Skip to content

ENG3-2064: Release 2.10.7 - #1408

Merged
cssjoe merged 7 commits into
masterfrom
ENG3-2064-release-2.10.7
Oct 1, 2026
Merged

cssjoe merged 7 commits into
masterfrom
ENG3-2064-release-2.10.7

Conversation

@cssjoe

@cssjoe cssjoe commented Oct 1, 2026

Copy link
Copy Markdown
Member

https://imh-internal.atlassian.net/browse/ENG3-2064

Summary

  • Sync secops/master (5df55a68) into public master for the 2.10.7 patch release. The head is a fast-forward of public master (c3ca682c), so this PR carries exactly the commits merged on secops since 2.10.6, including the reviewed and accepted release PR (BoldGrid/w3-total-cache-secops#52).
  • Bump Version, W3TC_VERSION, and the readme Stable tag to 2.10.7; replace @since X.X.X placeholders; regenerate languages/w3-total-cache.pot.
  • Add matching 2.10.7 changelog blocks to readme.txt and changelog.txt, plus the readme Upgrade Notice.
  • Browser Cache: constrain unquoted URL rewriting when removing query strings from static resources.
  • Release tooling: bin/update-since-versions.sh restricts replacement to *.php / *.js (GNU grep only honors --include as a filter when it precedes --exclude), and bin/make-pot.sh pins --slug=w3-total-cache so the POT header does not depend on the checkout directory name.

Changelog (2.10.7)

  • Feature: Minify: Cache selected external scripts locally for auto minify
  • Feature: Page Cache: Add a one-pass mode for sitemap cache preload
  • Enhancement: Developers: Add a generated reference of supported actions and filters
  • Fix: Browser Cache: Constrain unquoted URL rewriting when removing query strings from static resources
  • Fix: Page Cache: Remove the expired role-cookie compatibility path and skip caching for rejected roles
  • Fix: Page Cache: Avoid Options API calls before WordPress has loaded them during early bootstrap
  • Fix: Object Cache: Persist cache invalidation from wp-admin when admin object caching is disabled
  • Fix: CDN: Preserve custom attachment directories when pushing media
  • Fix: Google PageSpeed: Renew expired access tokens without discarding authorization
  • Fix: Licensing: Show the activation-limit notice for licenses that have reached their limit
  • Fix: Settings: Persist Purge via WP-Cron schedule settings
  • Fix: Settings: Skip unchanged w3tc_state option writes
  • Update: Remove leftover newsletter signup code
  • Update: Build: Omit development-only files from the release ZIP

Test plan

  • git merge-base --is-ancestor origin/master secops/master passes; diff vs master is the expected 29 files with no CI/config-only changes
  • bin/update-changelog.sh check 2.10.7 — readme.txt and changelog.txt match (14 bullets)
  • No @since X.X.X / 'X.X.X' placeholders remain in shipped PHP/JS
  • PHPUnit full suite on the release branch: 667 tests, 2722 assertions, 0 failures
  • Code review and acceptance completed on BoldGrid/w3-total-cache-secops#52 (upgrade from 2.10.6, General Settings save, Empty All Caches, admin smoke on single and multisite)
  • CI green on this PR
  • After merge: tag 2.10.7 and publish via the Travis / wordpress-tag-sync build

jacobd91 and others added 7 commits September 11, 2026 14:43
Exclude quote characters from the query/fragment capture in the
no-quote output-buffer regex so URL-like text inside other attribute
values is not rewritten. Add ob_callback regression tests.

Co-authored-by: Cursor <cursoragent@cursor.com>
Exclude quote characters from the query/fragment capture in the
no-quote output-buffer regex, so URL-like text inside other attribute
values is not rewritten. Add ob_callback regression tests.
* ENG3-2064: Bump version to 2.10.7

* ENG3-2064: Limit @SInCE placeholder replacement to PHP and JS files

GNU grep includes a file when no --include/--exclude matches unless the first
such option is --include, so the trailing --include patterns did not restrict
the file list and bin/release.sh and Markdown docs were rewritten.

* ENG3-2064: Replace @SInCE placeholders with 2.10.7

* ENG3-2064: Pin the POT slug so make-pot does not depend on the checkout directory name

* ENG3-2064: Regenerate POT for 2.10.7

* ENG3-2064: Add 2.10.7 changelog entries and upgrade notice
@cssjoe
cssjoe requested a review from a team October 1, 2026 13:46
@cssjoe cssjoe self-assigned this Oct 1, 2026
@cssjoe
cssjoe requested a review from jacobd91 October 1, 2026 13:46
@cssjoe cssjoe added this to the 2.10.7 milestone Oct 1, 2026

@jacobd91 jacobd91 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code review

Reviewed 5df55a68 against master (c3ca682c). The head is a fast-forward of master, so the diff is exactly the 2.10.7 release commits.

  • The only runtime logic change versus master is the Browser Cache unquoted-attribute query class in BrowserCache_Plugin.php, which now stops at ' and ". Verified it no longer consumes a closing quote, and that real quoted and unquoted src attributes still have their query strings removed. The new W3tc_Browsercache_Ob_Callback_Test passes (3 tests, 5 assertions).
  • Version bumps (Version, W3TC_VERSION, Stable tag), @since placeholders, POT header, and both changelog blocks are consistent. bin/update-changelog.sh check 2.10.7 reports readme.txt and changelog.txt match (14 bullets). No @since X.X.X placeholders remain in shipped PHP/JS.
  • bin/update-since-versions.sh and bin/make-pot.sh changes look correct.
  • Automated review (Bugbot) found no bugs; security review found no issues in the changed code.

One low-severity, non-blocking note: a URL-like string inside a quoted attribute that is terminated by a space before the closing quote (e.g. cite=" src=/x.css?v=1 ") can still match the unquoted-attribute pattern. It does not break the attribute boundary. Worth a follow-up test case, not a release blocker.

Acceptance

Checked out the PR head on a local single-site install:

  • Plugin reports version 2.10.7.
  • Authenticated admin smoke across the W3TC settings screens (dashboard, general, page cache, minify, database cache, object cache, browser cache, cache groups, CDN, user experience, extensions, PageSpeed, support, install, setup guide, about, and extension views): 22/22 HTTP 200, no fatals.
  • Page Cache screen shows the new "Preload the sitemap once" option.
  • General Settings save succeeded ("Plugin configuration successfully updated.") with cache enablement and engines unchanged.
  • Empty All Caches succeeded (flush_all).
  • Frontend and /wp-json/ return HTTP 200.

CI is green on this head. Approving.

@cssjoe
cssjoe merged commit b9385f7 into master Oct 1, 2026
5 checks passed
@cssjoe
cssjoe deleted the ENG3-2064-release-2.10.7 branch October 1, 2026 16:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants