Skip to content

fix: address WP.org review 30Aug26/4.2 (#228) - #236

Merged
pluginslab merged 1 commit into
mainfrom
fix/228-review-30aug
Sep 25, 2026
Merged

pluginslab merged 1 commit into
mainfrom
fix/228-review-30aug

Conversation

@pluginslab

Copy link
Copy Markdown
Owner

Answers the WP.org review sent on 30 Aug (R agentic-admin/schmitzoide/28May26/T4 30Aug26/4.2). This review carries the warning that another round with the same kinds of issues means rejection, so the goal is to remove each flagged item, not argue for it.

Stacked on #235 (the Tested up to 7.1 bump). Once #235 merges, this PR retargets to main.

What the review flagged, and what changed

1. Auth keys and salts (new). read-file could return wp-config.php, and the regex redaction misses non-literal define() forms.

  • read-file now refuses secret files outright: wp-config*.php, .env*, .htpasswd, private keys, SQL/SQLite dumps, .git/.ssh, and any file whose contents define the auth keys, salts, or DB_PASSWORD (checked across the whole file, not just the requested lines).
  • wp-config-list used to read wp-config.php through read-file. It now has its own PHP backend that uses token_get_all() to find constant names only, then reads live values for non-sensitive ones. Credentials, keys, and salts come back [REDACTED] and their values are never read.
  • Removed the security-scan salts check. It called wp_salt( 'auth' ), which returns key + salt, so it could never fail.

2. Calling files remotely (flagged for the second time). Removed the local knowledge base entirely: Transformers.js from jsDelivr, the indexing worker, the vector store, the codebase-index and code-search abilities, the four *-extract PHP abilities, and the Settings card and chat toggle. The build now has no jsDelivr reference. WebLLM's model download stays, and the readme now describes it as the service (what it is, which servers, no account needed).

3. File/directory locations (11 cases).

  • The plugins directory comes from the plugin's own plugin_dir_path() (agentic_admin_plugins_dir()), and mu-plugins from wp_get_mu_plugins().
  • verify-core-checksums: skips the literal wp-content/ prefix used by the checksums API. Fixes the bug the reviewer pointed out when the content directory is moved.
  • Debug log path: follows the error_log ini setting that wp_debug_mode() sets.
  • read-file and uploads-scan root: get_home_path().
  • diff-helpers: removed the ABSPATH . WPINC Text_Diff include. Text/Diff/Renderer/unified.php doesn't exist in core, so that branch never ran.
  • Remaining ABSPATH: core checksums (paths are relative to the WordPress directory by definition, as in wp core verify-checksums), the wp-config locator (same logic as wp-load.php), and wp-admin/includes requires.

4. Connectors (AI flag). is_connector_configured() no longer reads the API-key option. It uses AiClient::defaultRegistry()->hasProvider() && isProviderConfigured(), the same check as the core Connectors screen. Because that check was flaky in June, a positive result is cached for 5 minutes (only the boolean).

Testing

  • Unit tests: 75 passed (3 skipped), 6 of 7 suites.
  • Ability tests (Ollama): 67/70. The 3 failures (block listing, external tools, "address URL") don't involve any changed ability, and "address URL" passed in an earlier run.
  • composer lint: no errors (4 pre-existing warnings, none new). JS lint on changed files: warnings only, all pre-existing.
  • Ran on the local WP 7.1 install with WP_DEBUG on, with no new debug.log entries:
    • wp-config.php refused, both by name and by absolute path.
    • /etc/passwd refused (outside the root).
    • wp-config-list returned 19 constants with all keys, salts, and DB credentials redacted.
    • Core checksums: 3338/3338 pass.
    • Plugin checksums give the same results as before (WooCommerce fails on both old and new code).
    • uploads-scan, file-scan, and error-log-read all work.
  • npm run dist: 4.5 MB zip, 57 files, no .wasm, no jsDelivr.

Not in this PR

  • The reply email to the reviewer. Marcel sends it himself, by replying to the email thread (their checklist requires an email reply, not only the upload comment).
  • Docs under docs/ may still mention the knowledge base. They aren't in the distributed zip.

🤖 Generated with Claude Code

@pluginslab
pluginslab requested a review from ivdimova September 24, 2026 17:40
@pluginslab
pluginslab deleted the branch main September 25, 2026 12:05
@pluginslab pluginslab closed this Sep 25, 2026
@pluginslab pluginslab reopened this Sep 25, 2026
@pluginslab
pluginslab changed the base branch from fix/228-tested-up-to-7-1 to main September 25, 2026 12:05
Review ID: R agentic-admin/schmitzoide/28May26/T4 30Aug26/4.2

- Auth keys and salts: read-file now refuses files that can hold secrets
  (wp-config*.php, .env, private keys, DB dumps, .git/.ssh, and any file
  defining the auth keys, salts, or DB_PASSWORD) instead of relying on
  regex redaction. wp-config-list gets its own PHP backend that tokenizes
  wp-config.php for constant names only and never reads secret values.
  Removed the security-scan salts check (read wp_salt(), could never fail).
- Calling files remotely: removed the local knowledge base (Transformers.js
  from jsDelivr, embeddings, vector store, codebase-index/code-search and
  the four *-extract abilities). Readme now describes the model download
  as the service it is, with servers and account requirements.
- File/directory locations: plugins and mu-plugins dirs derived from the
  plugin's own location / wp_get_mu_plugins(); content-dir prefix bug in
  verify-core-checksums fixed; debug log follows the error_log ini set by
  wp_debug_mode(); read-file and uploads-scan use get_home_path(); dead
  Text_Diff include (unified renderer is not in core) removed.
- Connectors: configured state comes from the AI Client registry, as on
  the core Connectors screen, instead of reading API-key options.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@pluginslab
pluginslab merged commit 48af4c3 into main Sep 25, 2026
4 checks passed
@pluginslab
pluginslab deleted the fix/228-review-30aug branch September 25, 2026 12:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant