Skip to content

Releases: smartcloudsol/agent-composer

Agent Composer 1.3.9 – WordPress MCP Adapter upgrade

Choose a tag to compare

@scsinfo scsinfo released this 05 Oct 08:55

Summary

Agent Composer 1.3.9 restores its MCP connection when the separate WordPress MCP Adapter is upgraded to 0.7.0. The external-principal HTTP transport now uses the Adapter's revision-aware wire processor and array error envelopes. The existing path for MCP Adapter 0.6.1 remains supported.

Fixes

  • Resolve the toArray() fatal error and the removed JSON-RPC helper/router calls triggered by MCP Adapter 0.7.0.
  • Support the Adapter's 2025 initialization flow and sessionless 2026 request flow while keeping Composer authentication on every request. Composer does not store external principals as WordPress users.
  • Return Adapter-compatible responses for malformed JSON and unsupported HTTP methods.

Upgrade

Install Agent Composer 1.3.9 when upgrading MCP Adapter to 0.7.0. Restart the site's MCP tunnel and reconnect clients so they refresh the transport and tool catalog. No content migration is required.

Agent Composer 1.3.8 – Consistent validation for WordPress editing

Choose a tag to compare

@scsinfo scsinfo released this 02 Oct 09:36

Changes

  • Validate managed document changes in the classic WordPress editor, Quick Edit, and Bulk Edit before saving, using the authenticated editor session and nonce.
  • Validate complete stored editorial fields and the active Blueprint on partial Gutenberg saves, including requests that update only metadata.
  • Share editorial, relation, taxonomy assignment, and public term-definition validators across agent and native editing integrations.
  • Preserve the explicit opt-in required for native editing of published managed documents and the separate human-reviewed proposal workflow for agents.
  • Reject relations to the edited document or its proposal source, allow taxonomy assignments to be cleared, and report actual stored content-field values after updates.

Upgrade Notes

Partial native saves now enforce the same editorial and document rules as agent edits. Review and correct invalid existing titles, excerpts, SEO descriptions, or language metadata before editing. Native editing of published managed documents still requires explicit Blueprint opt-in; agent proposal permissions are unchanged.

Agent Composer 1.3.7 – Structure-contract improvements

Choose a tag to compare

@scsinfo scsinfo released this 01 Oct 19:08

Changes

  • Allow an explicitly opted-in, cookie-authenticated WordPress editor to save a published managed document through Gutenberg while retaining full Blueprint and Structure Contract validation.
  • Keep Composer/MCP agent updates on the separate human-reviewed proposal path; native editing remains blocked by default.
  • Expose the native published-edit policy in Blueprint configuration.
  • Allow registered block union types and schema defaults during validation, so optional unsaved attributes do not prevent existing managed documents from being edited.

Agent Composer 1.3.6 – Inline editing for synced pattern content

Choose a tag to compare

@scsinfo scsinfo released this 01 Oct 14:34

Changes

  • Edit each post's content inside synced structural patterns directly in Gutenberg, including nested pattern instances.
  • Add, remove, and reorder approved blocks and patterns from the block sidebar's List View tab, within the configured content limits.
  • Preserve each instance's content and native Pattern Overrides without changing the shared pattern or other posts.
  • Fix empty block separators appearing as invalid blocks or inflating content counts.
  • Initialize required content slots when creating managed documents in WordPress admin, while respecting per-pattern and section limits.
  • Discover WordPress Ability providers reliably during early admin requests and improve managed-document creation error diagnostics.

Upgrade Notes

Reload any open block editors after updating. Select a content section or one of its blocks, then open Block → List View in the right sidebar to manage its content. Available block types remain controlled by the site's contract. Existing instance content is preserved; no content migration or shared-pattern rewrite is required.

Agent Composer 1.3.5 – Approval cards for update proposals

Choose a tag to compare

@scsinfo scsinfo released this 30 Sep 19:51

Changes

  • Request a human approval card for a submitted update proposal from ChatGPT or another MCP Apps client.
  • Show the WordPress-rendered post-type preview in the card so the reviewer can merge the proposal, request changes, or reject it.
  • Bind the approval to the submitted revision and recheck the proposal and live source before applying a decision.
  • Include the updated WP Suite General Settings for additional frontend stylesheet URLs. Restart Composer's MCP runtime and refresh client tools and resources to discover the new approval action.

Agent Composer v1.3.4 – WP Ability/MCP mprovements

Choose a tag to compare

@scsinfo scsinfo released this 29 Sep 22:37

Changes

  • Render previews with the WordPress singular template selected for each post type, including dynamic blocks, synced patterns, Pattern Overrides, and classic PHP templates.
  • Show the rendered page in publication approval cards and provide a link to the full WordPress preview.
  • Deliver private preview images and fonts as verified MCP assets, and display images in the v8 preview with CSP-compatible URLs.
  • Let the assigned agent reopen a submitted proposal’s read-only rendered preview.
  • Allow site plugins to register guarded MCP tools and UI resources.

Agent Composer v1.3.3 – Fixed frontend rendering

Choose a tag to compare

@scsinfo scsinfo released this 24 Sep 12:19

SmartCloud Agent Composer 1.3.3

This release fixes frontend rendering of Composer-managed instance slots inside synced patterns.

Fixed

  • Saved instanceSlots content now appears in public page bodies and rendered previews.
  • Instance-slot content is injected after WordPress resolves the synced pattern, preserving native Pattern Overrides.
  • Multiple references to the same synced pattern retain their own independent slot content.
  • Nested pattern instances render correctly without recursive rendering loops.

Upgrade notes

No content migration is required. Clear page and full-page caches after installing the update so previously empty extension slots are rendered again.

Agent Composer v1.3.2 – Stabilized rendered previews

Choose a tag to compare

@scsinfo scsinfo released this 23 Sep 08:37

SmartCloud Agent Composer 1.3.2

This release stabilizes rendered previews and adds instance-level addressing for repeated synced patterns.

Fixed

  • Prevented rendered-draft and publication-approval previews from resizing the entire embedded app while content, styles, and fonts load.
  • Kept approval headers and actions fixed while only the preview area scrolls.
  • Deferred preview visibility until its assets and fonts are ready.
  • Suppressed duplicate preview delivery and refreshed the preview resource URIs for cache invalidation.
  • Fixed ambiguous overrides when the same synced pattern appears multiple times on a page or blueprint.

Added

  • Stable patternInstanceId values for individual synced pattern instances.
  • Override operations addressed by pattern_instance_id and field_id.
  • Independent native Pattern Overrides for repeated instances of the same synced pattern.
  • Slot-level allowed_patterns constraints.
  • Per-pattern minimum and maximum occurrence constraints.
  • Recursive synced-pattern reference, contract-version, and content-hash validation.
  • Cycle and nesting-depth protection for nested synced patterns.

Upgrade notes

Restart the MCP runtime and refresh client tools and resources after installing this update so clients load the new preview resources and semantic schemas.

Existing synced-pattern instances remain readable. Composer persists a compatibility instance ID when a legacy instance is first updated.

To use allowed_patterns, pattern_occurrences, or pinned content_hash values, clone the active Config Set, update it, validate it, and activate the new version.

No content is published or migrated automatically.

Agent Composer v1.3.1 – Publisher media and Static Publisher jobs

Choose a tag to compare

@scsinfo scsinfo released this 20 Sep 15:20

SmartCloud Agent Composer 1.3.1

This release adds governed Publisher media upload and bounded Static Publisher job operations to the protected Composer MCP surface.

Publisher media

  • Adds an explicitly enabled, Publisher-only MCP tool for publishing one governed raster image to the WordPress Media Library without granting general upload access.
  • Requires a semantic filename slug, title, descriptive-or-decorative alt-text decision, rights confirmation, and immediate-publication confirmation.
  • Bounds base64 and safe HTTPS inputs and validates the signature, MIME type, size, dimensions, and idempotency identity.
  • Keeps raw image bytes and source URLs out of the audit log.

Static Publisher operations

  • Admits a bounded list of registered external tools to the Composer MCP surface, including Static Publisher scheduling, target discovery, content-sync rule discovery, and job-status tools.
  • Classifies the explicit Static Publisher discovery tools at the read boundary while retaining provider-enforced Publisher-only discovery and job-specific status authorization in protected modes.
  • Preserves Composer’s prohibition on direct agent publication.
  • Refreshes MCP tool-list cache identity for the expanded governed tool surface.

Shared Hub

  • Bundles WP Suite Hub 2.5.16 so Static Publisher is notified when the shared translation catalog changes.

Agent Composer v1.3.0 – Structure Contracts and protected MCP access

Choose a tag to compare

@scsinfo scsinfo released this 20 Sep 14:34

SmartCloud Agent Composer 1.3.0

This release adds protected MCP access, human-controlled publication, semantic Structure Contracts, and deterministic content migrations.

Protected MCP access

  • Added optional Cognito access-token validation with group roles, per-client ceilings, optional scopes, filtered discovery, and invocation enforcement.
  • Added OAuth protected-resource discovery with PKCE S256, public-client authentication, authorization-code and refresh-token grants.
  • Bound MCP access tokens and advertised scopes to the exact external MCP resource URI.
  • Added principal-bound ownership and actor-aware audit context for accepted MCP requests and completed tool calls.
  • Added token-free transport diagnostics without storing bearer values, request arguments, or tool results.
  • Added a guided MCP Access administration screen with automatic Cognito provider discovery, manual overrides, and fail-closed status guidance.

Human publication

  • Added Publisher-only, revision- and hash-bound publication requests.
  • Added cross-principal, read-only handoff for human review.
  • Added an inline MCP App with app-private human decision tools and a WordPress administration fallback.
  • Kept publication and approval capabilities outside the agent-visible tool surface.

Structure Contracts and semantic editing

  • Added independently versioned Structure Contracts with protected editor projections, managed baselines, typed override manifests, drift detection, and machine-readable violations.
  • Added semantic document reads and field, media, section, and extension-slot operations using stable semantic IDs instead of serialized Gutenberg paths.
  • Added native synced-pattern materialization with Pattern Overrides and validation of expanded structures.
  • Added exact source and target baselines, deterministic migration operations, override-aware rebasing, zero-write previews, and plan-bound update proposals.
  • Added bounded bulk migration planning and compatibility reports, with idempotent proposal creation for explicitly reviewed items.
  • Added a governed extension-slot block for controlled layout customization.

Administration and compatibility

  • Added clearer separation between human migration guidance and executable migration policy.
  • Improved loading and pending states while preserving refreshed content in place.
  • Distinguished registry patterns from synced structural wp_block records.
  • Fixed Site Contract list handling so explicit lists replace defaults without retaining removed numeric entries.

Upgrade notes

  1. Install MCP Adapter 0.6.1 or newer.
  2. Validate and explicitly activate a Structure Contract Config Set, then synchronize its local patterns.
  3. Restart the MCP runtime and refresh the client tool and resource catalogue.
  4. Existing content is not migrated automatically; review migration previews before creating update proposals.
  5. MCP protection remains Open after upgrading. Before enabling Protected Required, configure a Cognito Hosted UI domain and a public authorization-code plus PKCE client with the exact callback URI.
  6. Configure the exact external MCP resource URI, group mappings, and client ceilings, migrate external tunnels from STDIO to HTTP where required, and complete a test OAuth round trip.
  7. Enable scope enforcement only after Cognito uses the same MCP resource URI as its resource-server identifier and the required App Client scopes are assigned.