Skip to content

mcp: widen ability_list sanitizer regex to match WP Abilities API ID grammar #218

Description

@pluginslab

From the v0.12.0 MCP endpoint security review (PR #216, finding [Low #6]).

`Settings::update_field()` for the `ability_list` type validates each entry against `^[a-z0-9-]+/[a-z0-9-]+$`. The WP Abilities API itself doesn't strictly constrain ability IDs to that grammar — names like `MyPlugin/list_orders` or `woo/Get-Product` could be valid registrations.

Today, a third-party ability with such a name cannot be allowlisted — the admin ticks the box, hits save, and the sanitizer silently drops it with no UI feedback.

Fix:

  1. Confirm the actual WP 6.9 Abilities API ID grammar (check core source / docs).
  2. Widen the regex accordingly. Still exclude null bytes, slashes (other than the single separator), control chars.
  3. Optional UX: surface a warning toast when an entry is dropped by the sanitizer.

Not a security issue (fails closed), but a correctness gap.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestphpPHP backend work

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions