diff --git a/includes/class-spacefast-plugin.php b/includes/class-spacefast-plugin.php index 43a0772..1dfffd3 100644 --- a/includes/class-spacefast-plugin.php +++ b/includes/class-spacefast-plugin.php @@ -235,7 +235,7 @@ public static function create_space(): void { 'idempotency_key' => $idempotency_key, ); } - if ( ! preg_match( '/^team_[A-Za-z0-9_-]+$/', $team_id ) || '' === $title ) { + if ( ! self::valid_space_creation_identity( $team_id, $title ) ) { self::notice( 'error', __( 'Spacefast could not determine the Team or Space name.', 'spacefast-wordpress' ) ); self::redirect(); } @@ -260,6 +260,12 @@ public static function create_space(): void { self::redirect(); } + private static function valid_space_creation_identity( string $team_id, string $title ): bool { + // Team IDs are opaque API identifiers. Do not impose a client-side prefix + // that can drift from the control plane's current identifier format. + return '' !== trim( $team_id ) && '' !== trim( $title ); + } + /** * @param array $space Spacefast Space. * @param array $team Authorized Team. diff --git a/readme.txt b/readme.txt index fb77ee3..8275a76 100644 --- a/readme.txt +++ b/readme.txt @@ -3,7 +3,7 @@ Contributors: spacefast Tags: static site, headless cms, simply static, deployment Requires at least: 6.5 Requires PHP: 8.1 -Stable tag: 0.5.0 +Stable tag: 0.5.1 License: GPLv2 or later Publish a Simply Static export to Spacefast, or rebuild a headless site when WordPress content changes. @@ -31,6 +31,9 @@ OAuth access is limited to the Team you authorize and the mode you choose. WordP == Changelog == += 0.5.1 = +* Accept Spacefast's opaque Team identifiers when creating a Space from WordPress. + = 0.5.0 = * Replace the mode-first wizard with a WordPress-first Publish with Spacefast journey. * Install and activate Simply Static from the primary setup action when permitted. diff --git a/spacefast-wordpress.php b/spacefast-wordpress.php index 84cb17d..1a22663 100644 --- a/spacefast-wordpress.php +++ b/spacefast-wordpress.php @@ -3,7 +3,7 @@ * Plugin Name: Spacefast * Plugin URI: https://spacefast.com/ * Description: Publishes static WordPress exports or rebuilds a headless Spacefast site. - * Version: 0.5.0 + * Version: 0.5.1 * Update URI: https://github.com/spacefast/wordpress * Requires at least: 6.5 * Requires PHP: 8.1 @@ -14,7 +14,7 @@ defined( 'ABSPATH' ) || exit; -define( 'SPACEFAST_WORDPRESS_VERSION', '0.5.0' ); +define( 'SPACEFAST_WORDPRESS_VERSION', '0.5.1' ); define( 'SPACEFAST_WORDPRESS_FILE', __FILE__ ); require_once __DIR__ . '/includes/class-spacefast-settings.php'; diff --git a/tests/acceptance/wordpress.php b/tests/acceptance/wordpress.php index 2fada9f..9be544e 100644 --- a/tests/acceptance/wordpress.php +++ b/tests/acceptance/wordpress.php @@ -113,7 +113,7 @@ function spacefast_accept( bool $condition, string $message ): void { ); $plugin = get_plugin_data( WP_PLUGIN_DIR . '/spacefast-wordpress/spacefast-wordpress.php', false, false ); -spacefast_accept( '0.5.0' === $plugin['Version'], 'Unexpected plugin version.' ); +spacefast_accept( '0.5.1' === $plugin['Version'], 'Unexpected plugin version.' ); spacefast_accept( 'https://github.com/spacefast/wordpress' === $plugin['UpdateURI'], 'Update URI is missing.' ); Spacefast_Settings::disconnect(); diff --git a/tests/behavior.php b/tests/behavior.php index 023bacf..6c4d626 100644 --- a/tests/behavior.php +++ b/tests/behavior.php @@ -328,6 +328,15 @@ static function ( string $url, array $args ) use ( &$create_requests ): array { array( 'teamId' => 'team_demo', 'title' => 'Spacefast Launchpad' ) === json_decode( $create_requests[0][1]['body'], true ), 'creates the Space in the authorized Team with the WordPress site name' ); +$valid_space_creation_identity = new ReflectionMethod( Spacefast_Plugin::class, 'valid_space_creation_identity' ); +check( + true === $valid_space_creation_identity->invoke( null, 'A7bc9DeF2gHi3JkLmN4pQrStUvWxYz01', 'Spacefast Launchpad' ), + 'accepts the opaque Team identifiers returned by Spacefast when creating a Space' +); +check( + false === $valid_space_creation_identity->invoke( null, '', 'Spacefast Launchpad' ), + 'rejects Space creation when the authorized Team is missing' +); $choices_before_creation = get_option( Spacefast_OAuth::CHOICES_OPTION ); Spacefast_OAuth::remember_space_choice( $created_space['data']['space'] ); Spacefast_OAuth::remember_space_choice( $created_space['data']['space'] );