# sonor-setup Changelog

## 7.1.2

- **The codemod moves `@sonordev/site-kit/engage` imports.** Engage was
  retired in Sonor and split in site-kit: chat imports (`ChatWidget`,
  `ChatConfig`, ...) move to `@sonordev/site-kit/chat`, popup types to
  `@sonordev/site-kit/website/popups` under their new names (`EngageElement`
  becomes `SitePopup`, kept as the local name so nothing else in the file
  changes). It flags `EngageWidget`, which `SiteKitLayout` already mounts.

- **Schema saves say what Sonor did.** `setup` and `migrate` say when Sonor
  saved a schema as a draft because it has template placeholders (with what
  to fill in), or kept the copy it already had, and report a failed save as
  failed, including an answer that says it didn't save. They used to print
  a check mark either way.

- **`migrate` keeps a page's schema until Sonor has it.** It replaces a
  page's JSON-LD with `ManagedSchema` only once Sonor has saved a copy; a
  refused key or a server error used to leave the page with no schema at
  all. JSON-LD built at render time stays as it is, and JSON-LD in a
  template literal that ends in a string value is read now (it never was).

- **`sync --schemas` lists, and stops failing.** It lists where each page
  gets its schema and points hand-written JSON-LD at `migrate`. It used to
  send that list to an endpoint that takes one schema at a time, so the
  step always failed.

- **The codemod puts the proxy where Next reads it.** Next only runs
  `proxy.ts` from the directory that holds the app: the project root, or
  `src/` when the app is `src/app`. A proxy anywhere else is ignored without
  a warning and the build still passes, so the site quietly sends no
  security headers and runs no managed redirects. The `next-16-proxy`
  transform (and `sonor-setup next16`) used to rename `middleware.ts` in
  place, which left `proxy.ts` at the root of `src/app` sites. It now writes
  `src/proxy.ts` there and re-points the file's relative imports, and it
  moves a root `proxy.ts` an earlier run left behind. When there's a proxy
  in both places, it changes neither and says which one Next runs.

- **`doctor` checks where the proxy is.** It warns when a proxy or
  middleware file sits at the root of a `src/app` site (or in `src/` when
  the app is at the root) and says where it goes, instead of calling the
  file present. `geo` no longer credits the discovery header to a proxy Next
  never runs. A comment that mentions `runtime` no longer reads as setting
  one.

- **Repeated reads collapse.** Renaming an old fallback such as
  `process.env.SONOR_API_KEY || process.env.UPTRADE_API_KEY` now gives
  `process.env.SONOR_API_KEY`, not the same read twice, and rerunning the
  codemod cleans up files an earlier version left that way. In an env file
  it no longer renames `UPTRADE_API_KEY` onto a `SONOR_API_KEY` that's
  already set (the later line would win); it flags the old line to delete.

- **Nothing extra is left in the project.** The codemod, `init` and
  `migrate` keep the originals of the files they overwrite in a folder under
  your OS temp directory, not as `.bak` or `.backup` files beside them, and
  the codemod prints where (`--no-backup` skips them). A `.env.local.bak`
  also slipped past the `.env*.local` ignore rule older Next.js templates
  use. The codemod never reads or edits `.env.example` (or `.env.sample`,
  `.env.template`): `.env.local` is the one env file.

- **The live-updates route fits a site with articles.** `scaffold` writes
  `createRevalidateRoute({ publicationBasePath: '/insights' })` with the
  site's own path, read from the app directory: a dynamic page that renders
  site-kit articles, or a `[slug]` route under a folder named blog,
  insights, news, resources or articles. When more than one folder looks
  like the publication, it writes the one-line route and lists them.
  `doctor` asks for the same form, warns when a site with articles uses the
  one-line route, and counts a route built on agency-site-kit's handler as
  kit-built rather than hand-rolled.

- `scaffold` writes the proxy beside the app directory too, and won't write
  one next to a middleware file or a proxy Next ignores.

## 7.1.1

- Messages say "Sonor" where they said "Portal", the product's old name: "Uploading FAQs to Sonor", "Get your API key from Sonor → Project Settings → API Keys", and the rest. No behavior changes.
- `sonor-setup manifest` ships site-kit 7.1.2's manifest.

## 7.1.0

- `doctor` checks for the live-updates route (`app/api/seo-revalidate`).
  Without it, content edits in Sonor wait for the site's cache to expire
  instead of going live in seconds.
- `scaffold` writes that route (one line, `export { POST } from
  '@sonordev/site-kit/revalidate'`) unless the site already has one.

## 7.0.0

First release as its own package. Until now the CLI shipped inside
`@sonordev/site-kit` (as its `sonor-setup` bin), where it was 3 MB of every
site's install and needed a site-kit release for every setup-only fix.

- `npx sonor-setup …` works as before; npx fetches this package.
- A site whose package.json scripts run `sonor-setup` needs it as a dev
  dependency; `sonor-setup codemod --write` adds it.
- `--json` envelopes report `siteKitVersion` (the site's installed site-kit,
  `none` when absent) and, new, `setupVersion` (this CLI).
- `manifest` reads the site's installed site-kit manifest, falling back to
  the copy shipped here.
- New codemod transform `site-kit-7`: runtime imports from the site-kit root
  (types-only since 7.0) move to their module's entry, deprecated paths move
  to their 7.x homes, and a site whose scripts run `sonor-setup` gets it as a
  dev dependency. See site-kit's docs/MIGRATING-TO-7.md.
- New codemod transform `next-16-proxy`: `middleware.ts` → `proxy.ts`, a
  named `middleware` export → `proxy` (or the default export when the file
  has its own `proxy`), and site-kit's `./middleware`/`createMiddleware` →
  `./proxy`/`createProxy`. Deterministic and offline; `next16` uses it
  instead of shelling out to `@next/codemod@canary`. A file that sets
  `runtime` is flagged, never moved, and nothing moves onto an existing
  `proxy.ts`. The engine can now rename files (`renamedTo` in `--json`).
- New command `mcp`: writes a site's MCP wiring with site-kit's built-in
  tools (the server file, the endpoint with tool-call reporting, the server
  card at both well-known paths, and on Netlify the rate-limited relay plus
  a generated `MCP_TRANSPORT_SECRET`). Never overwrites a file without
  `--force`; `--inquiry-form`, `--booking`, `--offerings`, `--articles`,
  `--netlify`/`--no-netlify`, `--dry-run`. On a site that runs its own MCP
  server it writes nothing and lists what's opt-in; `--force`
  replaces it. An existing route's extension decides route.ts vs route.js.
- One `.env` loader with site-kit (Next.js precedence), on Node's
  `util.parseEnv`; `dotenv` is gone. Node 20.19+.
- The codemod no longer scans `.claude/` (agent session worktrees).
