Repository navigation
Conversation
…-app#2600) - The control plane writes `FLYWP_BRAND` (the hex of `{name, url, icon}` JSON) on a White Label customer's site. `flywp()->brand()` reads it, then `getenv()` for Bedrock. Anything that does not decode is no brand: the plugin shows FlyWP exactly as before. - Under a brand: the Plugins list row (name, author, URLs, description, no "View details"), the admin bar, the settings page title, header and dashboard button (to the Reseller's address), the email tab, the test email and its template (no FlyWP address), the missing-key notice, the plugin rows sent to the dashboard, core's plugin update email, and Site Health. - `BrandTest` pins the format with a fixed vector the control plane's tests also assert. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01JmBiWG77NN53V6SmxtHdtm
… strip tags on decode Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01JmBiWG77NN53V6SmxtHdtm
…r URLs, today's defaults kept - The update email: rebuilt from core's own item and translated format, so this plugin's line is found in any language, and a plugin named "FlyWP …" is left alone. - A brand URL needs a host and takes no query or fragment; no URL ends in a newline. - Without a brand, `dashboard_url( 0 )` names site 0 as before, and the test email matches the 1.7.1 template byte for byte (a fixture). - Site Health keeps the entry in its place. Hex is checked with a regex (no ext-ctype). Bedrock also reads `$_ENV` / `$_SERVER`. - `BrandingTest` covers the four hooks, with a few WordPress stand-ins. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01JmBiWG77NN53V6SmxtHdtm
- The control plane sends `url` as null until the reseller confirms an address. - `Brand::decode()` needs a name only; a missing or bad URL gives `url()` and `dashboard_url()` as ''. - The settings page hides the dashboard button and the SMTP link then. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01JmBiWG77NN53V6SmxtHdtm
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
On a FlyWP White Label customer's site, the plugin shows the hosting Reseller's brand instead of "FlyWP" (flywp/flywp-app#2600).
FLYWP_BRAND(the hex of{name, url, icon}JSON). It goes inwp-config.php, or in the.envon Bedrock (getenv(), then$_ENV/$_SERVER).urlis null until the Reseller confirms an address. The brand's name shows, with no dashboard button and no SMTP link.Where the brand shows
{Reseller address}/site/{id}, the page where the customer signs in./fly-api/pluginsand the updates data.Not changed, on purpose:
?page=flywpslug,/fly-api/*and/flywp-magic-login;Testing
BrandTest:BrandingTest: the four hooks, with a few WordPress stand-ins. No hook is added without a brand.<script>…): it found a stored XSS in the admin menu title, fixed here (escaped, and tags stripped on decode).Known limits
%s. Existing translations show English there until they are updated.href="").Release
Before release:
flywp.phpis still 1.7.1. FollowRELEASE.md:bin/bump-version.sh <next version>.readme.txt.yarn build, which also regenerateslanguages/flywp.potfor the four changed strings.Release this to wp.org first. Sites get it by auto-update, and with no
FLYWP_BRANDnothing changes. The app then writes the brand: flywp/flywp-app#2662.🤖 Generated with Claude Code