| @@ -173,9 +173,15 @@ | ||
| 173 | 173 | |
| 174 | 174 | return $result; |
| 175 | 175 | } |
| 176 | 176 | |
| 177 | - foreach ( [ $pretty, $rest, $discovery, $challenge, $user_agent ] as $check ) { | |
| 177 | + // `$user_agent` is deliberately not in this list. It is the one check that | |
| 178 | + // does not measure this server: it probes what a *generic* HTTP client | |
| 179 | + // sees, and a host that refuses those may still answer the AI client's own | |
| 180 | + // User-Agent — which cannot be known from here. Letting that proxy signal | |
| 181 | + // overrule four checks that completed a real round trip reported working | |
| 182 | + // sites as broken (ADR-067). It is still reported, as its own warning row. | |
| 183 | + foreach ( [ $pretty, $rest, $discovery, $challenge ] as $check ) { | |
| 178 | 184 | if ( null === $check || 'ok' === $check['stage'] ) { |
| 179 | 185 | continue; |
| 180 | 186 | } |
| 181 | 187 | |
| @@ -693,14 +699,16 @@ | ||
| 693 | 699 | ]; |
| 694 | 700 | } |
| 695 | 701 | |
| 696 | 702 | /** |
| 697 | - * Detect a host that answers WordPress but refuses AI clients by User-Agent. | |
| 703 | + * Detect a host that answers WordPress but refuses generic clients by User-Agent. | |
| 698 | 704 | * |
| 699 | - * A blind spot worth stating plainly: this runs from the server's own IP, | |
| 700 | - * which host firewalls usually trust, so it catches User-Agent filtering but | |
| 701 | - * **not** an IP-range block of the AI vendor. A green result here does not | |
| 702 | - * prove an external client can connect. | |
| 705 | + * Two blind spots, both worth stating plainly. This runs from the server's own | |
| 706 | + * IP, which host firewalls usually trust, so it catches User-Agent filtering | |
| 707 | + * but **not** an IP-range block of the AI vendor: a green result does not prove | |
| 708 | + * an external client can connect. And the User-Agents below are representative, | |
| 709 | + * not the ones any particular vendor sends, so a red result does not prove one | |
| 710 | + * cannot — which is why this never sets the overall verdict (ADR-067). | |
| 703 | 711 | * |
| 704 | 712 | * @since 4.9.0 |
| 705 | 713 | * |
| 706 | 714 | * @param string $endpoint Pretty endpoint URL. |
| @@ -729,9 +737,9 @@ | ||
| 729 | 737 | return [ |
| 730 | 738 | 'stage' => 'ua_filter', |
| 731 | 739 | 'detail' => sprintf( |
| 732 | 740 | /* translators: 1: the User-Agent string tried, 2: the HTTP status it received, 3: the HTTP status WordPress' own User-Agent received. */ |
| 733 | - __( 'The endpoint answered %3$d for WordPress but %2$d for an AI client\'s User-Agent (%1$s). A security plugin, firewall or "block bad bots" rule is refusing non-browser clients — exempt the MCP and /.well-known/ paths, or no AI client will ever reach this site.', 'betterdocs' ), | |
| 741 | + __( 'The endpoint answered %3$d for WordPress but %2$d for a generic HTTP client\'s User-Agent (%1$s). A security plugin, firewall or "block bad bots" rule is refusing non-browser clients. Whether that affects your assistant depends on the User-Agent it sends, which this test cannot see — connect it and check that tools load. If they do not, exempt the MCP and /.well-known/ paths.', 'betterdocs' ), | |
| 734 | 742 | $agent, |
| 735 | 743 | $status, |
| 736 | 744 | $baseline |
| 737 | 745 | ) |
| @@ -739,9 +747,9 @@ | ||
| 739 | 747 | } |
| 740 | 748 | |
| 741 | 749 | return [ |
| 742 | 750 | 'stage' => 'ok', |
| 743 | - 'detail' => __( 'The endpoint answers AI-client User-Agents the same way it answers WordPress, so no bot filter is blocking them. This cannot see an IP-level block of the AI vendor.', 'betterdocs' ) | |
| 751 | + 'detail' => __( 'The endpoint answers generic HTTP clients the same way it answers WordPress, so no bot filter is refusing them. This cannot see an IP-level block of the AI vendor.', 'betterdocs' ) | |
| 744 | 752 | ]; |
| 745 | 753 | } |
| 746 | 754 | |
| 747 | 755 | /** |