Repository navigation
fix: address WP.org review 27Sep26/4.3 (#228) - #238
Merged
Merged
Conversation
Review ID: R agentic-admin/28May26/T5 27Sep26/4.3 - Tested up to: declared only in readme.txt, removed from the plugin header. - Escaping: the LLM proxy no longer echoes the provider's SSE body verbatim. Each data: event is decoded and re-encoded with wp_json_encode() using the JSON_HEX_* flags; non-JSON lines are dropped. Adds nosniff. - Remote loading: the Load Model notice now names the download source and real size instead of claiming no data is sent to external servers; the readme states nothing is downloaded until an admin clicks Load Model. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This was referenced Sep 27, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Answers WP.org review
R agentic-admin/28May26/T5 27Sep26/4.3.readme.txt. Removed from theagentic-admin.phpheader.class-llm-proxy.php:249): the proxy no longer echoes the remote SSE body as-is. Eachdata:event is decoded and re-encoded withwp_json_encode()using theJSON_HEX_TAG | AMP | APOS | QUOTflags. Non-JSON lines are dropped, and[DONE]passes through. Also addsX-Content-Type-Options: nosniff.Tested: a faked hostile SSE response (script tags, a raw HTML line, and non-JSON
data:) comes out as escaped JSON, with the rest dropped. Unit tests 75 passed, PHP lint shows no new warnings, and the build is clean.🤖 Generated with Claude Code