - [Changelog](https://github.com/supabase/supabase-js/blob/master/packages/core/supabase-js/CHANGELOG.md) - [Commits](https://github.com/supabase/supabase-js/commits/v2.112.4/packages/core/supabase-js) --- updated-dependencies: - dependency-name: "@supabase/supabase-js" dependency-version: 2.112.4 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: tangly1024 <mail@tangly1024.com>
Bumps [axios](https://github.com/axios/axios) from 1.19.0 to 1.20.0. - [Release notes](https://github.com/axios/axios/releases) - [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md) - [Commits](axios/axios@v1.19.0...v1.20.0) --- updated-dependencies: - dependency-name: axios dependency-version: 1.20.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: tangly1024 <mail@tangly1024.com>
Co-authored-by: tangly1024 <mail@tangly1024.com>
Co-authored-by: tangly1024 <mail@tangly1024.com>
…tes (notionnext-org#4485) Bumps the dev-dependencies group with 6 updates in the / directory: | Package | From | To | | --- | --- | --- | | [@ai-sdk/google](https://github.com/vercel/ai/tree/HEAD/packages/google) | `4.0.50` | `4.0.57` | | [@ai-sdk/vue](https://github.com/vercel/ai/tree/HEAD/packages/vue) | `4.0.77` | `4.0.84` | | [marked](https://github.com/markedjs/marked) | `18.0.10` | `18.0.11` | | [sharp](https://github.com/lovell/sharp) | `0.35.3` | `0.35.4` | | [vitepress-chat](https://github.com/cssnr/vitepress-chat) | `0.0.4` | `0.0.5` | | [zod](https://github.com/colinhacks/zod) | `4.4.3` | `4.5.2` | Updates `@ai-sdk/google` from 4.0.50 to 4.0.57 - [Release notes](https://github.com/vercel/ai/releases) - [Changelog](https://github.com/vercel/ai/blob/main/packages/google/CHANGELOG.md) - [Commits](https://github.com/vercel/ai/commits/@ai-sdk/google@4.0.57/packages/google) Updates `@ai-sdk/vue` from 4.0.77 to 4.0.84 - [Release notes](https://github.com/vercel/ai/releases) - [Changelog](https://github.com/vercel/ai/blob/main/packages/vue/CHANGELOG.md) - [Commits](https://github.com/vercel/ai/commits/@ai-sdk/vue@4.0.84/packages/vue) Updates `ai` from 7.0.77 to 7.0.84 - [Release notes](https://github.com/vercel/ai/releases) - [Changelog](https://github.com/vercel/ai/blob/main/packages/ai/CHANGELOG.md) - [Commits](https://github.com/vercel/ai/commits/ai@7.0.84/packages/ai) Updates `marked` from 18.0.10 to 18.0.11 - [Release notes](https://github.com/markedjs/marked/releases) - [Commits](markedjs/marked@v18.0.10...v18.0.11) Updates `sharp` from 0.35.3 to 0.35.4 - [Release notes](https://github.com/lovell/sharp/releases) - [Commits](lovell/sharp@v0.35.3...v0.35.4) Updates `vitepress-chat` from 0.0.4 to 0.0.5 - [Release notes](https://github.com/cssnr/vitepress-chat/releases) - [Commits](cssnr/vitepress-chat@0.0.4...0.0.5) Updates `zod` from 4.4.3 to 4.5.2 - [Release notes](https://github.com/colinhacks/zod/releases) - [Commits](colinhacks/zod@v4.4.3...v4.5.2) --- updated-dependencies: - dependency-name: "@ai-sdk/google" dependency-version: 4.0.57 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dev-dependencies - dependency-name: "@ai-sdk/vue" dependency-version: 4.0.84 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dev-dependencies - dependency-name: ai dependency-version: 7.0.84 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dev-dependencies - dependency-name: marked dependency-version: 18.0.11 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dev-dependencies - dependency-name: sharp dependency-version: 0.35.4 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dev-dependencies - dependency-name: vitepress-chat dependency-version: 0.0.5 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dev-dependencies - dependency-name: zod dependency-version: 4.5.2 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dev-dependencies ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: tangly1024 <mail@tangly1024.com>
…rg#4493) Bumps [postcss-selector-parser](https://github.com/postcss/postcss-selector-parser) from 6.1.2 to 6.1.4. - [Release notes](https://github.com/postcss/postcss-selector-parser/releases) - [Changelog](https://github.com/postcss/postcss-selector-parser/blob/main/CHANGELOG.md) - [Commits](postcss/postcss-selector-parser@v6.1.2...6.1.4) --- updated-dependencies: - dependency-name: postcss-selector-parser dependency-version: 6.1.4 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…g#4486) Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.37.3 to 4.37.9. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@v4.37.3...v4.37.9) --- updated-dependencies: - dependency-name: github/codeql-action dependency-version: 4.37.9 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: tangly1024 <mail@tangly1024.com>
…gement (notionnext-org#4492) * feat(mcp): bundle NotionNext Content MCP for AI-assisted content management Add a zero-dependency MCP server so Claude Code, Codex CLI, Cursor, and other AI coding assistants can read and write the Notion databases behind a NotionNext site over the Model Context Protocol. - tools/notionnext-content-mcp: 10 tools covering status inspection, draft build/create, data source schema inspection, page query/read/ update, block append, archive, and optional site cache refresh - Review-first safety model: writes default to an Invisible draft, tokens are redacted from every output, and operations are scoped to data sources registered via environment variables - NotionNext native write contract: first-class properties for structured fields, page blocks for body content, native Page Cover for covers; any ext-field write is rejected before a network request is made - docs/developer/NOTIONNEXT_CONTENT_MCP(.en).md: setup guides with connection snippets for Claude Code, Codex CLI, and Cursor - .env.example: optional MCP variable block * fix(mcp): harden ops credential handling in refresh_site_cache - Derive the ops cookie token with salted scrypt instead of a single SHA-256 pass, resolving the high-severity CodeQL alert (js/insufficient-password-hash) - Resolve the revalidate target URL from environment variables only and drop the model-controllable baseUrl argument, so the derived ops credential can never be sent to an arbitrary URL - Document the scrypt token contract in both setup guides * fix(mcp): fail closed when a page is outside any data source Pre-auditing the write boundary ahead of the focused review found one gap: getAllowedPage only asserted the allow-list when a page reported a parent data source id, so pages outside any data source (e.g. workspace-level pages) were readable and writable through get/update/append/archive without ever passing the allow-list check. - Extract assertPageInsideAllowedDataSource(page) and reject outright when no parent data source exists, so the boundary fails closed - Export the boundary check and cover it in the offline smoke test with three cases: allow-listed parent passes, unregistered id rejected, workspace-level page rejected - Document the fail-closed rule in both setup guides --------- Co-authored-by: tangly1024 <mail@tangly1024.com>
* fix(starter): 修复首页导航栏 hover 文字与主色背景颜色冲突 首页 Hero 区背景为 bg-primary(主色蓝),导航菜单项 hover 时 group-hover:text-primary 被 style.js 以 !important 强制设为主色蓝,覆盖了针对首页的 lg:group-hover:text-white,导致蓝底蓝字、文字几乎不可见。 将 hover 颜色按断点拆分: - 移动端:保持主色蓝(白底) - 桌面端首页:使用白色(蓝底) - 桌面端非首页:使用主色蓝(白底) * fix(starter): 补充 sticky 导航子菜单按钮 hover 为主色与普通菜单项一致 sticky(下滑后白底)状态下,含子菜单的按钮缺少与 li > a:hover 对称的 li > button:hover 变蓝规则,导致首页该按钮 hover 仍走 lg:group-hover:text-white 显示白色,白底白字不可见。补充亮色与暗色两条 button:hover 规则,使其与普通菜单项一致变为主色蓝。 --------- Co-authored-by: tangly1024 <mail@tangly1024.com>
…rg#4494) Co-authored-by: tangly1024 <mail@tangly1024.com>
… for new Notion file CDN (file.notion.com) (notionnext-org#4499) * Enhance mapImage.js for new Notion CDN links Add support for new Notion CDN direct links and restore attachment format. * Improve signed URL management for Notion file blocks Enhance handling of signed URLs for Notion file blocks, including new CDN direct links and improved expiration checks. * Add function to convert Notion file CDN URLs * Add tests for convertFileCdnUrl function * Refactor FILE_BLOCK_TYPES and update comments Updated FILE_BLOCK_TYPES to exclude 'image' and adjusted comments for clarity regarding new API behavior. * Update image URL conversion logic for new CDN Refactor image URL handling to convert new CDN signed URLs to attachment format using existing conversion logic. --------- Co-authored-by: tangly1024 <mail@tangly1024.com>
…#4503) Bumps the dev-dependencies group with 6 updates: | Package | From | To | | --- | --- | --- | | [@ai-sdk/google](https://github.com/vercel/ai/tree/HEAD/packages/google) | `4.0.57` | `4.0.63` | | [@ai-sdk/vue](https://github.com/vercel/ai/tree/HEAD/packages/vue) | `4.0.84` | `4.0.92` | | [@testing-library/user-event](https://github.com/testing-library/user-event) | `14.6.6` | `14.6.7` | | [ai](https://github.com/vercel/ai/tree/HEAD/packages/ai) | `7.0.84` | `7.0.92` | | [postcss](https://github.com/postcss/postcss) | `8.5.26` | `8.5.28` | | [zod](https://github.com/colinhacks/zod) | `4.5.2` | `4.5.4` | Updates `@ai-sdk/google` from 4.0.57 to 4.0.63 - [Release notes](https://github.com/vercel/ai/releases) - [Changelog](https://github.com/vercel/ai/blob/main/packages/google/CHANGELOG.md) - [Commits](https://github.com/vercel/ai/commits/@ai-sdk/google@4.0.63/packages/google) Updates `@ai-sdk/vue` from 4.0.84 to 4.0.92 - [Release notes](https://github.com/vercel/ai/releases) - [Changelog](https://github.com/vercel/ai/blob/main/packages/vue/CHANGELOG.md) - [Commits](https://github.com/vercel/ai/commits/@ai-sdk/vue@4.0.92/packages/vue) Updates `@testing-library/user-event` from 14.6.6 to 14.6.7 - [Release notes](https://github.com/testing-library/user-event/releases) - [Changelog](https://github.com/testing-library/user-event/blob/main/CHANGELOG.md) - [Commits](testing-library/user-event@v14.6.6...v14.6.7) Updates `ai` from 7.0.84 to 7.0.92 - [Release notes](https://github.com/vercel/ai/releases) - [Changelog](https://github.com/vercel/ai/blob/main/packages/ai/CHANGELOG.md) - [Commits](https://github.com/vercel/ai/commits/ai@7.0.92/packages/ai) Updates `postcss` from 8.5.26 to 8.5.28 - [Release notes](https://github.com/postcss/postcss/releases) - [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md) - [Commits](postcss/postcss@8.5.26...8.5.28) Updates `zod` from 4.5.2 to 4.5.4 - [Release notes](https://github.com/colinhacks/zod/releases) - [Commits](colinhacks/zod@v4.5.2...v4.5.4) --- updated-dependencies: - dependency-name: "@ai-sdk/google" dependency-version: 4.0.63 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dev-dependencies - dependency-name: "@ai-sdk/vue" dependency-version: 4.0.92 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dev-dependencies - dependency-name: "@testing-library/user-event" dependency-version: 14.6.7 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dev-dependencies - dependency-name: ai dependency-version: 7.0.92 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dev-dependencies - dependency-name: postcss dependency-version: 8.5.28 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dev-dependencies - dependency-name: zod dependency-version: 4.5.4 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dev-dependencies ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [p-limit](https://github.com/sindresorhus/p-limit) from 7.3.1 to 7.3.2. - [Release notes](https://github.com/sindresorhus/p-limit/releases) - [Commits](sindresorhus/p-limit@v7.3.1...v7.3.2) --- updated-dependencies: - dependency-name: p-limit dependency-version: 7.3.2 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: tangly1024 <mail@tangly1024.com>
…-org#4505) Bumps [@supabase/supabase-js](https://github.com/supabase/supabase-js/tree/HEAD/packages/core/supabase-js) from 2.112.4 to 2.115.0. - [Release notes](https://github.com/supabase/supabase-js/releases) - [Changelog](https://github.com/supabase/supabase-js/blob/master/packages/core/supabase-js/CHANGELOG.md) - [Commits](https://github.com/supabase/supabase-js/commits/v2.115.0/packages/core/supabase-js) --- updated-dependencies: - dependency-name: "@supabase/supabase-js" dependency-version: 2.115.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: tangly1024 <mail@tangly1024.com>
Bumps [next](https://github.com/vercel/next.js) from 15.5.24 to 15.5.25. - [Release notes](https://github.com/vercel/next.js/releases) - [Commits](vercel/next.js@v15.5.24...v15.5.25) --- updated-dependencies: - dependency-name: next dependency-version: 15.5.25 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: tangly1024 <mail@tangly1024.com>
Resolve conflicts in favor of upstream Notion data adapters (fixes public API shape changes that broke content fetch on gaoran.cc). Preserve default THEME=typography and site favicon.
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 868e7a8d6f
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| if (hasProperty(properties, 'Status', 'select')) { | ||
| pageProperties.Status = { select: { name: status } } | ||
| } |
There was a problem hiding this comment.
Require a usable Status field before enabling approval
When NOTION_COMMENT_REQUIRE_APPROVAL=true but the database omits Status, uses Notion's status type, or otherwise does not define it as a select, this branch silently skips persisting Pending while the response still tells the client the comment is awaiting approval. Subsequent GETs treat an empty status as public via isPublicComment, so the comment appears immediately and bypasses the requested moderation; fail closed or reject the configuration when approval is enabled without a writable status field.
Useful? React with 👍 / 👎.
Summary
Context
线上 https://gaoran.cc/ 首页报错:无法获取 Notion 数据(`NOTION_PAGE_ID=c8311ae3d787463ba95d6a48ec4669af`)。该库可公开读取且有约 45 篇 Published,问题在旧版 4.9.3 解析。
Test plan