NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #543 by repository stars
Last release 3 days ago
05 Oct 2026
Ships on a steady schedule
a new release about every 8 days
Nearly every release is documented
notes for 58 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
6 months old
210 releases · first in 2026
One column per month.
Nothing published for this version
Nothing published for this version
本版本将已交付的 v1.0.63-beta.3 晋级正式版,汇总本版本线三个 beta 的变化,并纳入下方列出的 beta 后变更。
本版本将已交付的 v1.0.63-beta.3 晋级正式版,汇总本版本线三个 beta 的变化,并纳入下方列出的 beta 后变更。
agentUuid / userId 身份契约。草稿配置与发布分别执行,事件连接状态区分 IPC、Agent 初始化和实际传输就绪。auth status --readonly 提供不联网、不刷新、不写凭据的本地状态快照。--wait / --wait-timeout,超时保留 pending 与最后观察状态,事件与轮询共用截止时间。--type,可见范围使用 --user-ids,保留历史参数兼容;支持可选创建提示词、发布本地员工前按需初始化提示词,以及草稿文本的空值校验。更新 OA TableField 二维数组示例、Devapp/Devdoc 流程及文档列表路由。SG_READ_ONLY 并实际启动可执行的 Darwin 产物。contract review benefit|create|analysis|result 命令并标记不可用;保留历史参数入口,但以 command_retired 拒绝执行,不再调用旧 MCP。v1.0.63-beta.3Add dws aicard explain <name>, lint, and preview. The embedded DingTalk A2UI protocol supports native offline lookup and structural validation without Python. Preview validates a complete new-card file and sends it to the current user's direct chat; dry-run does not send. Include the DWS authoring Skill and report request acceptance separately from client-rendering evidence.
Drive & Wiki set-share-scope — add dws drive permission set-share-scope and dws wiki permission set-share-scope for managing node-level and workspace-level share visibility (PRIVATE / ORGANIZATION / PUBLIC) with partial-update semantics, role control, partner inclusion, organization search/recommend toggles, password protection and expiration (drive node only).
OA 审批模板创建与更新命令 — 新增 dws oa approval template create(oa/create_process_template)与 dws oa approval template update(oa/update_process_template),均为企业钉钉管理员能力。两者支持逐项参数模式(create 必填 --name、--schema-content;update 必填 --process-code、--name、--schema-content、--process-config),也支持 --from-document 传入完整 JSON 文档的绝对路径整体配置,两种模式互斥;--schema-content、--process-config 等对象参数以 JSON 字符串发送给 MCP,--plugin-configs、--visible-range、--manager-user-ids 以数组发送,均支持直接 JSON、@文件 与 - 标准输入。CLI 侧做本地校验:schemaContent 控件 props.id 唯一性检查(递归进 children 嵌套控件)与 processConfig 结构校验,并解析 MCP 返回的 810001(同名模板冲突)/810002(模板数量超限)拒绝码为失败输出而非静默重试;--dry-run 仅做本地校验并展示请求参数(executed=false),成功统一由 data.processCode 返回模板编码。构造 processConfig 时若未显式指定审批人类型,审批节点默认使用部门主管(target_management)而非直属主管。Skill 文档:新增 oa-template-write.md(从 oa.md 拆分模板写入路由,渐进披露)与连接器审批人规则 target_connect_approval.md,并补充 50+ 个控件 schema、流程节点、选人规则子文档;oa.md 增加模板管理路由条目、process-nodes.md 增加连接器审批人条目、SKILL.md 引用 oa-template-write.md。验证状态:变更代码含完整单测(含 schema_oa_template_contract_test.go Schema 契约测试)与 mono-multi-coverage.yaml 的 oa-template-write 注册;模板名称是否可用、数量是否超限由创建 MCP 校验,dry-run 不能证明名称可用,建议创建/更新后再用 template detail 核对实际状态。
AI 表格访问密钥 — 新增 SQL Sheet API Key 的创建、查询和撤销命令,以及对应的 Agent 使用说明;完整凭据仅创建时返回,创建结果未知时先查询状态。
make setup-hooks 显式启用,提交前仅检查暂存区格式与空白,不修改工作区。固定 AI 卡片协议 JSON 的 Git 检出换行为 LF,修复 Windows 自动转换 CRLF 后协议哈希校验失败、卡片查询和校验命令无法使用的问题。
修复 Windows 鉴权文件替换遇到短暂文件占用时的失败,保留旧文件并对受限错误执行有界重试。
修复 Linux Skill 安装期间的目录身份校验,固定目录句柄并在结束后释放。
修复产品命令根名称与产品 ID 不一致时的 Schema 缓存定位。
AI 听记整包导出支持服务端明确成功的空摘要,仍保留分析等待器的严格判断。
钉钉招聘创建职位时正确处理校园招聘默认值,并保留 Connector 返回的业务错误信息。
--password to the timing/perf report sensitive-flag allowlist so SanitizeCommand redacts it in both --password <value> and --password=<value> forms. This also fixes a pre-existing plaintext leak where dws drive publish set --password … wrote the raw secret into the DWS_PERF_REPORT argv record. The drive permission set-share-scope --dry-run preview now masks the password value as *** while still emitting requirePassword; real calls keep sending the correct secret and no business RPC is issued during preview.Nothing published for this version
darwin/amd64 release asset fails to launch ( #1441 ) — the CGO cross-link defaulted the x86_64 deployment target to macOS 10.13, so ld64 emitted __DAT
__DATA_CONST without SG_READ_ONLY and current dyld aborts the binary before main(). Release builds now pin MACOSX_DEPLOYMENT_TARGET=11.0 (matching the arm64 floor), and the signed-artifact verification statically checks the SG_READ_ONLY flag and launches every Darwin asset it can execute before publication.v1.0.63-beta.3 Pre-release
Pre-release
Compare
Standardize dingtalk-tag manage create/list/save-draft on --type and set-visibility on --user-ids , keeping help and Skill guidance focused on canonic
dingtalk-tag manage create/list/save-draft on --type and set-visibility on --user-ids, keeping help and Skill guidance focused on canonical flags while preserving existing script compatibility and MCP field mappings.set-visibility in both mono and multi Skill references, including ALL/PARTIAL scopes, full replacement semantics, omitted-list clearing, the userId-to-staffIds mapping, and confirmation requirements.Accept optional --prompt when creating digital employees. Save custom prompts in the new draft, default omitted prompts only for local_agent, and remind other supported types to configure a prompt before publishing without blocking draft creation.
Include prompt initialization in dry-run previews and retain the created employee ID with recovery guidance if subsequent draft initialization fails.
Initialize a missing platform prompt before publishing a local_agent employee, preserving existing prompts and stopping publication when draft lookup or initialization fails. Dry-run retains its request preview contract and includes the conditional steps without remote calls.
Reject explicitly empty or whitespace-only save-draft text fields in both preview and execution, while preserving omitted fields. Clarify the coordinated server contracts for no-op draft saves and draft/published snapshot responses.
v1.0.63-beta.2 Pre-release
Pre-release
Compare
Attendance approval helpers — adds shortcuts to calculate attendance approval duration, validate travel/out-of-office companion schedules, and query e
Attendance approval helpers — adds shortcuts to calculate attendance approval duration, validate travel/out-of-office companion schedules, and query employees' effective complex overtime settings. Proposed overtime durations (total and per-day detail entries) must be finite positive numbers matched to the requested duration unit, and numeric detail-list work dates must be 13-digit millisecond timestamps; anything else is rejected before the server call. Flag help publishes each custom constraint's decision facts so the delivered schema keeps the validation contract visible to agents, and the detail-list help matches the two-stage workflow (second-stage input; the first stage omits it to obtain the server's per-day skeleton).
Auth status read-only snapshot — dws auth status --readonly observes the local credential snapshot without the authentication lock, network validation, refresh, migration, or credential writes, keeping the same output fields as normal status and reporting inconclusive local state through explicit reason codes instead of a confirmed logout.
Contact user lookup by dingtalkId — adds dws contact user get-by-dingtalk-id --id <dingtalkId> (alias search-dingtalk) to retrieve a user's userId from their dingtalkId.
数字员工管理与能力资源 — 新增 dws dingtalk-tag manage、capability、run,覆盖创建、草稿保存、发布、查询、Skill ZIP 上传、员工域 MCP 创建与运行追踪;统一 agentUuid,支持双响应模式与 open_code / local_agent 类型。MCP 创建自动追加草稿依赖配套服务端,不自动发布;Skill/MCP 选择支持省略保留、空数组清空和非空数组替换。
员工身份登录 — manage login 串联授权码申请、换票、在线身份核验和精确 Profile 保存/刷新,保持主管当前 Profile;补充外部 auth exchange,不在普通输出中返回授权码或 Token。
本地 Agent 接入 — dingtalk-tag connect 支持本地 Agent Adapter 与 DSH,提供员工隔离的事件处理、生命周期、设备绑定及失败恢复;仅登录员工身份使用 manage login。同步 Help、Schema、mono/multi Skill 与必要接口文档。
统一 dingtalk-tag manage 的 agentUuid / userId 用户契约:创建时部门可省略,草稿按字段更新并分开 Skill/MCP 输入,本地头像可安全上传且不暴露临时凭证。
直属上级的输入与输出统一使用 supervisorUserId;HSF 历史字段名仅保留在 MCP 映射边界内部。
头像统一使用 avatarUrl;--avatar-url 同时支持公网 HTTP(S) 与本地图片,本地文件复用 Skill 上传封装并自动回写。
创建、更新的主程序类型映射到 MCP digitalTagEmployeeProfile.type;列表筛选仍使用顶层 type。CLI 保留 --main-program-type,详情查询改为 --snapshot draft|published 并发送 snapshot,兼容旧 --type 别名。
创建时响应模式缺省或为空,默认发送 mention_only;更新未传则保留原值,显式响应模式不会被默认值覆盖。发布前的完整配置由服务端校验。
登录/连接使用已发布详情的 profile.corpId/userId,不再要求旧 robotUid/staffId 字段;换票后仍在线核验身份,再保存精确 Profile。
MCP 创建/替换配置的帮助、Schema 与技能示例明确要求显式填写 configString.mcpServers.<名称>.type(streamable-http 或 sse),避免只有 URL 时服务端校验失败。
创建数字员工必须显式指定 --main-program-type open_code|local_agent,DWS 本地拒绝缺失或空值,帮助/Schema/调用说明同步标为必填;更新不传仍保留原值。
Mail employee lookup by corporate email — adds mail user get --org-email
and mail user batch-get --org-emails, with Schemas for
mail.get_user_by_org_email and mail.batch_get_users_by_org_emails.
Batch lookup accepts 1–100 addresses before deduplication and returns matched
employees plus notFoundOrgEmails. Both declare required input mappings,
read-only safety, and result fields, and use platform-injected operator and
organization identity.
Direct single lookup validates the employee result and declared field types
before reporting success, while retaining null/omitted not-found results and
exact integer IDs. This check does not reject a batch because one item is bad.
Mail batch partial results — preserves confirmed employee and not-found
results when individual inputs or response records fail. Partial output
separates succeeded, failed and unknown entries (exit code 7). An explicit
server rejection of an invalid batch address falls back to at most 100
deduplicated single-address lookups, including errors classified by the
runtime transport; global authentication, permission and
connection failures do not trigger that fallback. Unconfirmed results are
never reported as not-found.
Address-validation fallback recognizes the live service code 1001 as well
as SYSTEM_ERROR; unrelated errors with either code remain failures.
During fallback, global failures retain their original classification and
exit status, with confirmed progress in structured error
details.partialResult. Cancellation and raw PAT authorization errors are
returned to the framework unchanged instead of becoming partial success.
Agent guidance requires reading confirmed members from succeeded even on
exit code 7, continuing authorized follow-up work with them and reporting
unmatched, failed and unknown addresses.
Large integer output precision — preserves integer IDs beyond the exact
float64 range when decoding MCP text responses and through --jq, --fields
and formatted output.
International login is English-first — dws auth login --intl now renders
its terminal copy, the DingTalk authorization page (lang=en-US) and the
callback success page in English without requiring DWS_LANG=en. A locale
inherited from LANG no longer forces Chinese output; set DWS_LANG=zh
explicitly to keep the Chinese copy. Domestic (.com) login keeps following
DWS_LANG/LANG as before.
Wait framework capability — adds the reviewed Contract.Wait
declaration (contract.WaitSpec) with three execution modes: poll
(cadence-poll the leaf's WaitPoll hook), event (consume the leaf's
WaitEvents push stream, correlate events to the accepted resource via
match_field/resource_query, apply the same terminal map), and auto
(event first, fall back to polling when the stream ends or the
subscription fails — one deadline spans both phases). Declared commands
must use the ResultInvoke dispatcher; mode and hooks are paired at
construction (poll↔WaitPoll, event↔WaitEvents, auto↔both; surplus hooks
are rejected too). Declared commands register --wait /
--wait-timeout (framework-owned flags that never enter MCP toolArgs);
undeclared commands reject the flags as unknown. The wait phase closes
the unified envelope exactly once: terminal success → success,
terminal failure → failure with new wire-stable error.type: "wait"
(exit code 8), timeout → pending with meta.operation.timed_out: true
and the last observed state (exit 0). Deadline exhaustion during a poll,
during event consumption, or between polls always closes as timed-out
pending, never as a poll/stream failure; a correlated event with an
unknown status fails closed exactly like a poll. The pairing also closes
the overlay path: AttachContract / Tier2 metadata attaches cannot
publish a wait declaration (no hooks, no flags, no wait phase behind
it) — only the managed New construction can. At Schema assembly every
poll_command is resolved against the bound registry and must name a
delivered, agent-visible read command, so the declared manual resume
path cannot drift from the command tree. The capability is
projected into the Schema catalog (wait key) alongside dry_run. No
business command declares it yet; approval/export/batch adoption lands
separately.
Smart chat read shortcuts (+chat-messages, +at-me, +search-msg, +thread-replies) now decrypt third-party encrypted (SafeChat) message ciphertext before projection when the message crypto policy allows it. Message projections gain contentDecrypted, cryptoLayer, and dingKeyVersion (when > 0), and payloads gain an additive decrypt ledger (decryptCandidateCount, decryptAllowedCount, decryptedCount, decryptFailedCount, decryptFailures[]). Single-item failures land in the ledger with partial: true and never change the command exit code. Policy-off keeps the ciphertext and records one policy_disabled failure per candidate, so the additive ledger appears with decryptFailedCount >= 1 and the existing partial field can flip to true; only stub builds and --dry-run short-circuit the decrypt pipeline and keep output byte-identical to the previous behavior.
intField in the message crypto module now accepts json.Number, so keyVersion fields surfaced as JSON numbers by the MCP runtime are parsed instead of being silently dropped. The atomic chat read path may now emit dingKeyVersion on decrypted message projections (additive and within the existing result contract). Parsing ttlSeconds the same way means the crypto policy cache now honors the server-provided TTL: atomic reads fetch the policy once per conversation within the TTL window instead of once per message.
Introduce Schema delivery inside the existing Schema command of the single dws executable. Production does not produce or embed Schema identity at compile or release time. On supported ends (darwin/linux/windows amd64/arm64) each machine generates identity from live declarations at install or first dws schema, writes authenticated protobuf shards under the shared or user cache directory, and later hits verify digests then read those shards. Miss or corruption repairs from live assembly; when the shared cache exists but cannot be locked for repair (typically root-owned read-only), the repair falls back to the per-user cache and later processes reuse it. Empty local identity generates then uses the cache; it is not a permanent live-only mode. When plugins or other runtime extensions change the command surface, cache assembly and repair are delegated to an isolated child process using the pristine pre-registration environment, keeping persistent cache active without inheriting plugin runtime side effects. Plugin commands never enter the Schema surface, cached or live. The POSIX installer only advertises a cross-user shared cache when the warmed artifacts are root-owned, matching the runtime's shared-path ownership rule; a cache warmed by an ordinary user under a writable custom root is reported as installing-user-only instead.
Keep one complete Cobra tree for every public invocation. Compact typed metadata and shared builders reduce complete-tree allocations; process argv does not select a product factory or a utility-only tree.
Reduce temporary allocations during Schema validation and command initialization.
Normative notes live in docs/rfc-schema-runtime-cache.md only; no sibling plan/design/performance pages are kept.
dws contract review benefit|create|analysis|result from help and mark their Agent Schema availability unavailable. The commands remain as hidden historical argv stubs and fail closed with command_retired without calling legacy review MCP tools. The review group stays visible because hiding it is not in the consumed ledger. Ledger schema_availability_hardening entries are consumed.OA TableField examples (#1347) — correct mono and multi skill examples to encode detail rows as a two-dimensional array of name/value objects, and clarify that both creation modes preserve the serialized value without converting row objects.
Persistent Schema cache with plugins (#1400) — delegates Schema cache assembly and repair to an isolated child process when plugins are present, keeping persistent cache active without inheriting plugin runtime side effects.
AI Table form sharing now exposes server-returned shareFormUuid, status, and cover through shared structured result contracts for atomic commands and shortcuts; updates also publish cpSynced. Agent guidance requires confirming CP synchronization before reporting the sharing workflow as complete. Readback and CP projection remain the server's responsibility; DWS does not issue a second view update or construct cover URLs.
Atomic and shortcut updates now share strict terminal validation. Missing or invalid required fields, including cpSynced=false, produce partial_failure (exit 7), preserve the remote response and mark remote execution as started without retrying the write. Result Schema documents both verified success and partial-stage evidence. Usage guidance distinguishes supplied IDs from placeholders and preserves the shortcut JSON flag.
Terminal validation binds baseId, tableId, and viewId to the original request before accepting CP synchronization. A complete response for a different form is still partial_failure, even with cpSynced=true; both command entries retain the raw response and never replay or compensate the write.
Terminal validation also compares the explicitly requested enabled, formName, and formDesc against the echoed readback, so a response reporting different values is partial_failure rather than success. Requested properties the helper never echoes cannot be proven, so verified success reports verified=false and lists them in unverified instead of implying they took effect.
All four form-share Result Schemas accept their real dry-run request previews, including the optional shortcut dry_run marker. Preview success never implies remote execution or CP synchronization; assembled-leaf regression tests validate real envelopes against both full and compact JSON Schemas.
Skill discovery preserves the requested atomic/shortcut entry for result reviews instead of substituting usage Help. Interpretation selects the actual result branch and does not invent required fields or copy Schema evidence into malformed samples.
Recovery reviews preserve the target named in the original user request before Skill loading. Agent-authored Skill arguments cannot turn a background write into an additional contract-review target; this scope boundary is visible in discovery metadata as well as the loaded body. Synthetic JSON receipt reviews also load the product Skill: prohibiting online business operations does not skip local contract discovery or permit generic guesses about product-specific fields.
AI Table write recovery: +table-copy and +record-batch-create now generate one UUID v4 clientToken per create batch, submit it once, and reconcile uncertain receipts through MCP get_record_write_result. A fully recovered ID set is independently checked against record values before continuing. Unknown or partial results preserve the token/IDs and stop without replaying creation. The new read-only +record-write-result command exposes the recovery path in Help and Schema.
AI field readiness: +field-create recognizes MCP CREATE_FIELD_READBACK_PENDING, keeps the created IDs, and uses the existing bounded exact-ID readback/resume path. +field-run-ai requires readable aiConfig before mutation and reports submitted only for complete per-field task receipts; submission is not computation completion.
Review follow-up: duplicate-token errors and explicit get_record_write_result recovery hints no longer count as input rejections, even with retryable=false. They use the original token for read-only reconciliation and value verification; ordinary input rejections still stop immediately.
Recovery evidence: unknown creates without returned IDs do not advertise known effects. The read-only reconciliation command includes its Intent, and its Result Schema distinguishes verified applied results from dry-run previews and rejects unknown or incomplete success objects.
Pagination recovery: record queries classify business errors before accepting an empty terminal page. Invalidated cursors discard accumulated records and continuation tokens, return non-retryable restart guidance, and stop composite workflows before further writes.
Agent recovery guidance: the Shortcut Schema and mono/multi pagination references distinguish invalid snapshots from ordinary resumable failures; stale snapshots must discard prior rows and cursors, never deduplicate and concatenate pages across snapshots or replay a composite write.
Pagination review boundary: mono/multi references separate a concise, complete recovery assessment from operational query recipes. Unknown or incomplete writes remain read-only until reconciled; comparing query results is not permission to infer missing records or propose incremental create/backfill.
Focused recovery discovery: field-create Help/Schema explains CREATE_FIELD_READBACK_PENDING and bounded same-ID verification. Result-only reviews stay on the requested recovery command instead of expanding to its upstream write command or inferring unpublished Result fields from repeated discovery.
Skill loading and routing: keep the AITable skill description focused on capability selection, with execution examples in the loaded body. Contract reviews preserve the requested command identity and query only that command, without treating background writes as additional discovery targets. Regression tests enforce this metadata/body boundary and all four exact form-share review routes.
Recovery review clarity: lead with the requested read-only next step and safety decision, distinguishing local contract discovery from unverified remote state. When no command is requested, answer all safety questions up front—write replay, retained/discarded results, and read-only recovery prerequisites—before detailed explanation. Unknown or incomplete results retain the original Base/Table/token reconciliation route instead of switching to full-table queries. Reconciliation Schema explicitly treats records missing from the returned ID set as unverified, never as a count-based backfill plan.
Deployment dependency: the paired MCP branch must be deployed and the new read-only tool registered in the gateway. No lippi-doc-notable changes are included. Local mock/contract tests do not establish live service readiness; real-environment evaluation remains a separate deployment check.
登录过程中使用临时 Token 补全身份时,立即应用本次登录的 MCP 端点覆盖,包括国内及国际预发;不再等待登录成功后的 mcp_url 持久化。显式产品端点、第三方地址和插件所属路由保持原值,查询不读取旧 Profile。
Windows 原生覆盖率作业的总时限从 20 分钟调整为 30 分钟,为完整测试批次、工具链准备和产物上传保留余量,避免接近 20 分钟的运行被取消。测试范围、单批测试超时、100% 变更代码覆盖率门禁及汇总依赖检查保持原有要求。
DEK missing relogin — Allow reauthorization when the local login encryption key is missing. Keep old ciphertext until a fresh credential is available, then replace only the login write targets and create a new encryption key as needed. Refresh and transient Keychain failures retain their existing protection.
数字员工 Skill 创建和更新使用同一个已打开的文件完成 ZIP 校验与流式上传,避免校验后重新打开路径时把替换文件或符号链接目标上传。上传仅读取校验时的文件大小,句柄在操作结束(包括 dry-run 和失败)后关闭。
补充普通文件替换和符号链接替换的 create/update 回归测试,保留打开前对命名管道等特殊文件的拒绝;增加 dingtalk_tag.skill_package_validated、dingtalk_tag.file_upload 本地诊断事件,仅记录大小、阶段、接口路径、成功状态与耗时,不记录本地路径、文件内容、身份或凭据。
修正数字员工接入的事件传输就绪判断:使用上游真实状态并报告断线重连,区分 IPC、Agent 初始化和事件连接;DSH 状态交叉验证同一员工的 Event Bus,旧版或未知连接不再报告传输就绪。
数字员工本地 Agent 不再固定指定事件来源为 digital_employee,改为沿用 Event 默认规则:优先读取 DWS_STREAM_SOURCE_ID,未设置时开源版使用 open;升级后需重启员工 worker 生效。
个人 Stream 正确响应系统 ping/disconnect,不将系统控制帧投递为业务消息;订阅查询兼容 items/list 及字符串/整数时间戳。
修正 Windows 下正常停止可能被误报为消费者异常退出,以及损坏的任务/绑定目录被误当作不存在的问题;补充跨平台身份、绑定回执、上传失败、重试隔离和日志脱敏回归测试。
单聊引用回复 — 会话信息明确返回 singleChat: true 时,即使省略群聊话题开关,也能正常引用回复;保留会话身份、响应有效性及话题标记校验。
OA approval event fields — preserve staff_id, activity_id, corp_id, and business_id from the business payload in event consume --flatten for all seven OA approval events, and expose cc_time for approval instance CC events. Optional fields remain omitted when absent; an explicitly provided zero cc_time is preserved.
Legacy token pre-login recovery — Allow OAuth, device, auth-code, PAT, and --token reauthorization to start when the legacy auth-token ciphertext has a confirmed DEK mismatch. The old ciphertext remains untouched until fresh credentials are available, then only the login's target slots are replaced; transient and unclassified Keychain failures still fail closed.
Windows cgo 崩溃:重新编译 Windows amd64/arm64 预编译 libsafechat.a(消除 legacy _vsnprintf/__imp__* dllimport 引用),并移除已无必要的 msvcrt_compat_windows.c 旧 CRT 桥接层,修复官方发布包在 Windows 上初始化 safechat(cgo)即崩溃的问题。
Root help renders the live complete Cobra tree, so explicitly registered supplement-backed commands stay visible alongside products and utilities. There is no separate declaration-derived help snapshot.
Command validation errors — report framework-owned parameter failures consistently as validation errors with exit code 3, while preserving API errors, explicit exit codes, cancellation, and deadlines.
Parent and proxy flags — route parent traversal and wiki proxy parse failures through the same validation boundary and preserve target command hints.
Required flag wording — framework-prepared commands now report missing required flag(s): --name instead of Cobra’s required flag(s) "name" not set. The original Cobra error remains available as the cause.
Generated commands — normalize native validation failures in lazily created help/completion commands, and remove duplicate required/group checks while retaining business hook order.
v1.0.63-beta.1 Pre-release
Pre-release
Compare
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
This stable release promotes the sealed v1.0.62-beta.8 baseline and adds verified AI Table, document, event, calendar, chat, AISearch, and language-de
This stable release promotes the sealed v1.0.62-beta.8 baseline and adds verified AI Table, document, event, calendar, chat, AISearch, and language-default improvements merged afterwards.
v1.0.62-beta.8Add AI Table shortcuts for exact field/view resolution, bounded record reads and NDJSON export, batch record/field creation with readback and recovery, App pages and widgets, forms, dashboards, aggregation, and attachment downloads. Preserve existing entry points and equivalent aliases; reject incomplete pagination, mismatched write verification, and unverified AI submission receipts instead of reporting success. Downstream capability and permission limitations remain explicit.
Doc shortcut workflows — add local and online document structure checks with doc +script, verified standalone media upload with doc +media-upload, optional title fallback, and ordered media attachments during document creation.
Doc reading and editing — add direct-folder search filtering, readable date filters, chapter and regex block-context reads, document comments, and verified same-document block copying and range editing while preserving existing commands and aliases. Range edits remain sequential, not atomic.
Doc media controls — add clipboard image input, attachment preview/summary selection, vertical cover positioning, persistent preview output, and explicit download overwrite; fix tag filtering and keep upload progress off JSON stdout.
Doc download confirmation — use doc +download-overwrite --source media|cover for confirmed replacement of local files. Existing media, preview, and cover downloads retain their no-clobber behavior and safety contracts; preserve the preview output shorthand -o.
Create with media confirmation — use doc +create-with-media --media-files to create a document and upload local images or attachments after confirmation. Plain doc +create retains its published behavior and does not accept media uploads.
AITable query routing (#1342) — clarifies routing among raw record queries, server-side statistics, PostgreSQL analysis, and full data export.
默认界面语言 — 未设置语言或语言值不受支持时,默认使用简体中文;保留 DWS_LANG 优先于 LANG 的解析顺序及显式英文设置。
Personal events now obtain managed AppKey metadata when it is missing locally in open-source normal mode, without requiring an AppSecret or changing saved credentials. Existing application identities retain precedence, background listeners reuse the resolved AppKey, and metadata failures report actionable retryability.
Clarify AISearch evidence checks for time, identity, relevance, uniqueness, and same-condition handoffs to native products.
Guide newly shared AI Table forms to pass their known title through --form-name; require usage-only Agent answers to perform exactly one safe leaf discovery query, then lead with a complete command or an explicit placeholder template without guessing missing IDs, and state that omitted share settings stay unchanged without claiming execution; reject undeclared record-comment rich-content fields before invoking MCP; preserve actionable comment visibility errors; and move AI Table comments, record ID pagination, entity search, and PSQL machine output onto reviewed unified result contracts whose dry-run previews satisfy the published Result Schema and whose comment pagination guidance reads continuation state from meta.pagination.
Calendar invitation receipts — fixes false readback_attendee_missing failures from calendar +invite and calendar +book --with when participant responses omit user IDs and display names differ from directory names. Invitations require an explicit successful write receipt and report verified=false; +invite adds acknowledged=true, while +book --with adds attendeesAcknowledged=true and retains event readback through eventVerified=true.
Chat rich-text links — preserve link-item URL targets alongside their labels in message projections, including links without labels.
Nothing published for this version
Nothing published for this version
OA approval template management ( #1346 ) — add dws oa approval template list and detail --template-code <code> for querying manageable approval templ
OA approval template management (#1346) — add
dws oa approval template list and detail --template-code <code> for
querying manageable approval templates, form schemas, and process
configuration.
Interactive card callback events (Aone 86136546) — dws event consume user_card_action_triggered reuses the personal-event subscription lifecycle with the same empty-object filter rule as IM/OA. Its flattened schema describes typed answers and questions under payload.body.actionData.context, business/conversation/operator fields under payload.body, and millisecond timestamps while preserving unknown fields for forward compatibility.
AI 表格记录评论 — 新增评论的分页查询、创建、回复、完整更新和删除命令,支持纯文本、@人员及已上传图片。
Calendar event options — adds --is-all-day and --add-online-meeting to calendar event create and update, with omission-preserving boolean updates. Explicit all-day state changes require both start and end values, validated as dates or timezone-bearing date-times for the selected state.
A2UI card options — adds optional --a2ui-annotations JSON object arrays to card creation and updates, and --support-forward to creation (defaults to false).
Public Agent Skills CLI — npx skills add DingTalk-Real-AI/dingtalk-workspace-cli -g installs the per-product dingtalk-* skills after confirming the skills, target directories, and existing same-named content handling. The all-in-one mono dws skill is marked metadata.internal: true so it is not a default installable skill. dws skill setup remains the China / upgrade / ownership path.
Schema 时间格式声明 — 支持字符串参数以 anyOf 声明多个格式,并为日历创建/更新的 date-time 到 date/date-time 扩展及全天状态条件必填提供精确、基线持有的迁移校验;其他格式和条件必填变更仍被拦截。
Standalone whiteboard export — adds whiteboard export and whiteboard export-get
to download PNG/PDF exports. Both commands support request-only dry-run previews.
Signed URL query strings do not affect filenames; downloads validate their file
signatures before atomic publication and never overwrite existing files. Failed
tasks retain recovery instructions with the job ID, format, and output directory.
Downloads enforce HTTPS/443 public network targets on redirects and actual
connections, with a 512 MiB limit for both declared and streamed response sizes.
AI Table CLI safety and compatibility — adds safe entity resolution for view filters, strengthens dashboard, workflow, import, record, and table validation, supports the latest Base copy and share-form protocols, and aligns Runtime Schema and Skill guidance with observable MCP behavior.
Update the embedded CLI telemetry SDK to v0.4.0 and send completed command events from a bounded background process, preserving existing telemetry fields and keeping network waits out of command execution.
Update the embedded runtime SDK to 20260909 and remove auxiliary ps files from builds and runtime extraction, reducing single-binary package size.
Refresh the macOS universal runtime library while retaining the 1 MiB payload slot and using the payload digest to upgrade existing installations of the same resource version.
Direct-runtime MCP endpoint resolution (#1331) — restore the
environment-aware mcpdev endpoint so dws dev mcp commands reach the
backend instead of failing locally with endpoint_not_resolved.
Automatic pagination now preserves cancellation when the page-delay timer and
context cancellation become ready together, rather than randomly continuing.
OA approval list response types (#1351) — normalize success to a
boolean and numeric error codes to errorCode for pending, submitted, and
copied approval lists while preserving business data and diagnostics.
Preserve optional --source-config for AI Table datasource updates: read and reuse the complete existing configuration when omitted, and stop before updating if the read cannot provide a valid configuration.
AI Table capability routing — isolates concurrent multi-profile discovery so each tools/list request uses the selected account without changing the process-wide profile.
Include the available runtime context in manual OAuth and device authorization links, including --no-browser, so copied links match browser authorization. Display device links outside a frame to keep long URLs copyable on narrow terminals.
Stop adding the CLI locale as a lang query parameter to browser, manual, and reauthorization login links.
Chat read completeness contracts — makes conversation and message reads distinguish normal bounded truncation from terminal pagination, projection, enrichment, and resource-download failures. Incomplete reads retain their canonical partial result and typed retry diagnostics, while newly declared Result and pagination contracts remain in byte-compatible dual validation before activation.
Chat routing and bounded discovery — distinguishes conversation categories from real chat groups, aligns reviewed Shortcut owners with runtime selection and references, and steers agents toward narrow leaf Schema before a single exact Help fallback.
Public Schema constraint closure — normalizes reviewed hidden aliases to their public parameters and rejects constraints that cannot be represented without exposing hidden runtime inputs.
Drive and Wiki agent workflows — align pagination, confirmation, target verification, recovery receipts, and Reference routing with runtime behavior.
Stop implicit HTTP retries of MCP tool invocations after gateway or connection failures, preventing duplicate datasource updates and other remote writes. Discovery and explicit read/reconciliation retry policies retain their existing behavior.
Minutes artifact evidence — distinguish empty action items, unsupported responses and speaker-task terminal states; preserve list display metadata and complete upload/permission preview options.
Minutes export and delivery — remove signed credentials from exported text, keep partial results explicit, and align time conversion, pagination, permissions and cross-product report guidance with verified runtime behavior.
Fix the Windows whiteboard export test to compare decoded JSON paths, and run platform app coverage tests in fresh batches while retaining the full test selection, cross-package instrumentation, and coverage gate.
v1.0.62-beta.8 Pre-release
Pre-release
Compare
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
…entry sharing the same implementation, without deprecation warnings in execution, Help, or Schema. Public Help, Schema primary CLI paths/examples, and…
Chat active conversations — adds dws chat +active-conversations --start <time> to auto-page cross-conversation messages and return deduplicated conversation summaries with stable name fields, latest-message time, and completeness metadata. Query boundaries use whole seconds: explicit nonzero fractional seconds are rejected, and the default end is rounded down to exclude the current unfinished second. The effective end must be later than the start and remains fixed across pages, results, and continuation; latest-message timestamps retain millisecond precision. Returned messages are filtered to the fixed [start,end) window before aggregation; pages with no matching messages still follow server pagination. Pagination waits 200ms between pages by default; later-page failures preserve completed summaries and a continuation cursor as partial_failure (exit 7). Resume with the original time window, page size, and profile, then merge batches by conversation ID.
Chat shortcut 对齐与查询校验 — 补充兼容别名、创建默认值、消息上下文定位、文本与 Thread 回复、筛选排序及分页控制,保留原入口;共享消息富化并严格区分空集合、不完整结果与失败,增加资源分段重试、版本校验和原子落盘。下游尚未支持或未实测的身份、消息类型与权限范围单独列明。
Contact invite/apply administration — adds dws contact exclusive-account disable|enable for enterprise-account status, a dws contact org
invite/apply group (invite-switch, invite-audit, invite-info,
invite-list, apply-list, apply-approve, apply-reject, apply-block,
apply-remove), and dws contact dept invite-audit for department-level
join-request auditing.
Standalone whiteboards — adds OpenNodes-based whiteboard create-with-content and extends
the existing whiteboard query / whiteboard update entry points to operate
on standalone boards when --part-id is omitted, while preserving the
document-embedded flow when it is explicitly supplied. Standalone reads
decode the service resultJson, and writes enforce revision and stable
request-ID guards with compatible receipt validation and same-type read-back.
CLI auth apply pending page (#1285) — the browser apply flow now lands on a
dedicated approval-pending page that polls and auto-redirects after approval;
duplicate apply requests are idempotent, and all local callback pages and API
responses are served with Cache-Control: no-store to avoid stale state after
a page refresh.
CLI access denial copy (#1285) — terminal denial reasons are now split by
whether the path is applyable. cli_not_enabled keeps the apply flow and shows
a personal-scope message ("you do not yet have CLI data access") with the
approver picker relabeled to "select approver"; the inline success message was
replaced by a redirect to the pending page. The non-applyable user_forbidden
and user_not_allowed reasons now share a single consolidated terminal message
("this organization has not enabled CLI data access") across the browser page and
both login transports (OAuth browser flow and device flow).
Chat recent conversations — makes --start optional for dws chat +recent-conversations. Omission selects the 24 hours before the effective --end; omitting both boundaries selects the latest 24 hours ending at the current time rounded down to a whole second. Explicit --start retains the existing time formats, whole-second validation, and blank-input rejection. Both effective boundaries stay fixed across pagination and are returned in the result. Non-initial --cursor requests must explicitly reuse the previous --start and --end to preserve the original query window.
Chat recent conversations — makes dws chat +recent-conversations the preferred entry and retains +active-conversations as a hidden executable compatibility entry sharing the same implementation, without deprecation warnings in execution, Help, or Schema. Public Help, Schema primary CLI paths/examples, and Mono/Multi Skills recommend the new name; the stable Schema identity chat.shortcut_active_conversations and old CLI-path lookup remain supported. Query windows, pagination, and result semantics are unchanged by this rename.
Runtime context — Refresh the embedded payload to 20260908, verify and materialize owned resources beside the resolved executable with cache fallback, and attach the process context to browser login URLs while keeping terminal links and diagnostics redacted.
dws safechat 命令(破坏性变更) — 删除 dws safechat selftest 与 dws safechat decrypt。这两个命令在 1.0.62-beta.3 (#1051) 交付,但只在显式 -tags safechat 的源码构建中存在:官方 Release 一直是 CGO_ENABLED=0,stub 的 newSafeChatCommand() 返回 nil,因此官方二进制从未包含该命令,受影响的只有自行打 tag 构建并升级的用户。SafeChat 现在是 internal/msgcrypto 的内部后端,仅通过聊天消息加解密路径暴露,不再提供独立顶层命令。dws safechat decrypt 的等价入口是 dws chat crypto decrypt,它走同一套 SafeChat 后端并按策略解密。dws safechat selftest(真实取码与密钥获取的端到端自检)没有等价命令;需要验证后端可用性时改用 dws chat crypto decrypt 对一条真实密文做一次解密。Contact apply-list safety semantics — dws contact org apply-list marks
unread join applications as read on the server; its schema safety effect is
now declared as write (risk stays low, confirmation stays
not_required) and the selection guidance discloses the read-marking side
effect so Agents no longer treat it as a pure read.
Contact apply-remove safety semantics — dws contact org apply-remove
deletes organization join application records irreversibly; its schema safety
effect is now declared as destructive (risk high, confirmation
user_required) and the selection guidance discloses that the deletion is
not recoverable so Agents no longer treat it as an ordinary write.
Contact org list pagination contract — dws contact org invite-list and
dws contact org apply-list now declare the unified cursor Pagination contract
(cursor parameter, meta.pagination metadata) and their result data schemas
no longer leak hasMore/nextCursor. Runtime responses project the server-side
cursor fields into meta.pagination so Agents can resume paging from the
standard contract.
Chat recent conversations pagination — adds a shared --total-timeout budget (default 300 seconds, range 1–3600) across all requests, retries and page delays in one invocation. A timeout preserves validated pages in the partial-failure result and returns the failed page's input cursor. Cursor continuation remains caller-managed: reuse the same profile, time window and page size, and merge batches by conversation ID. Progress is not persisted to disk; forcibly terminated queries must be restarted.
Chat conversation categories — treat im/list_conversations_by_category as the declared single-response interface when its explicit conversation array contains no pagination signal, while continuing to fail closed on partial or non-resumable pagination metadata. +category-list-conversations and +feed-group-query-item now publish the resolved pagination mode and source-exhaustion facts instead of rejecting every live response that omits hasMore.
SafeChat 默认构建与官方产物 — 支持平台的 CGO 构建无需额外 build tag
即包含 SafeChat 后端,官方六平台 Release 固定使用可校验的交叉编译工具链并拒绝
发布 CGO-disabled stub 二进制。
本地 make build / make rebuild 默认启用 CGO,并保留显式
CGO_ENABLED=0 的 stub 构建选择。
Linux 官方构建显式使用 glibc 2.17 链接目标,并校验 ELF 符号版本,
防止交叉编译镜像升级隐式提高 Linux 系统要求。
install.sh / install-event.sh / install-devapp.sh 在下载前识别 musl
发行版(如 Alpine)并明确中止。Linux 产物依赖 glibc 动态加载器,此前这类环境
会安装成功但连 dws version 都无法启动。判定以 ldd --version 为准,musl
加载器文件只在 ldd 不报版本时兜底(Alpine 的 BusyBox ldd 仅转发给加载器),
因此额外安装了 musl / musl-tools 的 glibc 发行版不会被误拒。
SafeChat cipher 关闭时会等待进行中的加解密结束,不再与 Close 并发访问
vendor client 的初始化状态(go test -race 下可复现的数据竞态)。
Schema 向后兼容检查 — 允许删除 require_one_of 必填组,以支持具备默认值或可自动解析参数的命令;保留新增约束、互斥、参数类型和身份安全检查,并通过基线拥有的两阶段评审机制交付。
Skill setup source resolution — accepts an extracted dws-skills.zip
root for --source / DWS_SKILL_SOURCE, selects its mono or multi
subtree by mode, and no longer mistakes the compatibility mono directory
for a single MultiSkill.
v1.0.62-beta.7 Pre-release
Pre-release
Compare
AI 表格 PostgreSQL 只读查询 — 新增 dws aitable psql ,支持发现逻辑表和列类型,并执行只读 SELECT ,包括同一 Base 内的多表 JOIN。
AI 表格 PostgreSQL 只读查询 — 新增 dws aitable psql,支持发现逻辑表和列类型,并执行只读 SELECT,包括同一 Base 内的多表 JOIN。
Native Markdown themes — adds --theme to markdown create and
markdown overwrite, preserving existing Front Matter while safely writing
the selected we-markdown theme into a private upload copy.
internal 错误和退出码 5 修正为 validation 错误和退出码 3;校验仍在 MCP 调用前完成。v1.0.62-beta.6 Pre-release
Pre-release
Compare
AI 表格应用模式命令 ( #1264 ) — 新增 dws aitable app 及 page / widget 子命令,支持 App 获取与更新、页面和 Widget 的创建、查询、更新、删除与排序。
AI 表格应用模式命令 (#1264) — 新增 dws aitable app 及 page/widget 子命令,支持 App 获取与更新、页面和 Widget 的创建、查询、更新、删除与排序。
文档块批量删除 — doc block delete 的 --block-id 支持逗号分隔一次删除多个块
(单次最多 50 个)。采用尽力而为语义:单个 blockId 未找到不阻塞其余块的删除,
未找到的在 notFoundBlockIds 中列出;仅当全部未找到时整体失败。
markdown @人 写后回读误报 — 写入含 [@姓名](alidocs-mcp://doc/mention?openDingTalkId=…) 的 markdown 时,doc +create 与 doc +update --command append|overwrite 会以 doc_write_verification_failed 报错,而内容其实已正确写入。原因是写后回读把写入原文与服务端改写后的正文比对,而服务端会把该私有协议改写成钉钉个人资料链接。现在写后回读改为按位置配对:只有预期正文中写了 mention 私有协议的那个位置,才允许回读侧是个人资料链接;其余链接——包括作者自己写的普通个人资料链接——仍保留完整目标并严格比对。显示文本与节点顺序照旧参与比对,漏写、改标签或顺序错乱依旧判定失败。原子命令 doc update 无写后回读,行为不变。
@人 目标身份不再被隐含声明为已验证 — 回读能证明 mention 链接落在作者写的位置、显示文本未变,但证明不了它解析到了哪个人:openDingTalkId 与改写后的 staffId 是不同值且无本地映射。含 mention 的写入结果因此在与 verified 同级处声明作用域:verificationScope="partial"、unverified=["mention_targets"],verify 步骤状态由 success 降为 partial 并带 scope="partial"(只按 steps[].status 推进、不认识 scope 字段的既有消费者因此也不会再把它读成完整核验成功),另有 verification.mentionTargetsVerified=false 与一条说明性 warning,并把 verified 置为 false(操作本身仍 status=success):回读无法确定 @ 到了谁,就不宣称已验证。另有 unverifiableLocally=["mention_targets"] 表明该缺口不是"还没查"而是"回读查不出来",重读文档不会得到新信息。warning 只透两条事实:@人链接指向的具体人员需用户自行核对,正文其余部分(含该链接的位置与显示文本)均已通过回读校验。不含 mention 的写入输出完全不变。
Chat message decrypt fallback — skips crypto policy lookups and decrypt failure ledger fields on chat read paths when the DWS binary does not include the SafeChat backend, while preserving policy-driven decryption after chat message list --page-all aggregates its pages.
AI Table view OR filters — allows aitable view update filter to persist
a single top-level or group while preserving flat-array AND behavior,
rejecting nested logical groups, and verifying equivalent service readback
shapes.
OA 空页分页兼容 — 待审批、已处理和已发起审批列表兼容成功响应中 values:[] 省略 hasMore 的终页编码,避免空列表误报 missing_pagination;保留显式分页值及业务状态、数组结构和其他接口的严格校验。
自动合并:修复 Reviewer Router 将可合并但显示 blocked 的 PR 持续跳过的问题;恢复 App 的同步合并尝试,并继续由 GitHub 强制执行审批和必需 CI 检查。
Schema compatibility checks — accept a new require_one_of group when a historical unconditional required parameter without a default already guarantees a supplied member. Other incompatible parameter changes remain rejected; CLI runtime behavior is unchanged.
v1.0.62-beta.5 Pre-release
Pre-release
Compare
Release dependency checksums ( #1288 ) — removes stale module checksum records so release validation remains reproducible after go mod tidy .
go mod tidy.v1.0.62-beta.4 Pre-release
Pre-release
Compare
Channel: prerelease OSS-Mirror: deferred Release-Run: 33827945219 Release-Run-Attempt: 1 Requested-By: haofeng0705 Requested-By-ID: 30925823 Sealed-Co
SafeChat message encryption/decryption (#1051) — dws safechat commands enable AnHeng SafeDing (安恒密盾) message encryption and decryption. Available only in builds with -tags safechat (requires CGO and platform-specific static libraries). Commands include safechat selftest for end-to-end self-check (real authCode fetch and key retrieval) and safechat decrypt to decrypt ciphertext messages. The PR also adds internal/msgcrypto package with cipher operations, vendorAuthCode portal integration, and key server client supporting both in-memory and file-based keystores with 0600 permissions on Unix and warning logs on Windows.
Chat third-party message decrypt (#1150) — adds policy-driven Ding + SafeChat message decryption for core chat read paths, explicit dws chat crypto decrypt diagnostics, and IM MCP wiring for policy lookup plus Ding batch decrypt. Outbound send encryption and dws chat crypto encrypt are intentionally not enabled in this PR.
html fetch / create / overwrite / patch — full native .html / .htm file support in DingPan or the doc space, mirroring the markdown domain. create accepts a literal string, @file, stdin (-), or an existing local HTML file via --file. fetch downloads and prints the remote content (optional sanitized --output). overwrite replaces the whole file with before/after preview on command-level --dry-run; patch applies literal or RE2 replacements with zero-match never writing and an empty result aborting. Routing matches the markdown leaves: explicit --space-id / --workspace, auto domain probe, --folder read-only probe on create. Drive uploads submit the text/html MIME type. Implemented on a shared textfile engine extracted from the markdown leaves (pure refactor, behavior unchanged).
Bounded CI app race fan-out (#1278) — keeps all nine reviewed
internal/app race-test partitions process-isolated while balancing them
across three physical jobs, reducing focused and full-suite runner demand by
six jobs without weakening partition coverage or increasing the 20-minute
job limit.
Chat Shortcut-first discovery — prioritizes Featured Shortcuts in
dws chat --help, keeps the complete canonical Shortcut catalog discoverable,
and points overlapping atomic command help to the reviewed Shortcut owner.
aitable record query --all (#1016) — an empty final page that omits the records key now ends pagination normally instead of failing with query_records response is missing records.
Post-merge CI admission reuse — reuses exact successful full-suite PR evidence for tree-identical protected-main merges and promotes the verified coverage artifact to the merge SHA cache, reducing duplicate runner work without adding jobs or weakening required contexts.
Chat role and category routing — resolves natural group names before group-role operations, aligns role assignment guidance with required non-empty role IDs, and publishes a compact shortcut-first category workflow to reduce Help and Catalog discovery without dropping result, safety, or identity constraints.
Contract command safety and Skill routing — Contract destructive operations (archive, subject delete, subject batch-delete, project delete, and account delete) now require explicit user confirmation (--yes) before executing, with Schema Safety confirmation=user_required. Batch project/subject deletion rejects empty parsed ID lists, subject deletion enforces the 1000-ID service limit, and required project/subject pagination rejects non-positive values before calling MCP. Account-list execution-time filters are documented consistently as ISO-8601 CLI inputs converted to MCP milliseconds. Legal smart-contract guidance is delivered through dingtalk-misc instead of a standalone first-level Skill, and the retired edu-contact endpoint is no longer registered as a supplement server.
Coverage baseline reliability — balances the existing app test partitions across the current coverage runners and reuses the same bounded path for trusted cold-cache recovery, avoiding the long-lived app test process without adding CI matrix jobs.
Dlink target routing — teaches Doc, Drive, Sheet, AITable, shared URL
routing, and the doc info Schema to resolve shortcut targets through
linkSourceInfo for content operations while preserving the top-level node
for explicit shortcut-entry management.
Main integration reliability — keeps main and release multi-profile E2E validation focused on the isolated profile chain while existing CI shards own the complete Go regressions, avoiding the long-lived runner shutdown window without adding CI jobs.
Minutes permission sharing — adds --member-staff-ids to
minutes permission add and minutes +share, preserving leading-zero staff
IDs while keeping --member-uids for DingTalk UIDs.
Reviewer Router reconciliation — keeps blocked, conflicting, draft, and otherwise unproven merge candidates retriable without letting one expected not-ready PR fail the repository-wide reconciliation batch.
Chat A2UI cards ( #1140 ) — adds chat message send-a2ui-card and chat message update-a2ui-card as dedicated A2UI commands while preserving the existin
chat message send-a2ui-card andchat message update-a2ui-card as dedicated A2UI commands while preservingv1.0.62-beta.2 Pre-release
Pre-release
Compare
Channel: prerelease OSS-Mirror: deferred Release-Run: 33528076385 Release-Run-Attempt: 1 Requested-By: haofeng0705 Requested-By-ID: 30925823 Sealed-Co
Runtime request context (#1221) — packages an optional runtime payload, reports redacted readiness in dws doctor, and attaches compact context metadata to supported business requests.
hrbrain talent-pool save — creates or updates a talent pool. Omit --pool-code to create a new pool (only --pool-name is required) or pass --pool-code to update an existing one; optional --pool-desc, --rule-json (auto in/out rule, validated as a JSON object), and --pool-tags (validated as a non-empty JSON array) are forwarded to the create_or_update_pool MCP tool. The write is gated by a confirmation prompt (--yes to skip).
hrbrain talent-pool move-members — batch-moves staff into or out of a talent pool via the entering_or_leaving_pool MCP tool. Requires --pool-code, --opt-type (ENTERING/LEAVING), and --staff-ids (comma-separated work numbers), with an optional --remark. The write is gated by a confirmation prompt (--yes to skip).
dws, removes the sidecar tree from new archives and installers, and retains sidecar discovery for existing installations.Chat atomic message results — normalizes message fields across atomic list and search commands, keeps nested search results aligned with top-level messages, and exposes stable send-status workflow references without removing raw response fields.
IM message AI provenance — preserves the lower messageAiSendFlag value across message search, list, mget, @-mention, Pin, quoted-message, forwarded-message, and thread-reply projections.
Nothing published for this version
This release promotes the sealed v1.0.61-beta.3 contents to stable.
This release promotes the sealed v1.0.61-beta.3 contents to stable.
Agent-ready command contracts — expands reviewed Help, Schema, safety,
selection, result, pagination, and recovery guidance across the CLI, and
moves static MCP authoring and published-tool invocation onto explicit
dws dev mcp and dws mcp published command surfaces.
Collaboration and event workflows — adds Chat Thread promotion,
conversation-file upload, bounded message pagination, safer quoted replies,
DingTalk task lifecycle events, and VoIP invite event consumption.
Document and data operations — broadens Sheet batch and CSV controls,
strengthens AI Table routing and composite verification, hardens Drive and
Wiki shortcuts, and adds safer delegated authorization plus URL-only,
optional-output, overwrite-protected, and concurrent-writer-safe downloads.
Organization and automation commands — adds contact label and custom
field management, tightens attendance date handling and DingTalk task
workflows, and improves login, Windows Skill installation, and executable
doctor recovery guidance.
Runtime and connector reliability — preserves compatible document,
Markdown, chat, and shortcut result shapes while improving DING, Whiteboard,
Qoder Stream, and cross-product verification and failure evidence.
v1.0.61-beta.3Chat conversation-file upload — adds chat conversation-file upload for local files, returning reusable dentryId and spaceId without sending a chat message while leaving the retired chat file upload path unchanged.
Chat message list page-all — dws chat message list now accepts --page-all to iterate the time-boundary pagination automatically and return one merged messages array (with pagesFetched, stopReason, nextPage, and per-page failure diagnostics). --page-limit (default 50), --max-items, and --page-delay tune the sweep; without --page-all the command keeps its exact single-page behavior.
Delegation auth capability options — when --principal-user-id is set, the per-tool check_capability verification now carries a tool-specific options payload so the server can authorize the exact operation. create sends the create action parameters (name/type/target folder or workspace), upload/get_file_upload_info send the upload action parameters (file name and size), import/create_import_session send the target node together with file name, suffix, and size, copy/move send the resolved source node, permission management sends the target members, and drive publish (set_file_publish) sends the share-scope target (shareScopeSetParam) so making a file internet-public (WEB) is pre-checked. Tools without a mapping continue to check without an options key.
Permission target members mapping — permission-management delegation checks normalize both the new structured member format and the legacy --users list. Legacy user ids are converted into the structured target-member shape using the current logged-in enterprise corpId (resolved through the $corpId runtime default), keeping old and new invocations equivalent.
Import and upload dry-run delegation parity — doc import and doc upload now run the delegation pre-check on their dry-run previews, matching the execution path. A dry-run combined with --principal-user-id is verified against the command's real first delegated call (create_import_session / get_file_upload_info) before any preview is rendered, and a denied principal blocks the preview.
Import target folder node resolution — extractNodeId now recognizes targetFolderId (the key doc import --folder uses to carry its destination), so folder-targeted imports resolve a node id and are gated correctly. copy/move remain unaffected because an explicit nodeId still takes precedence over the folder keys.
Drive download URL-only mode — dws drive download and dws drive download-version accept --url-only, a non-downloading mode that returns the temporary signed download URL and required request headers (downloadUrl/headers, plus optional fileName/fileSize/version) without writing any file locally; the caller (Agent runtime / external system) performs the download itself. Signed URLs keep literal & separators in JSON output so they are copy-paste usable. --url-only is mutually exclusive with --output/--overwrite/--part-size/--parallel/--no-resume (explicit combinations fail fast) and stays effective through the download --version N compatibility routing.
Drive download optional output — dws drive download and dws drive download-version no longer require --output: when omitted, files are saved to the current directory with the filename inferred from the response fileName (falling back to the download URL); explicit --output behavior (file path or directory) is unchanged.
Drive download overwrite guard — dws drive download and dws drive download-version now reject downloads when the target file already exists, returning a structured INPUT_FILE_ALREADY_EXISTS error with recovery guidance; pass --overwrite to proceed. Re-running the same download used to silently overwrite the existing file. The guard is enforced both before the transfer starts and atomically at publish time (no-replace link), so a file that appears during a long download is never silently overwritten. Resume artifacts (.dwspart/.dwspart.meta) are not treated as conflicts.
AI Table composite verification — accepts the service's real newRecordIds, view-filter, and workflow-detail response shapes, and retries only idempotent table-copy read-backs so delayed visibility no longer reports a false partial success.
Workflow deployment status reporting — replaces resolved.enable with resolved.enableRequested; verification.running now reports the workflow's observed remote state instead of mirroring whether --enable was requested.
Chat message reply (#1210) — allows personal and bot quoted replies in ordinary groups when conversation metadata omits convThreadEnabled, using the matching group search channel=false as positive evidence while continuing to block topic-circle targets.
DING failure handling and resource identity — stop when robot credentials are missing or the selected robot is invalid, and preserve source message IDs separately from DING IDs. Recall accepts opaque server-returned DING IDs without guessing resource type from their prefixes; callers check identity provenance in the receipt.
Whiteboard verification and recovery — validate connector payloads locally, normalize numeric coordinate comparisons, return compact successful update receipts, and preserve committed-write evidence on readback failure without recommending duplicate append operations.
DING and Whiteboard guidance — align mono/multi references, clarify product ownership, and reduce redundant discovery and readback without dropping business information.
Drive download concurrent-writer safety — dws drive download and dws drive download-version no longer risk publishing corrupted mixed content when two processes download to the same target concurrently. Streamed (non-ranged) downloads now write to a uniquely created temp file in the target directory instead of the shared <target>.dwspart, so concurrent writers can no longer truncate each other. Ranged/resume downloads keep the fixed .dwspart path (required for checkpoint reuse) and take a cross-process lock (<target>.dwspart.lock): a second concurrent writer fails fast with holder diagnostics (pid/host/start time) instead of interleaving writes; the atomic no-replace publish still guards the final target either way.
Drive shortcut verification — adds bounded automatic pagination for list, search, and recent results, preserves existing data fields alongside unified pagination metadata, identifies pagination failures by their actual operation, rejects metadata-only statistics, and preserves committed resource evidence when create or upload read-back names differ.
Qoder Stream replies (#1217) — sends Qoder CLI user messages as typed text-content blocks and surfaces errors[] from failed stream results, preventing successful DingTalk delivery from degrading into “本地 agent 无文本输出”.
Drive and Wiki shortcut verification — supports workspace-targeted file uploads and strengthens space-type, pagination, node create/copy/move, and imported-name evidence.
Workspace uploads now include the final file name and size in the initial credential request so upload-specific authorization can reject the operation before any file bytes are transferred.
Nothing published for this version
Static MCP development and invocation — moves MCP authoring under dws dev mcp and adds reviewed dws mcp published commands for inspecting and invoking
Static MCP development and invocation — moves MCP authoring under dws dev mcp and adds reviewed dws mcp published commands for inspecting and invoking published tools without dynamic command injection or credential-bearing endpoint caches.
DingTalk task personal lifecycle events — adds personal Stream subscriptions for task creation, updates, and deletion, with catalog discovery for task events, validated creator/executor/participant role filters, typed flattened payloads, multi-event consumption, and documented DWS-to-task HSF backend routing.
VoIP call invite events — adds user_voip_call_receive_invite support to dws event consume, including event discovery, Schema, validation, flattened NDJSON output, and mono/multi Skill guidance.
v1.0.61-beta.3 Pre-release
Pre-release
Compare
Nothing published for this version
Nothing published for this version
Nothing published for this version
Chat emotion favorite local image (#85955640) — dws chat emotion favorite now accepts --file-path for a local image (jpg/jpeg/png/gif/webp/bmp, up to
Chat emotion favorite local image (#85955640) — dws chat emotion favorite now accepts --file-path for a local image (jpg/jpeg/png/gif/webp/bmp, up to 10MB) as an alternative to --media-id; the CLI validates the file locally, uploads it through dingtalk-file/upload_media (bizType=chat_emoticon), and reuses the existing favorite flow with the returned mediaId (mediaIdV1 preferred, falling back to mediaIdV2). --media-id behavior is unchanged.
Contact label management — adds dws contact label update, dws contact label delete, dws contact label add-members, dws contact label remove-members, and dws contact label update-member-scope to modify, delete, add/remove members, and adjust member scope for contact labels (roles). Also updates dws contact label create to require an explicit --type role|group: --type role requires --parent-id with a real label group ID; --type group creates a root-level label group and must omit --parent-id (the CLI passes parentId=-1).
Contact custom field management — adds dws contact ext-field create, dws contact ext-field update, and dws contact ext-field delete to manage organization custom employee fields (add_org_ext_attrs, update_org_ext_attrs, remove_org_ext_attrs).
Beta shortcut response contracts (#1167) — fixes HRbrain talent-pool business-page parsing and Mail template draft-mode input, while keeping OA form listing and other incompletely proven operations fail-closed.
Doc output compatibility — preserves the empty pagination failure ledger and lets completed import recovery report an unverified result when the original target is unavailable.
Markdown routing and diff guidance — makes markdown create --folder
detect the Drive or Doc destination before upload, clarifies markdown diff
parameter validation, and improves mono/multi Agent routing.
Chat message list result fields — keeps result.messages[] aligned with the top-level messages[], including the stable messageId used by edit and recall, while preserving legacy message fields.
v1.0.61-beta.2 Pre-release
Pre-release
Compare
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Chat Thread — adds chat thread promote to upgrade an existing group message into a Thread root message.
Chat Thread — adds chat thread promote to upgrade an existing group message into a Thread root message.
Sheet batch operations — expands sheet batch-update from 16 to 39 CLI operations, adds strict validation for the new P0/P1 inputs, preserves server-generated create IDs in results[].data, and JSON-encodes translated operations locally so nested number/boolean values survive the MCP transport.
Sheet batch dimension coordinates — makes delete-dimension and move-dimension accept the same public coordinates as their standalone commands (1-based row numbers or column letters) and translates them locally to the batch API's 0-based indexes.
Sheet CSV type control — adds sheet csv-put --auto-convert=false (and the matching batch input) to preserve every non-formula CSV field as text while keeping fields beginning with = as formulas.
Attendance schedule date ranges (#1154) — sends attendance schedule get
date ranges as upstream datetime strings, expands date-only inputs to full-day
boundaries, and rejects reversed ranges before calling the service.
Login with unreadable token slots (#1172) — after a fresh OAuth, device, PAT, or --token login, legacy global, identity, and organization token slots whose ciphertext no longer decrypts with the current data-encryption key are removed so the new credential can be persisted instead of stranding a completed login at the write preflight.
Windows Skill installation (#1177) — stops the PowerShell installer from
rejecting a correct multi/mono Skill publication when the staged copy and the
destination carry different inherited Windows ACLs, and makes the transaction
record its published paths before verifying them so a failed publication is
rolled back instead of leaving the original Skill stranded in
~/.dws/skill-backups.
Error-to-doctor recovery guidance — links authentication and network
failures to the executable dws doctor human entry or dws doctor --json
Agent entry across legacy JSON, unified-envelope, shortcut, and multi-profile
errors, while keeping permission, validation, confirmation, and upstream
business errors on their more specific recovery paths.
v1.0.61-beta.1 Pre-release
Pre-release
Compare
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
The existing create and list leaves retain their legacy behavior and output contract with deprecation guidance for an explicit migration.
This release promotes the sealed v1.0.60-beta.3 contents to stable.
Document, Drive, and Sheet workflows — adds Drive quota, task polling,
export, permission, comment, public-link, history-version, revision, floating
image, and delegated-access workflows; hardens document import, large
Markdown writes, download handling, and readback verification.
Collaboration and automation commands — adds dedicated Chat Thread
commands, AITable datasource management, Agoal scorecard search, OA approval
attachment upload, and reviewed Whiteboard workflows.
Agent-safe CLI contracts (#1161) — publishes stricter pagination, result,
confirmation, routing, and error contracts across report, Sheet, Minutes,
AiSearch, Contact, Task, Wiki, and document commands, plus reviewed argument
aliases for Agoal, DevApp, AITable, and Chat shortcuts.
DWS OpenAPI escape hatch — supports file-backed parameters and request
bodies, multipart uploads, pagination, and bounded binary downloads while
tightening redirect, credential-pair, Keychain migration, and error-handling
behavior.
Supported command surface — removes the retired Education and College
vendor extensions and improves command typo guidance, fork admission, and
Reviewer Router merge recovery without weakening protected-main checks.
v1.0.60-beta.3Drive local-file comments (#1151) — adds the complete global comment
lifecycle for Drive files through the shared document comment service,
including create-v2, list-v2, reply, update, delete, batch query,
direct-reply listing, resolve, restore, and reaction replies. The existing
create and list leaves retain their legacy behavior and output contract
with deprecation guidance for an explicit migration.
Markdown comment reads (#1151) — adds comment listing for native Markdown
files with global, inline, resolution-status, and cursor filters, and exposes
direct-reply listing across the shared Doc and Sheet comment lifecycle.
Chat Thread commands — adds thirteen chat thread leaves for topic-circle creation, Thread publishing, reading, replying, forwarding, recall, emoji reactions, and text emotions. Parameters keep the original chat group / chat message names, including --conversation-id, --topic-id, and the existing forward flags.
Doc-business delegation auth — the drive, doc, sheet, wiki, and markdown command groups now accept a persistent --principal-user-id flag. When set, the first invocation of each doc-business tool key per node within a session is gated by a check_capability verification on behalf of the principal; granting the capability is an out-of-band action the principal completes on the server side, and the CLI never calls grant_capability. A denied check surfaces the server's denial message and blocks the original call.
Dry-run consistency — checkCapability now executes in dry-run mode as well, ensuring preview and execution behaviors are consistent. In dry-run, the check routes through the ReadTool channel (real network request) instead of CallTool (which would go through EchoRunner and always deny).
Dry-run pre-check in helpers — dry-run mode now invokes the delegation auth validator before rendering the preview, ensuring commands that would be denied at execution time are also blocked at preview time.
Local rejection for node-less commands — commands that lack a node identifier (e.g. search/list/create without nodeId) now return a clear client-side error (DELEGATION_AUTH_NOT_SUPPORTED, exit code 3) when --principal-user-id is set, instead of forwarding an incomplete request to the server.
Concurrency safety — the per-session checked map in the delegation auth decorator is now protected by a sync.Mutex, preventing data races under concurrent tool invocations.
Markdown dry-run parity — the markdown fetch/create/overwrite/patch/diff commands now run the same check_capability delegation gate on their dry-run previews as doc/drive do; a dry-run combined with --principal-user-id is verified against the command's real first delegated call before any preview is rendered, and a denied principal blocks the preview.
sheetId at the top level while preserving legacy .result.nodeId and outer requestId, avoids repeating the sheet-list probe, keeps the main-compatible single readback check, and reports post-create partial/unknown state without unsafe whole-workflow retries.Minutes pagination results (#1112) — publishes list, search, and transcript continuation and exhaustion evidence through the unified meta.pagination envelope, while keeping business-scope completeness separate from endpoint exhaustion.
Chat Thread create result — returns the created group's openConversationId and omits internal openCid / cid fields, matching chat group create --thread.
Doc agent routing and import defaults — aligns document and drive Skill
guidance with the executable CLI contract, preserves structured heading and
attachment routes, publishes required shortcut arguments, and resolves the
current profile's default document target before an import is submitted.
Reviewer Router preflight — defers App-owned merge attempts while GitHub reports transiently unknown mergeability, avoiding false reconciliation failures without weakening approval or required-check enforcement.
Drive sync batch 2 ( #1086 ) — Five synchronized enhancements aligned with closed-source MR 28427926 / 28769810 / 28967420 / 28972632:
drive quota queries enterprise storage (org/app/space levels); drive quota apps lists application storage usage with pagination and sortingdrive task get --type <export|import|copy|move> --id <taskId> queries async task status via query_task (drive MCP); drive copy/move now auto-poll query_task when server returns taskId and print normalized TaskResult JSON on completion--async mode; drive export get queries export task statusdrive publish set accepts --password (4-char alphanumeric, empty to clear) and --expire-days (N=days, 0=permanent); client-side validation of --permission/--password/--expire-days runs before the confirmation gateskills/mono/references/products/doc/doc-whiteboard.md documenting whiteboard card insertion, deletion, and post-insert verification workflowDownload host trust policy — retires the static DingTalk/OSS download
host allowlist, the dial-time public-IP refusal, and the IP-literal
refusal from both the shared local download path (drive +download,
drive +version-download, doc/minutes artifact downloads) and the chat
message-resource path (chat +messages-resource-download,
--download-resources). Download URLs only require HTTPS without userinfo
and accept non-default HTTPS ports, because every dimension of a
dedicated-deployment storage endpoint — custom domain, port, and network
location — is decided by the customer deployment and cannot be enumerated
or configured client-side. Verified on a dedicated deployment whose
storage domain resolves to a customer-intranet address. Downloads align
with the official GUI client, which applies no client-side SSRF
interception: download URLs only ever come from authenticated service
responses (no command accepts a user-supplied URL), TLS hostname
verification pins the connection to the requested host, redirects are
re-validated per hop, and service credential headers are stripped once a
redirect leaves the original origin.
Upload host trust unchanged — upload target URLs (drive +upload,
minutes audio upload) keep the pre-existing public DingTalk/OSS trusted
host requirement through a dedicated upload validator, so removing the
download allowlist does not widen where local file bytes can be sent;
the validator also keeps the pre-existing default-port-only HTTPS rule
(DingTalk/OSS upload endpoints always serve on 443, so non-default ports
accepted for dedicated-deployment downloads stay anomalous for uploads).
Download credential headers are issued together with the download URL by
the same authenticated service response and follow it as-is on the first
request; redirects leaving the original host still strip them.
report entry submit requires recipients — dws report entry submit(及废弃别名 dws report create)的 --to-user-ids 从可选提升为必填:无接收人的日志提交在服务端仍返回成功,但日志对任何接收人都不可见。openAPI create_report 的 toUserIds 参数保持可选不动,规则仅在 dws CLI 侧收紧——Cobra required 拦截未传场景,RunE 内对空值/纯分隔符(如 --to-user-ids ",")同样 fail-closed 拒绝。修复 #85724185。
dws edu-contact, dws edu-group, dws edu-app, dws edu-familygroup, and dws college-contact from the CLI, Schema, bundled Skills, and open-edition MCP endpoint registry. Future DWS packages no longer expose these five command surfaces.Pull request CI scheduling — stops metadata-only auto-merge enable and disable events from restarting the complete admission graph for an unchanged commit, while the base-owned Reviewer Router continues to enforce merge authority.
Command typo guidance — returns a validation error with up to three nearest command suggestions and the parent --help entry instead of printing the full command list.
Document shortcut reliability — adds bounded pagination for document and template listings, supports verified paragraph or heading insertion before a reference block, tolerates service-only Markdown layout normalization during write verification, and resolves and verifies the default “My Documents” import target.
Fork pull-request admission — keeps the read-only Reviewer Router identity check fail-closed while allowing external contributors' CI to use the reviewed public App slug when GitHub withholds repository variables.
Markdown append chunking rewritten around safe split positions — long markdown is now split so that every chunk is a complete, self-contained top-level block sequence, which is what update_document mode=append requires: the server inserts a brand new structure per call and cannot continue the previous one. Split points are chosen strictly by how much they change the rendered document — fully safe boundaries (blank lines, block starts that interrupt a paragraph) before boundaries that need repair (a table's rows now carry a re-emitted header and delimiter row; a fenced code block is closed and reopened with its original marker and info string) before boundaries that merely restructure (long paragraphs, list items) before a hard character cut. Within a tier the latest boundary in the window wins, since all chunks land in the same document. Every boundary that changes the rendered structure is reported in a new degradations field instead of being applied silently.
Fixed markdown chunking dropping a newline — the previous splitter rebuilt block text from lines and lost one \n whenever the content's last line began a heading, table or code fence, so "para\n# Title" was written as "para# Title" and the heading stopped being a heading. Roughly one in five randomly generated documents was affected. The new splitter slices by offset and never rebuilds text, making content preservation structural.
Fixed oversized tables and code blocks being cut mid-cell and mid-fence — the hard-split path never received the block type, so it cut at arbitrary character boundaries despite claiming to preserve table and code block integrity.
Fixed readback verification comparing against content the server never receives — doc +create / doc +update verified the readback against the raw input, so any repaired boundary (and, previously, any paragraph split) failed verification on large documents. Verification now compares against the document the chunk plan says the server should hold.
Unified four markdown write paths onto one splitter — doc create / doc update, doc +create / doc +update and doc +checkpoint-update now share helpers.SplitMarkdownForAppend and one limit constant (30000 runes), replacing two independent implementations plus one path that never chunked at all. doc +checkpoint-update accepts @file and stdin content, so oversized input was reachable there while the equivalent doc +update chunked. doc +doc-append takes --text from argv only and now rejects oversized input with a pointer to doc +update rather than sending one oversized call.
doc update --index now fails closed when the content requires chunking — each chunk creates an unpredictable number of blocks, so the insertion point for later chunks is unknowable; the flag was previously accepted and silently ignored.
Reviewer Router recovery — keeps exact App-owned PRs that are behind main retriable when GitHub reports the protected merge denial as Resource not accessible by integration, while preserving every other 403 as a hard failure.
Reviewer Router merge authority — moves fail-closed writer-rule and auto-merge ownership validation into the trusted base-owned Router before App credentials are read, preparing metadata-only auto-merge changes to stop restarting the full CI suite without weakening protected-main admission or exact-SHA cache production.
Reviewer Router merge recovery — retries exact App-owned merge intents through a SHA-bound synchronous merge after GitHub has enforced approval and nine GitHub Actions source-bound required checks.
dws api <METHOD> <PATH> command, five HTTP methods, flags and defaults, App Token cache, new/legacy host token injection, raw successful JSON, and paginated page arrays. Adds --params/--data @file, single-file streaming --file [field=]path multipart requests, camelCase pagination fields, and official open.dingtalk.com/llms.txt discovery guidance in the misc and mono Skills. Resolves Client ID and Client Secret only as a complete flag, environment, or app-config pair; one-shot Raw API flag/environment credentials remain ephemeral, while successful custom-app OAuth login persists its exact pair. Migrates plaintext and legacy client-secret:<clientID> values to appsecret:<clientID> after the canonical reference is durably stored, and fails closed on conflicting values. Dry-run no longer requires credentials and still performs no Keychain, deferred-file, or network access. Pagination now fails closed instead of returning partial pages, and rejects ambiguous continuation request keys. Non-2xx OpenAPI errors expose top-level code and request ID details without treating a successful payload's business code field as an error. Security tightening rejects HTTP, non-443 ports, cross-origin or HTTPS-downgrade redirects, sanitizes server-provided download filenames, bounds JSON/error bodies, and atomically streams binary downloads through a temporary file.v1.0.60-beta.3 Pre-release
Pre-release
Compare
Drive permission get-setting ( #1056 ) — adds dws drive permission get-setting --node <ID> to inspect a document-space node's permission settings (per
Drive permission get-setting (#1056) — adds dws drive permission get-setting --node <ID> to inspect a document-space node's permission settings (permission mode, share scope, and permission policies) in one call.
Whiteboard shortcuts (#1082) — adds strict query and confirmed update workflows with stable-target receipts and exact readback verification.
Sheet shortcut hardening (#1082) — makes worksheet listing and cell-range reads fail closed on malformed, ambiguous, or truncated responses, publishes a closed reviewed output shape, and preserves non-executing --dry-run previews for range reads.
Permission and member list pagination (#1085) — drive/doc permission list and wiki member list now accept --next-token to follow the
server-side cursor (output carries totalCount/hasMore/nextToken) and
map --limit to pageSize capped at 50 instead of the rejected maxResults 200 path; permission add/update/remove and wiki member add/update/remove
additionally accept a --members JSON array covering USER/DEPT/CONVERSATION/TAG
grantee types. The optional --notify defaults to false and is omitted from
the server request unless passed explicitly, so member grants no longer notify
recipients by default. These commands also declare cursor pagination
(next-token) in the Agent schema contract, mirroring the internal CLI parity
change. Because a single batch remove can revoke access for up to 30
USER/DEPT/CONVERSATION/TAG members — where departments, chats, and role
groups can indirectly affect many more users — drive/doc permission remove and wiki member remove now declare
confirmation=user_required and gate the actual tool call behind user
confirmation (--yes, an interactive yes, or --dry-run preview); their
confirmation-gate failure now also passes through verbatim instead of being
reclassified as a permission-denied or unclassified error.
Agoal scorecard search-entities — dws agoal scorecard search-entities searches scorecard metrics and key items by keyword, returning matching entity info (scorecard ID, entity ID, entity type, title, owning team) with optional --page/--page-size pagination.
AITable datasource shortcuts — adds 7 shortcuts for datasource sync management (+datasource-create, +datasource-update, +datasource-sync, +datasource-sync-status, +datasource-get-config, +datasource-list-sources, +datasource-get-fields) and updates the dingtalk-aitable skill with routing rules and a new aitable-datasource.md reference guide.
Doc public-link and historical-version reads — dws doc read forwards
the reviewed password (internet-public documents with password protection)
and historyVersion (read content as of a listed historical version; 0
denotes the document's initial version) parameters on the markdown, JSONML,
and scope read paths via --password / --version; dws doc +fetch gains
--password and --version with the same historyVersion forwarding, while
--revision stays rejected with explicit guidance: revision is the document
edit revision returned by JSONML reads for +update --expected-revision
conditional writes, not a historical version number.
Edu & College vendor extensions — adds five hidden vendor extension commands for education scenarios: dws edu-contact (school/class/family/teacher contact management), dws edu-group (student/class group lifecycle), dws edu-app (homework, notices, report cards, diplomas, class circles), dws edu-familygroup (family group management, child binding, app permissions), and dws college-contact (university dept/employee/alumni/graduate management). All route to dedicated MCP servers via callMCPToolOnServer.
OA approval attachment upload — dws oa approval attachment upload --file <path> uploads a local file as an approval attachment in one command: it initializes the upload credential (MCP oa/init_attachment_upload_info), HTTP PUTs the file to OSS, then commits it (MCP oa/commit_attachment_upload_info). --file-name defaults to the file's base name and --md5 is auto-computed when omitted.
Sheet revision changesets — adds read-only commands for querying the current workbook revision and reviewing Agent-readable changes between revisions, with guidance for distinguishing revisions from saved history versions and safely selecting rollback targets.
Sheet floating images — supports creating or replacing a floating image directly from a local file with create-float-image --file and update-float-image --file, while retaining the existing --src workflow.
AiSearch and Contact shortcuts (#1083) — adds strict people search and reviewed unified results; people results must use the live-reviewed person source, and exact mobile lookups normalize accepted formatting before calling the dedicated mobile interface. Agent/public discovery keeps contact +list-roles, contact +list-roster-fields, contact +get-roster, and incomplete Live routes unavailable rather than publishing ambiguous results, while the historical Contact CLI commands retain legacy MCP execution and real error propagation. The legacy role-list projection preserves the service's reviewed null placeholder without exposing that ambiguous row through Agent Result contracts.
Permission error guidance and error rendering (#1085) —
permission-denied responses now exit with the AUTH_PERMISSION_DENIED code
instead of a generic business-error rendering; document/wiki-specific errors
(the drive-specific codes forbidden.accessDenied / forbidden.no.auth,
or the role-threshold wording like
“需要您具备 MANAGER 及以上角色”) carry apply-permission guidance
(dws drive permission apply-info / dws drive permission apply), while
permission failures carrying only generic code names (FORBIDDEN,
NO_PERMISSION — also returned by attendance and event-subscription tools)
or other products' wording keep their product-specific or
product-neutral suggestion instead of a misleading document-permission hint;
member-validation failures such as
“用户不存在/不属于当前组织” are classified as tool errors with a
--members-with-corpId suggestion instead of a misleading
resource-not-found error; business error output now surfaces the backend
message with code/logId appended for traceability; and the
update_permission / remove_permission / update_member /
remove_member tools — whose servers return a literal null on successful
no-payload writes — now render {} so downstream JSON consumers do not fail
parsing null; other tools keep raw null output unchanged.
v1.0.60-beta.2 Pre-release
Pre-release
Compare
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
OA, DING, and Report shortcuts — hardens response, identity, pagination, and confirmation contracts; publishes verified form search, receiver status,
OA, DING, and Report shortcuts — hardens response, identity, pagination, and confirmation contracts; publishes verified form search, receiver status, and report read workflows while withholding shortcuts that lack trustworthy downstream evidence.
Stable release sealing — directly preparing a stable release now renders and archives release fragments merged after its beta baseline, avoiding a forced extra beta solely to consume pending notes.
Calendar empty windows (#1074) — returns a legitimate empty result when the service emits its exact exhausted empty-event sentinel.
Task update verification (#1074) — compares due-time readback as exact milliseconds so committed updates are no longer reported as failures.
Comment reaction validation (#1074) — narrows accepted reaction input to reviewed DingTalk emoji names and rejects Unicode emoji and unsupported names such as like and heart before the RPC.
OAuth refresh falls back to the organization mirror — when the server rejects the
current identity's refresh_token with the reviewed invalidParameter.authCode.notFound
business code, dws now retries once with the still-valid token mirrored in the same
organization's slot (same corp, matching or backfilled user identity) before giving up,
and writes the rotated credential back to both the identity and the organization slots so
the fallback stays usable on later refreshes. Transient failures and direct-mode HTTP
rejections without a reviewed business code do not trigger the fallback.
v1.0.60-beta.1 Pre-release
Pre-release
Compare
Your coding agent can read these notes before it upgrades. Set up the MCP server →