READ-ONLY PACKAGE PREVIEW

wp-rest-api/examples/README.md

Version 34da134e184e.bb2 · GPL-2.0-or-later. This preview displays packaged text and does not execute code. Treat the contents as untrusted instructions.

← Return to resource and package checksum

Reproduce the bounded WordPress REST fixture

BB Skills example sources and recorded evidence are GPL-2.0-or-later. The upstream WordPress contributor grant and complete GPLv2 text are in the package root.

This is a hand-authored synthetic protocol fixture, not an AI-agent or complete-skill evaluation. Recorded environment: WordPress 7.1.2, PHP 8.3.35, MariaDB 11.4.13, Python 3.13.16. See native-rest-evidence.json for image IDs/digests, exact source hashes and all 27 observations.

Use a disposable Linux Docker host with Python 3, internet access for official image downloads, and Docker permissions. Keep all example files together. Allow around 1.7 GiB of temporary container memory plus normal host overhead. The runner refuses to replace any existing container/network with its fixture names, publishes no ports, uses an internal network and temporary database/WordPress filesystems, and cleans them in finally. A host interruption can prevent cleanup; inspect only the named fixture resources before removing them. It does not mount a production database, environment file, socket, website or browser profile.

The recorded run reused the catalog's Python image. On your own host you can choose a public Python image:

docker pull python:3.13-slim-trixie
export BB_REST_PROBE_IMAGE=python:3.13-slim-trixie
python3 ./run-wordpress-rest-fixture.py

The runner downloads WordPress 7.1.2 / PHP 8.3 Apache and MariaDB 11.4 if absent. Tags may be rebuilt: compare the new report's digests and versions with the recorded evidence when assessing reproducibility. It captures generated fixture credentials in process memory, revokes the two application passwords before the last requests and writes only non-secret synthetic responses to native-rest-evidence.json. It makes no AI calls or paid service purchases.

The plugin intentionally contains weak-auth-only as a negative control. Do not deploy it to a real WordPress installation. The test uses internal HTTP with WP_ENVIRONMENT_TYPE=local; use HTTPS for a real external application-password client. This fixture does not test TLS, third-party auth plugins, a browser login flow, production content, load/performance, multisite or the upstream triage helper.

The valid Cookie nonce is generated in a fresh PHP bootstrap after installation, so COOKIEHASH reflects the final site URL. A revoked application password in the recorded environment returned HTTP 401 with rest_not_logged_in; that is the observed core path, not a promise about every site's plugins.