docs
    sonor-setup CLI: Changelog
    v7.1.2.md

    sonor-setup Changelog

    7.1.2

    • The codemod moves @sonordev/site-kit/engage imports. Engage was retired in Sonor and split in site-kit: chat imports (ChatWidget, ChatConfig, ...) move to @sonordev/site-kit/chat, popup types to @sonordev/site-kit/website/popups under their new names (EngageElement becomes SitePopup, kept as the local name so nothing else in the file changes). It flags EngageWidget, which SiteKitLayout already mounts.

    • Schema saves say what Sonor did. setup and migrate say when Sonor saved a schema as a draft because it has template placeholders (with what to fill in), or kept the copy it already had, and report a failed save as failed, including an answer that says it didn't save. They used to print a check mark either way.

    • migrate keeps a page's schema until Sonor has it. It replaces a page's JSON-LD with ManagedSchema only once Sonor has saved a copy; a refused key or a server error used to leave the page with no schema at all. JSON-LD built at render time stays as it is, and JSON-LD in a template literal that ends in a string value is read now (it never was).

    • sync --schemas lists, and stops failing. It lists where each page gets its schema and points hand-written JSON-LD at migrate. It used to send that list to an endpoint that takes one schema at a time, so the step always failed.

    • The codemod puts the proxy where Next reads it. Next only runs proxy.ts from the directory that holds the app: the project root, or src/ when the app is src/app. A proxy anywhere else is ignored without a warning and the build still passes, so the site quietly sends no security headers and runs no managed redirects. The next-16-proxy transform (and sonor-setup next16) used to rename middleware.ts in place, which left proxy.ts at the root of src/app sites. It now writes src/proxy.ts there and re-points the file's relative imports, and it moves a root proxy.ts an earlier run left behind. When there's a proxy in both places, it changes neither and says which one Next runs.

    • doctor checks where the proxy is. It warns when a proxy or middleware file sits at the root of a src/app site (or in src/ when the app is at the root) and says where it goes, instead of calling the file present. geo no longer credits the discovery header to a proxy Next never runs. A comment that mentions runtime no longer reads as setting one.

    • Repeated reads collapse. Renaming an old fallback such as process.env.SONOR_API_KEY || process.env.UPTRADE_API_KEY now gives process.env.SONOR_API_KEY, not the same read twice, and rerunning the codemod cleans up files an earlier version left that way. In an env file it no longer renames UPTRADE_API_KEY onto a SONOR_API_KEY that's already set (the later line would win); it flags the old line to delete.

    • Nothing extra is left in the project. The codemod, init and migrate keep the originals of the files they overwrite in a folder under your OS temp directory, not as .bak or .backup files beside them, and the codemod prints where (--no-backup skips them). A .env.local.bak also slipped past the .env*.local ignore rule older Next.js templates use. The codemod never reads or edits .env.example (or .env.sample, .env.template): .env.local is the one env file.

    • The live-updates route fits a site with articles. scaffold writes createRevalidateRoute({ publicationBasePath: '/insights' }) with the site's own path, read from the app directory: a dynamic page that renders site-kit articles, or a [slug] route under a folder named blog, insights, news, resources or articles. When more than one folder looks like the publication, it writes the one-line route and lists them. doctor asks for the same form, warns when a site with articles uses the one-line route, and counts a route built on agency-site-kit's handler as kit-built rather than hand-rolled.

    • scaffold writes the proxy beside the app directory too, and won't write one next to a middleware file or a proxy Next ignores.

    7.1.1

    • Messages say "Sonor" where they said "Portal", the product's old name: "Uploading FAQs to Sonor", "Get your API key from Sonor → Project Settings → API Keys", and the rest. No behavior changes.
    • sonor-setup manifest ships site-kit 7.1.2's manifest.

    7.1.0

    • doctor checks for the live-updates route (app/api/seo-revalidate). Without it, content edits in Sonor wait for the site's cache to expire instead of going live in seconds.
    • scaffold writes that route (one line, export { POST } from '@sonordev/site-kit/revalidate') unless the site already has one.

    7.0.0

    First release as its own package. Until now the CLI shipped inside @sonordev/site-kit (as its sonor-setup bin), where it was 3 MB of every site's install and needed a site-kit release for every setup-only fix.

    • npx sonor-setup … works as before; npx fetches this package.
    • A site whose package.json scripts run sonor-setup needs it as a dev dependency; sonor-setup codemod --write adds it.
    • --json envelopes report siteKitVersion (the site's installed site-kit, none when absent) and, new, setupVersion (this CLI).
    • manifest reads the site's installed site-kit manifest, falling back to the copy shipped here.
    • New codemod transform site-kit-7: runtime imports from the site-kit root (types-only since 7.0) move to their module's entry, deprecated paths move to their 7.x homes, and a site whose scripts run sonor-setup gets it as a dev dependency. See site-kit's docs/MIGRATING-TO-7.md.
    • New codemod transform next-16-proxy: middleware.ts → proxy.ts, a named middleware export → proxy (or the default export when the file has its own proxy), and site-kit's ./middleware/createMiddleware → ./proxy/createProxy. Deterministic and offline; next16 uses it instead of shelling out to @next/codemod@canary. A file that sets runtime is flagged, never moved, and nothing moves onto an existing proxy.ts. The engine can now rename files (renamedTo in --json).
    • New command mcp: writes a site's MCP wiring with site-kit's built-in tools (the server file, the endpoint with tool-call reporting, the server card at both well-known paths, and on Netlify the rate-limited relay plus a generated MCP_TRANSPORT_SECRET). Never overwrites a file without --force; --inquiry-form, --booking, --offerings, --articles, --netlify/--no-netlify, --dry-run. On a site that runs its own MCP server it writes nothing and lists what's opt-in; --force replaces it. An existing route's extension decides route.ts vs route.js.
    • One .env loader with site-kit (Next.js precedence), on Node's util.parseEnv; dotenv is gone. Node 20.19+.
    • The codemod no longer scans .claude/ (agent session worktrees).