Skip to content

fix: address WP.org T4 review items (#228) - #230

Merged
pluginslab merged 1 commit into
mainfrom
fix/228-wporg-t4-closeout
Aug 23, 2026
Merged

pluginslab merged 1 commit into
mainfrom
fix/228-wporg-t4-closeout

Conversation

@ivdimova

Copy link
Copy Markdown
Collaborator

Addresses the two concrete code changes flagged in WP.org review R agentic-admin/schmitzoide/1Jun26/T4, tracked in #228.

Changes

  • uploads-scan.php — resolve the .well-known scan path via get_home_path() instead of ABSPATH. On subdirectory installs the site root (document root, where .well-known lives) differs from the WordPress core directory, so ABSPATH . '.well-known' scanned the wrong place. Guards the wp-admin/includes/file.php require so get_home_path() is available in the ability's REST load path.
  • vector-store.js — pin the Transformers.js jsDelivr URL to @3.8.1 (was floating @3). Now matches indexing-worker.js and makes the existing readme changelog claim accurate; a privacy-first plugin should not depend on a CDN range that can ship new code without a deliberate bump.

Not in this PR (decisions in #228)

  • The remote-loading answer (item 1) is a reply to the reviewer, not a code change — the feature is kept to avoid breaking functionality; the pin above strengthens the "static, deliberate asset" position.
  • voy .module.wasm (item 2) — keeping the upstream reference for now; vendoring is the fallback if a T5 pushes back.

Verification

  • composer lint / wp-scripts lint-js clean on both files
  • npm run build compiles
  • Version stays at 0.11.0 (submission is pinned there)

Part of #228.

🤖 Generated with Claude Code

Two concrete code changes flagged in review R agentic-admin/schmitzoide/1Jun26/T4:

- uploads-scan.php: resolve .well-known via get_home_path() instead of
  ABSPATH, which is wrong on subdirectory installs where the site root
  (document root) differs from the WordPress core directory. Guards the
  wp-admin/includes/file.php require so get_home_path() is available in
  the ability's REST load path.

- vector-store.js: pin the Transformers.js jsDelivr URL to @3.8.1 (was
  floating @3). Matches indexing-worker.js and makes the readme changelog
  claim accurate — a privacy-first plugin should not depend on a CDN range
  that can ship new code without a deliberate bump.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@pluginslab

Copy link
Copy Markdown
Owner

This is exactly the two code items on the #228 plan, thanks for picking it up.

Both changes check out against the tree:

  • The guarded require_once of wp-admin/includes/file.php is the right call. get_home_path() is not loaded on the REST path, so the ability would fatal without it.
  • readme.txt:57 and :109 already claimed the @3.8.1 pin while vector-store.js was still on floating @3. This closes that gap rather than making a new claim, so the changelog is now accurate.

Version correctly left at 0.11.0.

Agreed on parking the two decisions. I have put notes on both in #228, including the drafted reviewer reply, so they stay with the submission history: the remote-loading answer needs a framing change before it goes out, and the voy vendoring question is still open.

Reminder for whoever merges: this does not go to the reviewer on its own. Zip upload and reply together, per the definition of done in #228.

@pluginslab pluginslab left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verified against the tree. Both changes are correct and CI is green. Merging as step one of the #228 closeout.

@pluginslab
pluginslab merged commit e3f083a into main Aug 23, 2026
4 checks passed
@pluginslab
pluginslab deleted the fix/228-wporg-t4-closeout branch August 23, 2026 12:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants