v1.1.1
Released September 21, 2026. This patch fixes existing routing, authentication and WooCommerce behavior.
Fixes
- Response caching and both idempotency middleware isolate namespaces, concrete request paths and URL parameters, even when query/body fields shadow URL IDs.
- JWT, Bearer and Application Password middleware restore the previous native WordPress user after downstream execution, including exceptions. Unmapped tokens run as native user
0; shared auth fields no longer retain stale outer identities. - Woo order writes initialize gateways, calculate taxes/totals before the requested status transition, recalculate address-only updates and avoid repeated payment completion for already-paid updates.
- Order and stock quantities preserve fractions supported by Woo's stock normalizer; values that would be changed are rejected before persistence. OpenAPI quantity types match this behavior.
Migration required
Read Upgrade to 1.1.1 before deployment. Default idempotency records from earlier versions are not replayed under the new key scheme. Coordinate writers and retries across deployment and rollback; waiting for TTL alone is insufficient. No new table schema is required from 1.1.0.
Authentication remains scoped to the middleware pipeline: later WordPress response filters and _embed processing use the restored caller. Address-only order changes can affect totals, including paid orders.
No Store API, cart, checkout or refund endpoints were added. Your application's REST namespace and OpenAPI version remain under your control.