Implemented foundation#
The Update Manager models catalogs, compares versions/channels, validates compatibility and stages packages. These components are not proven to be wired into web startup or an automatic update UI.
Catalog contracts#
The outbound base is https://yaadmin.io/wp-json/yaadmin/ with API version v1. Client-built paths are:
/v1/updates/catalog/server/latest?channel=<channel>¤t=<version>
/v1/updates/catalog/modules/<target_id>/latest?channel=<channel>¤t=<version>These are client contracts, not a claim that the website serves those endpoints. Catalog fields include kind,target_id,version,channel,package_url,published_at and optional release_notes. update_available=false yields no update.
Versions and channels#
Channels are stable, beta and developer. Update version comparison supports SemVer-style prerelease/build data; compatibility includes min_server_version,module_sdk_major and optional max_server_version. Module SDK nonempty version strings are a different contract.
Package validation and staging#
.yaupdate ZIP packages contain update.json and payload.zip, with signature.ed25519 when signed. Required manifest fields are schema_version,package_id,kind,target_id,version,channel,published_at,payload,compatibility and signing; release_notes is optional.
Staging rejects unsafe paths/symlinks, checks payload SHA-256/size and verifies canonical manifest signatures through injected trusted Ed25519 keys. Unsigned packages require developer channel plus explicit permission to allow them.
Current limitation#
No general package downloader, scheduled checking, native provider network transport or production update UI is verified. The ordinary module upload route does not accept .yaupdate as a module package.