Repository navigation
Release 4.4.2 — security hardening of admin notice dismissal (udx/lib-wp-bootstrap 1.3.5) - #842
Conversation
| '0e6d7bf4a5811bfa5cf40c5ccd6fae6a' => __DIR__ . '/..' . '/symfony/polyfill-mbstring/bootstrap.php', | ||
| '6e3fae29631ef280660b3cdad06f25a8' => __DIR__ . '/..' . '/symfony/deprecation-contracts/function.php', | ||
| 'a4a119a56e50fbb293281d9a48007e0e' => __DIR__ . '/..' . '/symfony/polyfill-php80/bootstrap.php', | ||
| '320cde22f66dd4f5d3fd621d3e88b98f' => __DIR__ . '/..' . '/symfony/polyfill-ctype/bootstrap.php', | ||
| '8825ede83f2f289127722d4e842cf7e8' => __DIR__ . '/..' . '/symfony/polyfill-intl-grapheme/bootstrap.php', | ||
| 'e69f7f6ee287b969198c3c9d6777bd38' => __DIR__ . '/..' . '/symfony/polyfill-intl-normalizer/bootstrap.php', | ||
| '0d59ee240a4cd96ddbb4ff164fccea4d' => __DIR__ . '/..' . '/symfony/polyfill-php73/bootstrap.php', | ||
| 'b6b991a57620e2fb6b2f66f03fe9ddc2' => __DIR__ . '/..' . '/symfony/string/Resources/functions.php', |
There was a problem hiding this comment.
🔴 Missing dependencies crash plugin startup
Loading vendor/autoload.php follows $files into uncommitted Symfony paths. The first require fails, so every WP-Stateless startup aborts.
Prompt for agents
Regenerate the committed Composer runtime files from a clean installation that matches the distributed vendor tree. The current vendor/composer/autoload_static.php, autoload_files.php, autoload_psr4.php, autoload_classmap.php, installed.php, and installed.json include require-dev packages, while vendor/symfony, vendor/league, vendor/psr, vendor/coenjacobs, and vendor/deliciousbrains are absent. Ensure vendor/autoload.php loads successfully from the release archive and retain the intended vendor/wpmetabox installation path.
Was this helpful? React with 👍 or 👎 to provide feedback.
There was a problem hiding this comment.
🟡 Changes recommended
The generated autoloader eagerly requires absent dev-dependency files, causing plugin loading to fail.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Pull request overview
Updates WP-Stateless to 4.4.2 with hardened admin-notice dismissal handling.
Changes:
- Adds nonce, capability, key-pattern, and sanitization checks.
- Bumps release metadata and changelogs.
- Updates Composer metadata and generated autoload files.
File summaries
| File | Description |
|---|---|
wp-stateless-media.php |
Bumps plugin version. |
vendor/udx/lib-wp-bootstrap/lib/classes/class-bootstrap.php |
Hardens the AJAX handler. |
vendor/udx/lib-wp-bootstrap/changes.md |
Documents library release. |
vendor/composer/installed.php |
Updates installed-package metadata. |
vendor/composer/installed.json |
Updates package metadata. |
vendor/composer/autoload_static.php |
Adds generated dev-package mappings. |
vendor/composer/autoload_real.php |
Eagerly loads generated file mappings. |
vendor/composer/autoload_psr4.php |
Adds PSR-4 mappings. |
vendor/composer/autoload_files.php |
Adds generated file autoloads. |
vendor/composer/autoload_classmap.php |
Adds generated class mappings. |
readme.txt |
Updates stable tag and changelog. |
composer.lock |
Locks lib-wp-bootstrap 1.3.5. |
changes.md |
Adds the 4.4.2 release entry. |
changelog.txt |
Adds the 4.4.2 release entry. |
Review details
- Files reviewed: 4/14 changed files
- Comments generated: 0
- Review effort level: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
There was a problem hiding this comment.
🟡 Changes recommended
The release ships thousands of unnecessary development files, and its broad dependency refresh is not fully reflected in the PR scope.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Review details
- Files reviewed: 2/4925 changed files
- Comments generated: 1
- Review effort level: Balanced
| * ENHANCEMENT - updated `guzzlehttp/guzzle` library from 7.10.0 to 7.15.5. | ||
| * ENHANCEMENT - updated `phpseclib/phpseclib` library from 3.0.48 to 3.0.57. | ||
| * ENHANCEMENT - updated `google/protobuf` library from 4.33.2 to 4.33.6. |
ec4ec35 to
d5d35e1
Compare
There was a problem hiding this comment.
🟡 Changes recommended
The bundled Google SDK rejects PHP 8.1 and ships protobuf 5.36.1 despite the plugin metadata and changelogs stating otherwise.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Review details
- Files reviewed: 2/661 changed files
- Comments generated: 3
- Review effort level: Balanced
| * FIX - `udx/lib-wp-bootstrap` package updated to 1.3.5: security hardening of the admin notice dismissal AJAX handler (nonce verification, capability check, and option key restriction). | ||
| * ENHANCEMENT - updated `guzzlehttp/guzzle` library from 7.10.0 to 7.15.5. | ||
| * ENHANCEMENT - updated `phpseclib/phpseclib` library from 3.0.48 to 3.0.57. | ||
| * ENHANCEMENT - updated `google/protobuf` library from 4.33.2 to 4.33.6. |
| * FIX - `udx/lib-wp-bootstrap` package updated to 1.3.5: security hardening of the admin notice dismissal AJAX handler (nonce verification, capability check, and option key restriction). | ||
| * ENHANCEMENT - updated `guzzlehttp/guzzle` library from 7.10.0 to 7.15.5. | ||
| * ENHANCEMENT - updated `phpseclib/phpseclib` library from 3.0.48 to 3.0.57. | ||
| * ENHANCEMENT - updated `google/protobuf` library from 4.33.2 to 4.33.6. |
| * FIX - `udx/lib-wp-bootstrap` package updated to 1.3.5: security hardening of the admin notice dismissal AJAX handler (nonce verification, capability check, and option key restriction). | ||
| * ENHANCEMENT - updated `guzzlehttp/guzzle` library from 7.10.0 to 7.15.5. | ||
| * ENHANCEMENT - updated `phpseclib/phpseclib` library from 3.0.48 to 3.0.57. | ||
| * ENHANCEMENT - updated `google/protobuf` library from 4.33.2 to 4.33.6. |
d5d35e1 to
34b9efb
Compare
There was a problem hiding this comment.
🟡 Changes recommended
The vendored Google autoloader now requires PHP 8.2 while the plugin still declares PHP 8.1 support.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Review details
- Files reviewed: 3/571 changed files
- Comments generated: 0 new
- Review effort level: Balanced
34b9efb to
fe0de8c
Compare
…7, protobuf 4.33.6) and prune dev files from vendored tree
fe0de8c to
c746443
Compare
There was a problem hiding this comment.
🔵 Needs a closer look
The security fix is sound, but the 547-file dependency refresh includes extensive cryptographic, HTTP, and generated-code changes requiring final human validation.
Review details
- Files reviewed: 3/547 changed files
- Comments generated: 0 new
- Review effort level: Balanced
|
Bot feedback addressed and re-verified on the final tree:
GI regression suite 3/3 passing against this branch on the dev environment, incl. the in-browser subscriber exploit test returning |
Summary
Security release. Updates the vendored
udx/lib-wp-bootstrappackage to 1.3.5, which hardens theud_bootstrap_dismiss_noticeAJAX handler (registered aswp_ajax_ud_bootstrap_dismiss_notice):check_ajax_referer)manage_optionscapabilitydismiss_*_noticepattern (the only shape the library reads back)Reported via Patchstack responsible disclosure (report ec72be3a, scheduled to publish Oct 1, 2026). Changelog wording intentionally avoids exploit detail until publication. Sibling handlers already carry nonce checks (CVE-2024-1385 fix in lib 1.3.3); this handler was missed.
Also included, driven by the Grype security scan failing on the PR:
--no-dev(phpunit/php_codesniffer/composer-composer etc. no longer shipped),google/apiclient-servicespruned to the Storage service via the package's own cleanup script (as before), and vendored.github/directories removed — these were the sources of the remaining Grype hits (github-action CVEs in vendored workflow files, nested lockfiles of dev packages)--no-dev, so the committed autoloader never references uncommitted dev filesChanges
composer update udx/lib-wp-bootstrap→ 1.3.5 (vendored tree verified byte-identical to the 1.3.5 tag; lib PR: Harden dismiss-notice AJAX handler (nonce, capability, key allow-list) lib-wp-bootstrap#19)wp-stateless-media.php4.4.1 → 4.4.2,readme.txtstable tag 4.4.2changes.md,changelog.txt,readme.txt(4.4.2 - 2026-09-02)lib/Google/composer.lock+ regenerated vendored treeVerification
On a live environment (wpcloud.io develop-stateless pod) running exactly this branch's tree (fresh-synced after pruning):
-1, target option untouched (previouslysuccess:1with the option overwritten)dismiss_*_noticekey →success:1(dismiss flow preserved)-1