Repository navigation
Releases: jonschr/guest-key
Release list
Guest Key 0.1.4
Guest Key now requires the actual administrator role on the current site, together with the native manage_options capability. Custom roles with admin-like capabilities are no longer eligible.
- Non-admin roles get no Guest Key menus, toolbar controls, notices, scripts or styles and cannot create or use Guest Keys.
- Removing the administrator role immediately ends existing Guest Key REST/MCP and browser access, even when capabilities remain.
- Multisite additionally requires super-administrator status and the administrator role on the credential’s issuing subsite.
- Ordinary non-admin WordPress browser sessions remain intact.
Validation: 153 role, settings, native REST, MCP authentication, browser and multisite checks passed during implementation; the final 0.1.4 build passed the 49 role/settings checks, PHP lint on 72 project files and JavaScript syntax. The installable ZIP bootstrapped in WordPress with administrator eligibility and anonymous denial verified. Existing credentials and adapter configuration were preserved; disposable fixtures were removed. Development tests are excluded from release archives.
Remote hosting and PHP 7.4 runtime were not tested.
Guest Key 0.1.3
Guest Key 0.1.3 makes the settings-page inventory smaller and helps agents identify their requests clearly.
- Replace the verbose inventory tables with one searchable list limited to 240px in height. Click an entry for its descriptions, endpoints, and schemas.
- Include the requested T3 Code User-Agent example in copied connection details. Agents are instructed to resolve their actual client/version, agent, and model, keep the phrase
user-directed AI agent, and omit unknown values. - Preserve interactive browser headers and explain how to configure MCP transport and downstream HTTP headers where supported.
Validation: 46 settings-page and browser integration checks; PHP lint on 71 project files; JavaScript syntax; desktop and 390px mobile inspection; schema search, dialogs, and empty states; and the release ZIP bootstrapped successfully in WordPress. Development tests are excluded from release archives.
External agent clients and remote hosting were not tested for this release.
Guest Key 0.1.2
Guest Key now provides a compact connection page for giving a local agent six-hour administrator access. Create or copy access from one card; connection details and the searchable technical inventory are available when needed.
This release includes:
- Native REST command discovery and execution, with two corresponding MCP tools and optional MCP Adapter setup.
- Generic WordPress content, metadata, settings, media, plugin and theme operations, including batches and references to earlier results.
- Read-only wp-content browsing, chunked source reads and bounded text search.
- On-demand design guidance covering visual direction, typography, color, layout and motion.
- Correct GET parameters and nested REST field filtering, lazy application-password authentication, and multisite credential boundaries.
- Accessible connection status, actionable setup messages and a mobile-friendly settings page.
Validation: 945 checks across the existing site, a clean WordPress 6.9 installation and a disposable multisite network; PHP lint on 8.1, 8.4 and 8.5; browser connection workflows; installable ZIP verification; and a successful native WordPress update from 0.1.1 to the published 0.1.2 archive with network activation preserved.
PHP 7.4 runtime and remote hosting were not tested.