π§ Bug Fixes & Authentication Improvements
Major Fixes
- β
REST API Authentication Fixed: Apache now properly passes Authorization header to PHP
- β
Autoloader Bug Fixed: Renamed MCPConnection class file for proper loading
- β
Basic Auth Working: Implemented proper password verification with wp_check_password
- β
Early Authentication: Added init hook authentication before REST routing
What's Fixed
- Admin pages load without errors
- MCP API endpoints authenticate with Basic Auth (
username:password)
- Support for multiple auth methods:
- Basic Auth (new, now working!)
- API Key (X-API-Key header)
- Bearer Token (Authorization: Bearer)
- Session cookies
Technical Changes
- Added Apache .htaccess mod_rewrite rule for Authorization header passthrough
- Implemented early REST authentication via init hook (priority 1)
- Fixed wp_check_password integration for secure credential verification
- All endpoints now return proper API responses
Installation
- Download
webweaver-0.2.2.zip
- WordPress Admin > Plugins > Upload
- Activate
- Use
wp-json/wp-mcp/v1/ endpoints with authentication
API Test
curl -u admin:your_password http://localhost/wp-json/wp-mcp/v1/posts
Package Info
- SHA256:
03f61900202f23a9184ab77887fe2eb18369770f65dab5ff8ad9dd5302a5ddbe
- Tested on WordPress 6.4 with PHP 8.1+