Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 7 additions & 1 deletion includes/class-spacefast-plugin.php
Original file line number Diff line number Diff line change
Expand Up @@ -235,7 +235,7 @@ public static function create_space(): void {
'idempotency_key' => $idempotency_key,
);
}
if ( ! preg_match( '/^team_[A-Za-z0-9_-]+$/', $team_id ) || '' === $title ) {
if ( ! self::valid_space_creation_identity( $team_id, $title ) ) {
self::notice( 'error', __( 'Spacefast could not determine the Team or Space name.', 'spacefast-wordpress' ) );
self::redirect();
}
Expand All @@ -260,6 +260,12 @@ public static function create_space(): void {
self::redirect();
}

private static function valid_space_creation_identity( string $team_id, string $title ): bool {
// Team IDs are opaque API identifiers. Do not impose a client-side prefix
// that can drift from the control plane's current identifier format.
return '' !== trim( $team_id ) && '' !== trim( $title );
}

/**
* @param array<string,mixed> $space Spacefast Space.
* @param array<string,mixed> $team Authorized Team.
Expand Down
5 changes: 4 additions & 1 deletion readme.txt
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@ Contributors: spacefast
Tags: static site, headless cms, simply static, deployment
Requires at least: 6.5
Requires PHP: 8.1
Stable tag: 0.5.0
Stable tag: 0.5.1
License: GPLv2 or later

Publish a Simply Static export to Spacefast, or rebuild a headless site when WordPress content changes.
Expand Down Expand Up @@ -31,6 +31,9 @@ OAuth access is limited to the Team you authorize and the mode you choose. WordP

== Changelog ==

= 0.5.1 =
* Accept Spacefast's opaque Team identifiers when creating a Space from WordPress.

= 0.5.0 =
* Replace the mode-first wizard with a WordPress-first Publish with Spacefast journey.
* Install and activate Simply Static from the primary setup action when permitted.
Expand Down
4 changes: 2 additions & 2 deletions spacefast-wordpress.php
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@
* Plugin Name: Spacefast
* Plugin URI: https://spacefast.com/
* Description: Publishes static WordPress exports or rebuilds a headless Spacefast site.
* Version: 0.5.0
* Version: 0.5.1
* Update URI: https://github.com/spacefast/wordpress
* Requires at least: 6.5
* Requires PHP: 8.1
Expand All @@ -14,7 +14,7 @@

defined( 'ABSPATH' ) || exit;

define( 'SPACEFAST_WORDPRESS_VERSION', '0.5.0' );
define( 'SPACEFAST_WORDPRESS_VERSION', '0.5.1' );
define( 'SPACEFAST_WORDPRESS_FILE', __FILE__ );

require_once __DIR__ . '/includes/class-spacefast-settings.php';
Expand Down
2 changes: 1 addition & 1 deletion tests/acceptance/wordpress.php
Original file line number Diff line number Diff line change
Expand Up @@ -113,7 +113,7 @@ function spacefast_accept( bool $condition, string $message ): void {
);

$plugin = get_plugin_data( WP_PLUGIN_DIR . '/spacefast-wordpress/spacefast-wordpress.php', false, false );
spacefast_accept( '0.5.0' === $plugin['Version'], 'Unexpected plugin version.' );
spacefast_accept( '0.5.1' === $plugin['Version'], 'Unexpected plugin version.' );
spacefast_accept( 'https://github.com/spacefast/wordpress' === $plugin['UpdateURI'], 'Update URI is missing.' );

Spacefast_Settings::disconnect();
Expand Down
9 changes: 9 additions & 0 deletions tests/behavior.php
Original file line number Diff line number Diff line change
Expand Up @@ -328,6 +328,15 @@ static function ( string $url, array $args ) use ( &$create_requests ): array {
array( 'teamId' => 'team_demo', 'title' => 'Spacefast Launchpad' ) === json_decode( $create_requests[0][1]['body'], true ),
'creates the Space in the authorized Team with the WordPress site name'
);
$valid_space_creation_identity = new ReflectionMethod( Spacefast_Plugin::class, 'valid_space_creation_identity' );
check(
true === $valid_space_creation_identity->invoke( null, 'A7bc9DeF2gHi3JkLmN4pQrStUvWxYz01', 'Spacefast Launchpad' ),
'accepts the opaque Team identifiers returned by Spacefast when creating a Space'
);
check(
false === $valid_space_creation_identity->invoke( null, '', 'Spacefast Launchpad' ),
'rejects Space creation when the authorized Team is missing'
);
$choices_before_creation = get_option( Spacefast_OAuth::CHOICES_OPTION );
Spacefast_OAuth::remember_space_choice( $created_space['data']['space'] );
Spacefast_OAuth::remember_space_choice( $created_space['data']['space'] );
Expand Down
Loading