WP AI Bridge v0.4.2
Patch release hardening OAuth refresh recovery and Native Ability boundaries.
Changes
- Makes rotating OAuth refresh-token exchange retry-safe after an ambiguous lost response using bounded recovery state that preserves client, resource, user, scope, and approved-client revision binding while retaining normal one-time rotation and replay protection.
- Keeps the Gateway-facing provider-native Ability catalog aligned with the active MCP Adapter exposure contract, with a fail-closed fallback when the Adapter runtime resolver is unavailable.
- Bounds provider-native Ability results at the canonical WP AI Bridge MCP edge so credential/security-like nested values, errors, and throwables cannot cross that boundary. Direct/default MCP Adapter execution and Bridge-owned purpose-specific credential contracts remain unchanged.
Upgrade notes
Already-canonical v0.4.0 and v0.4.1 installations can update normally to v0.4.2. No data migration, OAuth client reset, or ChatGPT reconnection is required solely because of this patch release.
Sites still on v0.3.0 that must preserve pre-canonical Workspace data must first use the immutable v0.4.0 migration release, verify the migrated Workspace, and then update to the current release.
Validation
- Final release source:
main@1bc3693b21072d2a23aa9f7e534eff39591642c9 - Final release tree:
e4f5925896380d86cdbfaafd47e51d4853cc3bd1 - Release preparation: PR #87
- Executable-mode correction: PR #88
- Final exact-head CI:
35382164466/ #425 — 13/13 SUCCESS - Release artifact:
wp-ai-bridge.zip - SHA-256:
1214fa1a6a5ff7da8682fe91535c1100f45d30cbfe23b380630e1234eec1f2ca - Included engineering work: #80, #81, #82
- Issue #82 independent HIGH_ASSURANCE review: COMPLETE / APPROVE; no material findings.
Release tracking: #86