Skip to content

Release Spacious v1.10.0 - #153

Merged
iamprazol merged 20 commits into
masterfrom
release/v1.10.0
Sep 29, 2026
Merged

iamprazol merged 20 commits into
masterfrom
release/v1.10.0

Conversation

@deepench

Copy link
Copy Markdown
Contributor

Release Spacious v1.10.0.

Changelog

== Version 1.10.0 - 2026-09-28 ==

  • Dev - Missing capability check on demo-import migration trigger.
  • Dev - Unbounded get_users() full-table scan in theme-switch cleanup.
  • Dev - Meta box save routine reads $_POST without isset() checks or a value whitelist.
  • Dev - Deprecation notice on every page load from the IE 8 html5shiv script under WordPress 6.9+.
  • Dev - JavaScript errors from navigation.js on the Widgets screen and other pages without the theme header.
  • Fix - Submenu caret icon never flips direction when toggled.
  • Fix - Search block input renders taller than its Search button.
  • Fix - Slider scripts loaded on the homepage even when the slider setting was off.
  • Fix - Header cart count and total now update right after an AJAX add to cart, without a page reload.
  • Fix - Block editor typography (fonts, sizes, and colors) didn't reflect the Customizer's configured settings.
  • Fix - Block borders set in the editor now also show on the front end. Borders that were set but hidden will now appear.

deepench and others added 18 commits September 25, 2026 05:15
…ript allowlist key

pnpm 9 doesn't gate install/postinstall scripts at all, so downgrading to it
silently dropped the build-script allowlist protection pnpm 11 had (verified
directly: pnpm 11 blocks an unlisted package's postinstall by default, pnpm 9
runs every package's scripts unconditionally). pnpm 10.34.5 declares the same
Node >=18.12 compatibility as 9, so it still fixes the original CI failure,
but keeps the same default-deny behavior as 11.

Also switched pnpm-workspace.yaml from the pnpm 11-only "allowBuilds" map
(confirmed not recognized by pnpm 10) to the documented, version-portable
"onlyBuiltDependencies" array, which works correctly on both.
#138)

* Fix - Responsive menu shows enabled but never applies until saved once

* Fix - Copilot review findings on the responsive-menu e2e suite

Scopes the changeset cleanup to the suite's own admin user, represents an
absent theme_mods row instead of throwing on a fresh install, restricts menu
reuse to the primary location, maps inc/functions.php into the header area,
fixes the mobile-menu-toggle spec to open the submenu's own caret toggle
before asserting its content is visible, and publishes reverted Customizer
values in cleanup (not just setting them) so Playground runs actually revert.

Also fixes: a missing ignoreHTTPSErrors option that blocked the suite from
ever running against a local DDEV site, and several specs calling
setControl() on a page that had already navigated away from the Customizer.

* Fix - auth.setup guards against a cold-boot fill race on Playground

Waits for both login fields to be visible and confirms the password value
actually landed before submitting, instead of filling immediately after
goto(). A cold Playground boot can serve wp-login.php before it has fully
hydrated, silently losing a fill() with no error.
* Fix - Version theme scripts and styles with the theme version

The main stylesheet and most theme scripts were enqueued without a
version, so WordPress appended its own core version and browsers or CDNs
kept serving old copies after a theme update until WordPress itself was
updated. Pass SPACIOUS_THEME_VERSION, as the Customizer and admin assets
already do. Handles, dependencies and load order are unchanged.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Fix - Leave a child theme's stylesheet on its default version

get_stylesheet_uri() is the child theme's own style.css when a child
theme is active, so stamping it with the parent's version was wrong.
Keep WordPress' default version there, exactly as before this change,
and use the theme version only for Spacious' own stylesheet.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
The sub-toggle click handler looked for a child matching ".sub-toggle .fa",
but inside the handler `this` already is the .sub-toggle element itself, not
a container of one - so the selector never matched anything and
toggleClass() silently ran on an empty set. The submenu itself opened and
closed correctly (a separate call), only the caret's own direction
(caret-right/caret-down) never updated. Fixed by matching the icon's actual
direct child selector, ".fa".

Verified live in both themes: before the fix, clicking the caret expanded
the submenu but the icon class never changed; after, it flips
fa-caret-right <-> fa-caret-down correctly in both directions.

Also checked and ruled out a previously-suspected duplicate id="site-navigation"
theory: header.php's two spacious_main_nav() call sites are wrapped in
genuinely mutually exclusive conditions (spacious_header_display_type ===
'four' vs !== 'four'), so only one nav ever renders - confirmed with 0
duplicates under both settings, live. Nothing to fix there.
…every page load (WP 6.9+) (#151)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
…dgets screen previews) (#147)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Adds current_user_can( 'edit_theme_options' ) alongside the existing nonce
verification in the demo-import migration trigger, its notice, and its
dismiss handler. The nonce alone only proved the request came from the
current user's own session, not that they were allowed to run the action -
any logged-in user, regardless of role, could force a site-wide theme_mods
and options rewrite using stale legacy data, since the migration functions
are hooked to after_setup_theme, which fires on the front end too.

Verified live: a subscriber-role account, using a nonce genuinely valid for
their own session, is now correctly rejected with "You do not have
permission to perform this action."
)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
* Fix - Header cart count and total stayed stale after AJAX add to cart

The header cart block was rendered once at page load and never registered
as a WooCommerce cart fragment, so it only refreshed on a full reload
while the mini-cart updated. Move the block into a shared function used
by both the initial render and a woocommerce_add_to_cart_fragments
filter. The filter is registered with the default spacious_cart_icon(),
so a child theme overriding it keeps its own markup, and it never
overwrites a fragment already supplied for the same selector.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Update translation template after moving the header cart strings

Regenerated with the makepot options from Gruntfile.js. Only the creation
date and source line references change.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Fix - Update the header cart on the Cart and Checkout pages

The WooCommerce cart widget, which normally loads cart fragments, hides
itself on the Cart and Checkout pages, so the header cart never refreshed
there. The Cart and Checkout blocks also change the cart through the Store
API without firing the events cart fragments listen for.

Load cart fragments whenever the header cart icon is on, and when the Cart
or Checkout block's cart store changes its item count or subtotal, trigger
a fragment refresh so the header is re-rendered by spacious_cart_icon_views().

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
* Fix - Block editor ignores Customizer typography and colors

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Fix - Editor post title used the H1 size instead of the front-end title size

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Add - E2E guard: block editor matches the front-end Customizer typography and colors

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Remove - manually added E2E spec; specs come from the verify-fix flow

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
spacious_footer_copyright()'s default text was missing a colon after
"Theme" and carried a trailing period Pro's own fix already dropped -
"Theme Spacious by ThemeGrill. Powered by: WordPress." here vs Pro's
"Theme: Spacious Pro by ThemeGrill. Powered by: WordPress".

Added the colon and removed the trailing period so both editions read
the same way.

Verified live: front end now shows "Theme: Spacious by ThemeGrill.
Powered by: WordPress" with no trailing period. PHPCS unchanged (166
errors / 66 warnings, identical before and after).

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Unresolved moderate issues remain in release metadata, unbounded cleanup queries, typography defaults, cart hooks, and test configuration.

Review effort: Lite
Findings: 3 Medium severity · 1 Low severity

Open (4)
What changed in this PR

Release Spacious v1.10.0 with security, frontend, editor, WooCommerce, build, and E2E updates.

Changes:

  • Hardens admin actions and theme-switch cleanup.
  • Fixes navigation, sliders, cart updates, typography, borders, and search styling.
  • Updates release metadata, translations, pnpm tooling, CI, and E2E coverage.
File Summary
tests/​e2e/​specs/​single-post/​related-posts-toggle.spec.ts Improves Customizer reopening and cleanup.
tests/​e2e/​specs/​single-post/​author-bio-round-trip.spec.ts Improves Customizer cleanup.
tests/​e2e/​specs/​front-page/​slider-activation-toggle.spec.ts Restores slider settings during tests.
tests/​e2e/​specs/​customizer/​site-layout-body-class-round-trip.spec.ts Publishes restored settings.
tests/​e2e/​specs/​customizer/​global-primary-color-round-trip.spec.ts Publishes restored settings.
tests/​e2e/​specs/​blog-layout/​archive-display-type-full-content-vs-excerpt.spec.ts Improves Customizer state handling.
tests/​e2e/​specs/​blog-layout/​archive-display-type-body-class-round-trip.spec.ts Publishes restored settings.
tests/​e2e/​specs/​accessibility/​mobile-menu-toggle.spec.ts Covers submenu caret interaction.
tests/​e2e/​playwright.config.ts Local HTTPS handling is added; certificate ignoring should be scoped to local targets.
tests/​e2e/​global-setup.ts Cleanup is scoped to the test user; early password validation disrupts the authentication failure path.
tests/​e2e/​fixtures/​theme-mods-snapshot.ts Supports absent theme-mod baselines.
tests/​e2e/​fixtures/​content.ts Selects menus assigned to the primary location.
tests/​e2e/​auth.setup.ts Stabilizes login field filling.
style.css Adds styling and release metadata; the source version header must be updated before regeneration.
style-rtl.css Adds RTL-equivalent styling and metadata.
style-editor-block.css Updates block editor selectors.
readme.txt Adds the v1.10.0 changelog.
pnpm-workspace.yaml Updates pnpm build configuration.
pnpm-lock.yaml Refreshes lockfile metadata.
package.json Updates package and pnpm versions.
languages/​spacious.pot Translation entries and project version metadata remain stale.
js/​spacious-custom.js Fixes submenu caret toggling; its QA mapping is missing.
js/​navigation.js Prevents errors when navigation markup is absent.
inc/​spacious-toolkit.php Adds asset versioning.
inc/​header-functions.php Adds cart fragment synchronization; hooks are skipped for child-theme cart renderers.
inc/​functions.php Adds editor typography and color styles; typography defaults are incomplete, and footer translation strings changed without POT updates.
inc/​enqueue-scripts.php Fixes slider loading and asset versioning.
inc/​demo-import-migration.php Adds capability checks.
inc/​admin/​meta-boxes.php Adds POST guards and value validation.
inc/​admin/​class-spacious-theme-review-notice.php Uses ID-only user queries, but the query remains unbounded.
inc/​admin/​class-spacious-tdi-notice.php Uses ID-only user queries, but the query remains unbounded.
assets/​scss/​_theme-style.scss Adds source styling; its version header remains 1.9.12.
.themegrill-qa/​suite.json Updates QA mappings; the custom JavaScript path is not mapped.
.github/​workflows/​pr-build-zip.yml Switches the release build to pnpm.
Files not reviewed (1)
  • pnpm-lock.yaml: Generated file

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.


public function remove_tdi_notice() {
$get_all_users = get_users();
$user_ids = get_users( array( 'fields' => 'ID' ) );
public function review_notice_data_remove() {

$get_all_users = get_users();
$user_ids = get_users( array( 'fields' => 'ID' ) );
Comment thread inc/header-functions.php
Comment on lines +94 to +98
// Registered with the default renderer, so a child theme overriding spacious_cart_icon() keeps its own markup.
add_filter( 'woocommerce_add_to_cart_fragments', 'spacious_cart_icon_fragment' );
add_action( 'wp_enqueue_scripts', 'spacious_cart_icon_scripts' );

endif;
Comment thread languages/spacious.pot Outdated
"Project-Id-Version: Spacious 1.9.12\n"
"Report-Msgid-Bugs-To: themegrill@gmail.com\n"
"POT-Creation-Date: 2026-09-18 11:47:31+00:00\n"
"POT-Creation-Date: 2026-09-28 06:56:32+00:00\n"
@deepench

Copy link
Copy Markdown
Contributor Author

Testable ZIP for this release (built from this branch, grunt compress):

https://github.com/themegrill/spacious/raw/release-zip-v1.10.0/spacious-v1.10.0.zip

get_option( $themename ) returns false whenever the option doesn't exist
(fresh installs), and the subsequent unset() calls on that false value log
PHP 8.1+ "Automatic conversion of false to array" deprecation notices on
every after_setup_theme bootstrap until the migration flag is set.

Ported from spacious-pro release/v2.8.0 (commit 7601809f), which fixed the
same pattern against its own hardcoded 'spacious' option lookup.

Verified live: reproduced 2 deprecation notices at migration.php:63 with
the old spacious option absent, confirmed 0 after, via a real front-end
request with Playwright against the Spacious theme.
# Conflicts:
#	languages/spacious.pot
#	style-rtl.css
#	style.css
@iamprazol
iamprazol merged commit 5a5afcd into master Sep 29, 2026
2 checks passed
@iamprazol
iamprazol deleted the release/v1.10.0 branch September 29, 2026 10:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants