Skip to content

Add snippet for Disable WP REST API compatibility - #3857

Merged
pfefferle merged 1 commit into
trunkfrom
add/disable-wp-rest-api-snippet
Oct 6, 2026
Merged

pfefferle merged 1 commit into
trunkfrom
add/disable-wp-rest-api-snippet

Conversation

@pfefferle

Copy link
Copy Markdown
Member

Related: https://wordpress.org/support/topic/conflicts-between-activitypub-and-disable-wp-rest-api/#post-19037585

Proposed changes:

  • Add a standalone, opt-in snippet allowing ActivityPub requests through the free Disable WP REST API plugin's existing allowlist filter.
  • Match WordPress's resolved REST route, covering pretty/plain permalinks and built-in WebFinger/NodeInfo rewrites without exempting unrelated namespaces.
  • Preserve existing allowlist entries and ActivityPub's own authentication, signature and permission checks.
  • Include installation instructions and focused regression tests. No automatic integration or changes to the main plugin's behavior.

Other information:

  • Have you written new tests for your changes, if applicable?

All 18 snippet tests (20 assertions) and targeted PHPCS pass. A focused code review found no actionable issues. Skip Changelog: snippets are opt-in and excluded from the distributed plugin.

Testing instructions:

  • Install and activate ActivityPub and the free Disable WP REST API plugin on a test site. Logged-out REST requests should initially return rest_login_required.
  • Copy snippets/disable-wp-rest-api/ into wp-content/plugins/ and activate Allow ActivityPub through Disable WP REST API. Alternatively, put its PHP file in wp-content/mu-plugins/.
  • Logged out, request an enabled actor's /wp-json/activitypub/1.0/actors/<id> endpoint and /.well-known/webfinger?resource=acct:<account>@<domain>. They should reach ActivityPub normally.
  • Repeat with /?rest_route=/activitypub/1.0/actors/<id>. Verify /wp-json/wp/v2/users remains restricted, including when a query parameter contains an ActivityPub URL.
  • Confirm protected ActivityPub operations still require their usual permissions/signatures. Deactivate the snippet and confirm the original restriction returns.
  • Run npm run env-test -- --filter=Test_Disable_Wp_Rest_Api.

Changelog entry

  • Automatically create a changelog entry from the details below.
Changelog Entry Details

Significance

  • Patch
  • Minor
  • Major

Type

  • Added - for new features
  • Changed - for changes in existing functionality
  • Deprecated - for soon-to-be removed features
  • Removed - for now removed features
  • Fixed - for any bug fixes
  • Security - in case of vulnerabilities

Message

Copilot AI balanced review requested due to automatic review settings October 6, 2026 12:46
@pfefferle pfefferle added the Skip Changelog Disables the "Changelog Updated" action for PRs where changelog entries are not necessary. label Oct 6, 2026
@pfefferle pfefferle self-assigned this Oct 6, 2026
@pfefferle
pfefferle requested a review from a team October 6, 2026 12:47

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The documented installation can overwrite Disable WP REST API and remove its REST restrictions.

Review effort: Balanced
Findings: 1 High severity

Open (1)
What changed in this PR

Adds an opt-in compatibility snippet that keeps ActivityPub endpoints accessible when Disable WP REST API restricts REST access, without changing the main plugin.

Changes:

  • Allows resolved ActivityPub routes while preserving existing allowlist entries.
  • Documents installation and compatibility boundaries.
  • Adds regression tests and snippet-testing guidance.
File Description
tests/​README.md Documents snippet test placement and cleanup.
tests/​phpunit/​tests/​snippets/​disable-wp-rest-api/​class-test-disable-wp-rest-api.php Tests route matching, exclusions, and allowlist preservation.
snippets/​README.md Adds the snippet to the catalog.
snippets/​disable-wp-rest-api/​README.md Explains installation, behavior, and requirements.
snippets/​disable-wp-rest-api/​disable-wp-rest-api.php Implements the ActivityPub route exception.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread snippets/disable-wp-rest-api/README.md
@pfefferle
pfefferle merged commit e5a1c80 into trunk Oct 6, 2026
13 of 14 checks passed
@pfefferle
pfefferle deleted the add/disable-wp-rest-api-snippet branch October 6, 2026 12:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Docs Skip Changelog Disables the "Changelog Updated" action for PRs where changelog entries are not necessary. [Tests] Includes Tests

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants