Repository navigation
fix: address WP.org review 30Aug26/4.2 (#228) - #236
Merged
Merged
Conversation
Review ID: R agentic-admin/schmitzoide/28May26/T4 30Aug26/4.2 - Auth keys and salts: read-file now refuses files that can hold secrets (wp-config*.php, .env, private keys, DB dumps, .git/.ssh, and any file defining the auth keys, salts, or DB_PASSWORD) instead of relying on regex redaction. wp-config-list gets its own PHP backend that tokenizes wp-config.php for constant names only and never reads secret values. Removed the security-scan salts check (read wp_salt(), could never fail). - Calling files remotely: removed the local knowledge base (Transformers.js from jsDelivr, embeddings, vector store, codebase-index/code-search and the four *-extract abilities). Readme now describes the model download as the service it is, with servers and account requirements. - File/directory locations: plugins and mu-plugins dirs derived from the plugin's own location / wp_get_mu_plugins(); content-dir prefix bug in verify-core-checksums fixed; debug log follows the error_log ini set by wp_debug_mode(); read-file and uploads-scan use get_home_path(); dead Text_Diff include (unified renderer is not in core) removed. - Connectors: configured state comes from the AI Client registry, as on the core Connectors screen, instead of reading API-key options. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
pluginslab
force-pushed
the
fix/228-review-30aug
branch
from
September 25, 2026 12:06
cf84493 to
232f32a
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Answers the WP.org review sent on 30 Aug (
R agentic-admin/schmitzoide/28May26/T4 30Aug26/4.2). This review carries the warning that another round with the same kinds of issues means rejection, so the goal is to remove each flagged item, not argue for it.Stacked on #235 (the Tested up to 7.1 bump). Once #235 merges, this PR retargets to
main.What the review flagged, and what changed
1. Auth keys and salts (new).
read-filecould returnwp-config.php, and the regex redaction misses non-literaldefine()forms.read-filenow refuses secret files outright:wp-config*.php,.env*,.htpasswd, private keys, SQL/SQLite dumps,.git/.ssh, and any file whose contents define the auth keys, salts, orDB_PASSWORD(checked across the whole file, not just the requested lines).wp-config-listused to read wp-config.php throughread-file. It now has its own PHP backend that usestoken_get_all()to find constant names only, then reads live values for non-sensitive ones. Credentials, keys, and salts come back[REDACTED]and their values are never read.security-scansalts check. It calledwp_salt( 'auth' ), which returns key + salt, so it could never fail.2. Calling files remotely (flagged for the second time). Removed the local knowledge base entirely: Transformers.js from jsDelivr, the indexing worker, the vector store, the
codebase-indexandcode-searchabilities, the four*-extractPHP abilities, and the Settings card and chat toggle. The build now has no jsDelivr reference. WebLLM's model download stays, and the readme now describes it as the service (what it is, which servers, no account needed).3. File/directory locations (11 cases).
plugin_dir_path()(agentic_admin_plugins_dir()), and mu-plugins fromwp_get_mu_plugins().verify-core-checksums: skips the literalwp-content/prefix used by the checksums API. Fixes the bug the reviewer pointed out when the content directory is moved.error_logini setting thatwp_debug_mode()sets.read-fileanduploads-scanroot:get_home_path().diff-helpers: removed theABSPATH . WPINCText_Diff include.Text/Diff/Renderer/unified.phpdoesn't exist in core, so that branch never ran.ABSPATH: core checksums (paths are relative to the WordPress directory by definition, as inwp core verify-checksums), the wp-config locator (same logic aswp-load.php), andwp-admin/includesrequires.4. Connectors (AI flag).
is_connector_configured()no longer reads the API-key option. It usesAiClient::defaultRegistry()->hasProvider() && isProviderConfigured(), the same check as the core Connectors screen. Because that check was flaky in June, a positive result is cached for 5 minutes (only the boolean).Testing
composer lint: no errors (4 pre-existing warnings, none new). JS lint on changed files: warnings only, all pre-existing.wp-config.phprefused, both by name and by absolute path./etc/passwdrefused (outside the root).wp-config-listreturned 19 constants with all keys, salts, and DB credentials redacted.npm run dist: 4.5 MB zip, 57 files, no.wasm, no jsDelivr.Not in this PR
docs/may still mention the knowledge base. They aren't in the distributed zip.🤖 Generated with Claude Code