v0.8.4
WordPress 7.1 Abilities API adoption. Minimum WordPress is now 7.1 and minimum PHP 8.2.
Two changes are visible to existing clients and both are listed below: domain rejections now answer 4xx instead of the HTTP 500 every one of them used to return (public error codes unchanged), and update-llms-txt is now annotated destructive.
Published retroactively on 2026-09-03. The release was committed on 2026-09-01 and tagged two days later, so this tag's date is later than the work it contains.
Runtime verification: 24/24 verifiers green on WordPress 7.1 (2026-09-01).
Changelog
- WordPress 7.1 is now the minimum supported version (ADR 0027). The plugin declares it and contains no 6.x compatibility branches. Nothing here is optional on an older release — the exposure flag, the lifecycle hooks, and the filtering used below all arrived in 7.1.
- Fixed: every rejection answered HTTP 500. No ability error carried a status, so a missing post, a refused capability, and an oversized payload were all indistinguishable from a server fault over REST — agent clients retried them and monitoring read them as outages. Domain rejections now answer the status they always meant: 400 for invalid input, 403 for a refused capability, 404 for content that is missing or not visible to the caller, 409 for a concurrency or state conflict, 413 for an over-limit payload, 501 for an unavailable provider, and 500 only for an actual internal fault. Public error codes are unchanged, so any client matching on
codekeeps working; only the status differs. - Missing and not-visible deliberately share 404. Which of the two it was is not disclosed, so status codes cannot be used to enumerate content a caller may not read.
wp-content-bridge/update-llms-txtis now annotateddestructive(ADR 0028), because its input is a complete configuration that replaces the stored one — a caller omitting a field loses it. Its HTTP method is unchanged: it remains non-idempotent, so it is still POST, not DELETE. No other annotation changed; the other thirty were already correct under the definition this release finally writes down.- Abilities now declare 7.1's unified
publicexposure flag alongside the explicitshow_in_restthey already carried. Registration metadata is built in one place, which removed thirteen near-identical per-class helpers — two of which took different single booleans under the same name. - Added an off-by-default invocation telemetry diagnostic mode (ADR 0029). Enabled, it records the last 200 invocation attempts — ability name, principal, channel, outcome, timestamp, and nothing else — including the permission denials that previously left no trace anywhere. It never touches the audit table, never stores ability input, and writes once per request. It is a diagnostic, not an audit record: the hook fires before validation and authorization, so an entry proves an attempt was made, never that anything happened.
get-diagnosticsreports the site's minimum WordPress version and which Abilities API features it actually detected at runtime, rather than assuming them from a version number.
Install: download wp-content-bridge.zip below and install it as a plugin, or let the built-in updater offer it.
Full Changelog: v0.8.3...v0.8.4