Why Short Links' API keys only open one door, and webhooks never fire inline
The question: WordPress already ships Application Passwords. Why give Short Links its own API keys, and how should it tell other apps that something changed?
Trust boundaries, capabilities, and safely handling author-supplied code
View All TagsThe question: WordPress already ships Application Passwords. Why give Short Links its own API keys, and how should it tell other apps that something changed?
The question: we are adding a link shortener to Unyson+. What should its storage, defaults and admin look like, and what should it deliberately do differently from the plugins people would be switching from?
The question: What should a WordPress security extension for UnysonPlus actually contain — separating what protects from what only implies protection — and where does a custom admin / login URL belong?
The question: The Forms extension was mail-and-forget — a submission was emailed to the admin and discarded. To make the contact form usable as a booking form, a quote request or a survey, submissions have to be stored somewhere. Since the Newsletter CRM already has a table of people with emails, lists and tags, can the form data just go in there, so everything about a person is in one list?
The question: The Newsletter CRM had only two public endpoints — confirm and unsubscribe. With multiple lists, a subscriber needs a way to say "keep the product news, drop the offers" without leaving entirely. That page needs a credential in the email link, and it needs an answer to the obvious edge case: what does the CRM do when the reader unticks everything and presses Save?
The question: Is there a way to secure the AI Dev Kit code from developers who want to reverse-engineer it — base64, a password an agent has to supply before reading, something like that? And if not, how do you license the intent?
The question: an audit flagged "no rate limiting" on the framework's public AJAX endpoints. But every one of them verifies a nonce, sanitizes its input and validates it. Is a nonce not sufficient?
The question: the Motion Snippet (rung 5 of the GSAP ladder) lets a user type GSAP that executes on the front end. That's arbitrary JavaScript — the same trust surface as a Custom HTML block or a theme's custom-JS box. How do we make it safe without breaking it, and where does the capability check actually belong?