Repository navigation
Conversation
With cloudflare-api.log removed, a failed purge left almost nothing to debug with: the non-200 path logged only the status code, and the new success:false path logged nothing at all, while the toolbar still told the user to check the error log. Both paths now append the codes and messages from Cloudflare's errors array (or note that the body was not valid JSON). These never contain credentials, and a test asserts the token and email stay out of the log. Co-Authored-By: Claude Opus 5.5 <[email protected]> Signed-off-by: Filip Ilic <[email protected]>
Deriving destructive from !readonly marked every write as destructive, so purge-url (clearing a single page) asked MCP clients for the same confirmation as purge-all, and both purges were flagged non-idempotent although repeating a purge has no further effect, which stops clients from retrying after a timeout. register() now requires readonly, destructive and idempotent for every ability, so new abilities cannot inherit a derived default. A test pins the values for each ability. Co-Authored-By: Claude Opus 5.5 <[email protected]> Signed-off-by: Filip Ilic <[email protected]>
The workflow ran on every push as well as on pull_request, so each push to a PR branch ran the matrix twice. Pushes now only trigger it on the same branches as phpstan.yml, matching progress-planner's phpunit.yml, and a concurrency group cancels superseded runs on the same branch. The README now states that, with every ability MCP-public, an MCP client authenticated as an administrator can replace the zone ID or API token. Co-Authored-By: Claude Opus 5.5 <[email protected]> Signed-off-by: Filip Ilic <[email protected]>
Contributor
|
Pushed three commits on top:
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Cloudflare Utils previously exposed cache purging and connection settings only through WordPress hooks and the admin UI. This adds five administrator-only WordPress abilities for reading and updating settings, inspecting automatic behavior, purging one URL, and purging the configured zone.
Tokens remain write-only, constant-controlled settings cannot be changed, URL purges are limited to this site's hostname, and full-zone purges require explicit confirmation. Abilities are discoverable through REST and the WordPress MCP Adapter while older WordPress versions continue to load without the Abilities API.
The shared purge service no longer writes credentials to a log and now checks Cloudflare's JSON success flag before reporting success. Documentation and a CI workflow cover the new abilities.
Validation: PHP lint, coding standards, PHPStan and Composer validation passed. Integration tests passed with 66 assertions on both WordPress 6.9.4 and 7.1.2; loading without the Abilities API also passed. Tests use real WordPress registration and schema validation with mocked options, authorization and HTTP requests. No live Cloudflare cache or site settings were changed.