Skip to content

fix: address WP.org review 27Sep26/4.3 (#228) - #238

Merged
pluginslab merged 1 commit into
mainfrom
fix/228-review-27sep
Sep 27, 2026
Merged

pluginslab merged 1 commit into
mainfrom
fix/228-review-27sep

Conversation

@pluginslab

Copy link
Copy Markdown
Owner

Answers WP.org review R agentic-admin/28May26/T5 27Sep26/4.3.

  • Tested up to: now only in readme.txt. Removed from the agentic-admin.php header.
  • Escaping (class-llm-proxy.php:249): the proxy no longer echoes the remote SSE body as-is. Each data: event is decoded and re-encoded with wp_json_encode() using the JSON_HEX_TAG | AMP | APOS | QUOT flags. Non-JSON lines are dropped, and [DONE] passes through. Also adds X-Content-Type-Options: nosniff.
  • Remote loading: the notice next to Load Model now names the source (MLC-AI on Hugging Face and GitHub) and the real size. It used to say "no data is sent to external servers" and "250MB-1GB". The readme now says nothing downloads until an admin clicks Load Model. The WebLLM code the reviewer cites is unchanged: model libraries are only hosted on GitHub, so that question goes to the reviewer by email.

Tested: a faked hostile SSE response (script tags, a raw HTML line, and non-JSON data:) comes out as escaped JSON, with the rest dropped. Unit tests 75 passed, PHP lint shows no new warnings, and the build is clean.

🤖 Generated with Claude Code

Review ID: R agentic-admin/28May26/T5 27Sep26/4.3

- Tested up to: declared only in readme.txt, removed from the plugin header.
- Escaping: the LLM proxy no longer echoes the provider's SSE body verbatim.
  Each data: event is decoded and re-encoded with wp_json_encode() using
  the JSON_HEX_* flags; non-JSON lines are dropped. Adds nosniff.
- Remote loading: the Load Model notice now names the download source and
  real size instead of claiming no data is sent to external servers; the
  readme states nothing is downloaded until an admin clicks Load Model.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@pluginslab
pluginslab merged commit cf2406b into main Sep 27, 2026
4 checks passed
@pluginslab
pluginslab deleted the fix/228-review-27sep branch September 27, 2026 21:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant