v1.3.5 — MCP auth, nonce fix, app password detection
Summary
- Force-enable Application Passwords on HTTPS/proxy/reverse-proxy hosts
- Detect app passwords for all users with
manage_options(not only administrator role) - Admin panel: no more wp_die on expired nonce — graceful error + redirect
- Auto-setup uses POST instead of GET link
- Bootstrap respects existing stored password and manual-pass.txt import
- Improved health diagnostics for manual app passwords
Upgrade
Replace plugin folder or upload release ZIP. Then open Ustawienia → Cursor Bridge and save app password or run full auto-setup.
Test plan
- Panel: Application Passwords = OK
- Save app password in Cursor Bridge settings (no white screen)
- Full auto-setup completes without nonce error
-
cursor-bridge/pingreturnsok: truein Cursor MCP