Skip to content

WP.org review compliance + AI connector fixes - #227

Merged
pluginslab merged 5 commits into
mainfrom
fix/wporg-prereview-debrand-and-prefix-rename
Aug 1, 2026
Merged

pluginslab merged 5 commits into
mainfrom
fix/wporg-prereview-debrand-and-prefix-rename

Conversation

@pluginslab

Copy link
Copy Markdown
Owner

Clears the WordPress.org plugin-directory review (multiple rounds) and fixes pre-existing AI Connector bugs found while testing.

WP.org review fixes

  • Ownership/de-brand: individual submission as Marcel Schmitz (schmitzoide), not Pluginslab. Author/Contributors/URIs updated.
  • Prefix: dropped the reserved wp prefix everywhere (AGENTIC_ADMIN_*, namespace AgenticAdmin, JS global agenticAdmin, ability IDs + REST namespace agentic-admin/*). Main file renamed to agentic-admin.php.
  • Trialware (Guideline 5): removed the AGENTIC_ADMIN_ENABLE_LABS gate; deleted write-file + content-generate; promoted discover-plugin-abilities + run-plugin-ability to core so the third-party Plugin Abilities platform ships fully enabled.
  • Unsafe SQL: removed query-database (LLM-authored arbitrary SQL).
  • cURL: dropped the curl SSE path in the LLM proxy; WP HTTP API only.
  • Direct file access: service worker now served via admin-post.php (WordPress loaded); sw-loader.php deleted.
  • Prefixes/paths: stray wpaa_ → agentic_admin_; WPMU_PLUGIN_DIR/WPINC instead of hardcoded paths.
  • Misc: Plugin URI → GitHub repo, NVD terms URL fix, admin menu position 3 → null, source/build documented in readme.
  • Remote loading ([Ability] disk-usage — Check wp-content disk usage #7): Transformers.js (KB embeddings) stays a documented opt-in CDN service — bundling it pulls an ONNX runtime that does not bundle cleanly.

AI Connector fixes (pre-existing bugs)

  • is_connected and the chat "configured" gate used AiClient isProviderConfigured(), which is non-deterministic — caused "No AI Connectors configured yet" and spurious 400s even with a valid key. Replaced with a deterministic credential-presence check.
  • Surface WP 7.0's connector-approval gate as an actionable message pointing to Tools → AI Connector Approval instead of a raw network error.

Verification

composer lint 0, lint-js 0, 91 unit tests pass, production build OK. Anthropic connector verified end-to-end on a local WP 7.0 instance.

🤖 Generated with Claude Code

pluginslab and others added 3 commits May 29, 2026 13:31
Address the WordPress.org plugin directory pre-review for "agentic-admin".

Ownership: submit as an individual (Author "Marcel Schmitz", Contributors
"schmitzoide", Author URI to the WP.org profile) instead of the "Pluginslab"
entity, so no trademark/domain ownership check applies.

Prefix: drop the "wp" prefix flagged as reserved/common. Constants
WP_AGENTIC_ADMIN_* -> AGENTIC_ADMIN_*, namespace/class WPAgenticAdmin ->
AgenticAdmin, JS global wpAgenticAdmin -> agenticAdmin, ability IDs and REST
namespace wp-agentic-admin/* -> agentic-admin/*, CSS classes, phpcs prefix
allow-list, and the webpack chunk global (package.json name -> agentic-admin).
Main file renamed wp-agentic-admin.php -> agentic-admin.php to match the slug;
.distpackage and Playground blueprints updated.

Other flagged items: Plugin URI 404 -> GitHub repo; NVD terms URL
/general/ -> /developers/terms-of-use; admin menu position 3 -> null (appended
to bottom). sw-loader.php direct access left intentional (documented).

Verified: 96 unit tests pass, production build OK, composer lint exit 0,
lint-js 0 errors. Version stays 0.11.0 (submission was pended, not published).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
WordPress.org plugin review (manual pass) plus AI Connector bug fixes.

Review fixes:
- Trialware (Guideline 5): remove the LABS opt-in gate; delete write-file and
  content-generate abilities; promote discover/run-plugin-ability to core so the
  third-party Plugin Abilities platform ships fully enabled.
- Unsafe SQL: remove the query-database ability (LLM-authored arbitrary SQL).
- cURL: drop the curl SSE path in the LLM proxy; use the WP HTTP API only.
- Direct file access: serve the service worker through admin-post.php (WordPress
  loaded) and delete sw-loader.php.
- Generic prefixes: rename the stray wpaa_ transient and error codes to
  agentic_admin_.
- File locations: use WPMU_PLUGIN_DIR and WPINC instead of hardcoded paths; the
  remaining ABSPATH/WP_PLUGIN_DIR uses are read-only core/plugin scans.
- Source/build: document the voy-search wasm and build steps in the readme. The
  Transformers.js embedding library stays a documented opt-in CDN service
  (bundling it pulls in an ONNX runtime that does not bundle cleanly).

AI Connector fixes (pre-existing bugs):
- is_connected and the chat "configured" check used AiClient
  isProviderConfigured(), which is non-deterministic and made the connector list
  flap to "none configured" and return spurious 400s. Replaced with a
  deterministic credential-presence check.
- Surface WP 7.0's connector-approval gate as an actionable message pointing to
  Tools -> AI Connector Approval instead of a raw network error.

Verified: composer lint 0, lint-js 0, 91 unit tests pass.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
The inline plugin activate/deactivate buttons (ActionButton + INVERSE_ACTIONS in
MessageItem) were fed only by the content-generate auto-insert path, which was
removed during the WP.org trialware cleanup. Nothing populated message.actions
anymore, leaving stateless dead buttons. Remove ActionButton, the inverse-action
map, the messageActions rendering, and the now-unused onAction plumbing
(MessageList, ChatContainer handleAction + toolRegistry/executeAbility imports).
Plugins are still activated/deactivated via natural language.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

@ivdimova ivdimova left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review

Overall this is a well-reasoned PR — the connector bug fix and WP.org compliance work are solid. A few things to address before merging:


🔴 Settings data loss on upgrade

ARCHITECTURE.md notes the settings option key changes from wp_agentic_admin_settings → agentic_admin_settings, but there is no migration in activate(). Existing users who upgrade will silently lose all saved settings (model selection, endpoint URL, API keys, etc.).

Needs a migration in activate():

$old = get_option( 'wp_agentic_admin_settings' );
if ( $old && ! get_option( 'agentic_admin_settings' ) ) {
    update_option( 'agentic_admin_settings', $old );
}

🟡 Broken indentation in class-llm-proxy.php — proxy_streaming()

After removing the cURL block the remaining code has inconsistent indentation — if ( \is_wp_error( $response ) ) is at 1 tab instead of 2, and flush() is over-indented. The PR description says composer lint passed; worth re-running against this file specifically since WPCS can miss whitespace-only diffs in some configurations.


🟡 Broken repo URLs in docs

Several docs were updated to reference pluginslab/agentic-admin but the GitHub repo is still pluginslab/wp-agentic-admin:

  • ONBOARDING.md: git clone https://github.com/pluginslab/agentic-admin.git → 404
  • README.md: Playground badge URL → pluginslab/agentic-admin/main/.playground/blueprint.json → badge broken

These should stay as pluginslab/wp-agentic-admin until the repo is actually renamed on GitHub.


✅ What looks good

  • is_connector_configured() is a clean fix — deterministic credential-presence check, well-commented rationale for replacing isProviderConfigured()
  • WP 7.0 approval gate: catching "not been approved" and returning a 403 with approval_url in the error body is great UX
  • admin_post_agentic_admin_sw + admin_post_nopriv_agentic_admin_sw pair is correct — SW must be accessible to unauthenticated browser fetches
  • All WP_Error codes consistently renamed wpaa_* → agentic_admin_*
  • Rate limiter transient key renamed (wpaa_conn_rl_ → agentic_admin_conn_rl_)
  • discover-plugin-abilities and run-plugin-ability promoted to core (no longer behind the LABS gate)
  • phpcs.xml.dist correctly drops the legacy WP_AGENTIC_ADMIN and WPAgenticAdmin prefixes

Minor

.release-notes/0.11.0.md comparison table has a copy-paste typo — the "before" column for the function prefix row reads agentic_admin_ (blocked) instead of wp_agentic_admin_ (blocked).

Resolves the four points from @ivdimova's review:

- Settings data loss on upgrade: add idempotent maybe_migrate_settings()
  copying wp_agentic_admin_settings -> agentic_admin_settings (then drops
  the legacy key). Runs from both activate() and init() since the
  activation hook does not fire on WordPress.org auto-updates.
- Fix broken indentation in class-llm-proxy.php proxy_streaming() left
  behind after the cURL block was removed.
- Revert premature pluginslab/agentic-admin repo URLs back to
  pluginslab/wp-agentic-admin across 5 docs (repo not yet renamed).
- Fix function-prefix typo in .release-notes/0.11.0.md comparison table
  (before column: wp_agentic_admin_).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@pluginslab

Copy link
Copy Markdown
Owner Author

Thanks for the thorough review @ivdimova — all four addressed in 451ba2c.

🔴 Settings data loss on upgrade — added an idempotent maybe_migrate_settings() that copies wp_agentic_admin_settings → agentic_admin_settings and then drops the legacy key. One nuance on your suggested snippet: register_activation_hook doesn't fire on WordPress.org auto-updates, which is the exact upgrade path at risk — so it runs from both activate() and init(). It short-circuits cheaply after the first run (old option deleted; new option is autoloaded).

🟡 proxy_streaming() indentation — re-indented the leftover cURL-block body + ob_flush()/flush() to consistent 2-tab depth. (You were right that WPCS waved it through — composer lint still reports 0 errors on the file either way.)

🟡 Broken repo URLs — reverted pluginslab/agentic-admin → pluginslab/wp-agentic-admin. It was actually 5 files / 7 lines (README, ONBOARDING ×2, UI-AUDIT, debugging-development ×3), all fixed until the repo is actually renamed.

Minor — release-notes typo — fixed; the "before" column now reads wp_agentic_admin_ (blocked).

Re-requesting review when you have a moment 🙏

@pluginslab
pluginslab requested a review from ivdimova June 10, 2026 22:29

@ivdimova ivdimova left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All four points from the previous review are addressed — thank you for the quick turnaround. LGTM with one tiny nit.


✅ Settings migration

maybe_migrate_settings() looks correct. The false !== $old / false === get_option( 'agentic_admin_settings' ) guards are tight, the old key is deleted after migration so subsequent calls are a no-op, and running it from both activate() and init() correctly covers the WP.org auto-update path (where the activation hook doesn't fire). Good call.

✅ LLM proxy indentation

proxy_streaming() indentation is clean throughout now.

✅ Repo URLs and release notes typo

All reverted/fixed correctly across ONBOARDING.md, README.md, UI-AUDIT-WP-7.0.md, 12-debugging-development.md, and the release notes table.


Minor nit (docs only)

In both ONBOARDING.md and docs/ai-fundamentals/12-debugging-development.md the clone URL was correctly reverted to pluginslab/wp-agentic-admin, but the cd line immediately after was not updated:

git clone https://github.com/pluginslab/wp-agentic-admin.git
cd agentic-admin   # ← directory will be wp-agentic-admin after this clone

git clone creates a directory matching the repo name (wp-agentic-admin), so cd agentic-admin would fail. Should be cd wp-agentic-admin. Not a blocker for the WP.org submission but worth fixing before merge.

Address ivdimova review nit on PR #227 — git clone creates a
wp-agentic-admin directory, so the cd line must match.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@pluginslab
pluginslab merged commit d1d0108 into main Aug 1, 2026
4 checks passed
pluginslab added a commit that referenced this pull request Aug 1, 2026
window.wpAgenticLogLevel used the reserved `wp` prefix, the same class of
issue the Plugins Team flagged on 28 May for the wpAgenticAdmin localize
handle. The prefix rename in #227 missed it because it is set at runtime
rather than declared in PHP.

  window.wpAgenticLogLevel  ->  window.agenticAdminLogLevel

Also drops the redundant assignment before defineProperty, and clears the
last "WP Agentic" branding strings from the SW console label and the SCSS
headers, left over from the de-branding pass.

Refs #228, #229
pluginslab added a commit that referenced this pull request Aug 27, 2026
Audit before resubmission found the External services section describing
something the code does not do. Guideline 6 is the section under review,
so the disclosure has to match reality.

- CVE lookups were attributed to a `plugin-vulnerability-scan` ability
  that does not exist anywhere in the codebase. NVD and MITRE are called
  by `security-scan`, unconditionally, via
  agentic_admin_scan_for_vulnerabilities() at security-scan.php:149.
- `core.svn.wordpress.org` was undisclosed. verify-core-checksums.php:273
  fetches the original core file to build a diff when a checksum
  mismatches. Now documented, including that the checksum list itself
  comes from core's own get_core_checksums().
- Two absolute claims ("No admin data ever leaves your device", "no
  admin data are sent to any server unless you enable the external LLM
  provider") were contradicted by the section's own list a few
  paragraphs below. Reworded to separate AI inference, which really is
  local, from the public-data lookups a few abilities make.
- Dropped a changelog reference to sw-loader.php, removed in the same
  release by #227.

Verified: every host the code contacts is now disclosed, and every
ability named in the section exists.

Readme only, no code change.

Refs #228

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
@pluginslab
pluginslab deleted the fix/wporg-prereview-debrand-and-prefix-rename branch October 3, 2026 14:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants