PluginProbe
Code Engine – PHP Snippets, AI Functions & Automation for WordPress / trunk
Code Engine – PHP Snippets, AI Functions & Automation for WordPress vtrunk
0.5.6 0.5.5 0.5.4 0.5.3 0.5.2 0.5.1 0.5.0 0.4.9 0.4.8 0.4.7 0.4.6 trunk 0.0.1 0.0.2 0.2.8 0.2.9 0.3.0 0.3.1 0.3.2 0.3.3 0.3.4 0.3.5 0.3.6 0.3.7 0.3.8 All 32 releases
← All changes | classes/core.php +210 -55 0.4.6trunk View file →
@@ -14,8 +14,12 @@
14 14 public $site_url = null;
15 15 public $mwcode = null;
16 16 public $licenser = null;
17 17
18 + // IDs of global snippets already executed this request (by the plugins_loaded pass
19 + // or by load_global_snippets), so a global never runs twice and never re-declares.
20 + public $loaded_global_ids = [];
21 +
18 22 private $option_name = 'mwcode_options';
19 23
20 24 public function __construct() {
21 25 global $mwcode;
@@ -102,8 +106,9 @@
102 106
103 107 //AI
104 108 "ai_suggestions" => false,
105 109 "ai_engine_status"=> false,
110 + "mwai_active" => false,
106 111 "ai_engine_message" => "",
107 112
108 113 //API
109 114 "api_endpoint" => false,
@@ -110,8 +115,9 @@
110 115 "api_token" => md5( time() . rand() ),
111 116
112 117 //MCP
113 118 "mcp_support" => false,
119 + "mcp_functions" => false,
114 120
115 121 //MAINTENANCE
116 122 "clean_uninstall" => false,
117 123 ];
@@ -185,8 +191,12 @@
185 191
186 192 private function updateAIEngineStatus( &$options ) {
187 193 global $mwai;
188 194
195 + // AI Engine is active (regardless of whether an API key is configured).
196 + // MCP exposure only needs AI Engine present, not a key, so the MCP toggles
197 + // gate on this rather than on mwai_has_ai.
198 + $options['mwai_active'] = !empty( $mwai );
189 199 $options['mwai_has_ai'] = !empty( $mwai ) && method_exists( $mwai, 'hasAI' ) && $mwai->hasAI();
190 200 // Legacy
191 201 $options['ai_engine_status'] = $options['mwai_has_ai'];
192 202
@@ -220,9 +230,24 @@
220 230
221 231 $this->snippet->validate( $params );
222 232
223 233 $params = $this->snippet->formatParamsForDatabase( $params );
224 - $result = $this->snippet->insert( $params );
234 +
235 + // Route to UPDATE when an existing snippet id is provided (updateSnippet / the
236 + // MCP mwcode_update_snippet tool). This previously always insert()ed, so an
237 + // update tried to INSERT a row with an already-used primary key: that fails on
238 + // the SQLite backend (Studio/Playground) with "Could not insert the snippet",
239 + // and duplicates or errors elsewhere. The admin UI was unaffected because it
240 + // calls snippet->update() directly.
241 + $existing = !empty( $params['id'] ) ? $this->snippet->select_one( $params['id'] ) : null;
242 + if ( $existing ) {
243 + $this->snippet->update( $params );
244 + $result = $params['id'];
245 + }
246 + else {
247 + unset( $params['id'] );
248 + $result = $this->snippet->insert( $params );
249 + }
225 250 $snippet = $this->snippet->select_one( $result );
226 251
227 252 if( $result ) {
228 253 $params['id'] = (string)$result;
@@ -337,35 +362,17 @@
337 362 'values' => $snippet['functionArgsDict'] // Contains the default values of the arguments
338 363 ];
339 364 }
340 365
341 - // Sanitize all the arguments if the option is enabled
342 - if ( $this->get_option( 'sanitize_arguments', true ) ) {
366 + // Arguments used to be sanitized into PHP-literal strings here (quoting,
367 + // esc_sql, var_export) so they could be concatenated into a string of PHP and
368 + // eval-ed. That is gone: the function is now called with call_user_func_array
369 + // (see below), so values are passed as data and need no literal-formatting.
370 + // The old formatting also prefixed argument keys with "$" via sanitize_arg,
371 + // which stored the provided value under "$name" while the call read "name", so
372 + // provided arguments never reached the function. Passing the raw values through
373 + // fixes both issues at once.
343 374
344 - if ( $args ) {
345 - foreach ( $args as $name => $value ) {
346 - list( $sanitizedName, $sanitizedValue ) = $this->sanitize_arg( $name, $value );
347 - unset( $args[$name] );
348 -
349 - $args[$sanitizedName] = $sanitizedValue;
350 - }
351 - }
352 -
353 - foreach ( $params['values'] as $name => $value ) {
354 -
355 - if( array_key_exists( 'input', $value) ) {
356 - list( $sanitizedInputName, $sanitizedInputValue ) = $this->sanitize_arg( $name, $value['input'], $value['type'] );
357 - $params['values'][$sanitizedInputName]['input'] = $sanitizedInputValue;
358 - }
359 -
360 - if( array_key_exists( 'default', $value) ) {
361 - list( $sanitizedDefaultValueName, $sanitizedDefaultValue ) = $this->sanitize_arg( $name, $value['default'], $value['type'] );
362 - $params['values'][$sanitizedDefaultValueName]['default'] = $sanitizedDefaultValue;
363 - }
364 - }
365 -
366 - }
367 -
368 375 // Make sure the function is existing and is the one in the snippet
369 376 if ( empty( $params['code'] ) ) {
370 377 throw new Exception( 'Code Engine: The snippet code appears to be empty.' );
371 378 }
@@ -373,17 +380,32 @@
373 380 if ( empty( $params['name'] ) || ! str_contains( $params['code'], $params['name'] ) ) {
374 381 throw new Exception( "Code Engine: Function name does not match. The name should be {$params['name']}." );
375 382 }
376 383
377 - // Overwrite the default values with the provided ones
384 + // Collect the provided values, keyed by their normalized (dollar-less) name.
385 + // Incoming keys come from the AI/MCP schema, where register_function_tools()
386 + // strips a leading "$" from the declared name. The stored arg names can still
387 + // carry the "$", so we normalize both sides before matching below. Without this
388 + // a value provided as "style" never binds to an argument declared "$style".
389 + $provided = [];
378 390 if ( $args ) {
379 391 foreach ( $args as $name => $value ) {
380 - $params['values'][$name]['input'] = $value;
392 + $provided[ ltrim( $name, '$' ) ] = $value;
381 393 }
382 394
383 395 $this->log( '⚡ Arguments provided: ' . json_encode( $args ) );
384 396 }
385 397
398 + // Global snippets are meant to be always accessible. On non-whitelisted REST routes
399 + // (Workflow Engine, MCP, AI function-calling) the plugins_loaded pass blocks them, so
400 + // make sure their helper library is loaded before we run a function that may call it.
401 + $this->load_global_snippets();
402 +
403 + // Make every *other* active PHP function snippet available so this function can
404 + // call its siblings. We pass the current name as the exception so the target is
405 + // still defined below (with the edited/test code when testing), not pre-defined here.
406 + $this->define_all_functions( $params['name'] );
407 +
386 408 // Check if the function has already been defined
387 409 if ( !in_array( $params['name'], $defined_functions ) ) {
388 410
389 411 // If not, proceed with modification and definition
@@ -401,49 +423,58 @@
401 423 // If already defined, just prepare to call the function without redefining it
402 424 $params['code'] = '';
403 425 }
404 426
405 - // Prepare the code to be executed
406 - $params['code'] .= "\n\$mwcode_result = {$params['name']}(";
407 - foreach ( $params['args'] as $index => $arg ) {
408 - $value = 'null'; // In case the argument is not provided it will be null
409 -
410 - if ( array_key_exists( $arg, $params['values'] ) ) { // Avoid warnings if the argument is not provided
411 -
412 - // If the argument is provided, use it, if not use the default value
413 - if ( !empty( $params['values'][$arg]['input'] ) ) {
414 - $value = $params['values'][$arg]['input'];
415 -
416 - } else if ( !empty( $params['values'][$arg]['default'] ) ) {
417 - $value = $params['values'][$arg]['default'];
418 - }
427 + // Resolve the arguments as REAL PHP values, in the function's declared order.
428 + // The previous version concatenated each value into a string of PHP and eval-ed
429 + // the call, which broke on any string or edge-case value with a parse error
430 + // ("syntax error, unexpected token ')'"). call_user_func_array passes them as
431 + // data, so no value can ever corrupt the call syntax.
432 + $callArgs = [];
433 + foreach ( $params['args'] as $arg ) {
434 + $key = ltrim( $arg, '$' ); // Match the normalized name the caller sent.
435 + $value = null; // Not provided and no default -> null.
436 + // array_key_exists, not !empty: a legitimately provided 0, "0", "" or false
437 + // must reach the function instead of silently falling back to the default.
438 + if ( array_key_exists( $key, $provided ) ) {
439 + $value = $provided[ $key ];
440 + } else if ( isset( $params['values'][$arg]['default'] ) && $params['values'][$arg]['default'] !== '' ) {
441 + $value = $params['values'][$arg]['default'];
419 442 }
420 -
421 - $params['code'] .= "{$value}";
422 - if ( $index < count( $params['args'] ) - 1 ) {
423 - $params['code'] .= ', ';
443 + // An array-typed argument can arrive as a string like "[1, 2, 3]"; turn it
444 + // into a real array so the function receives what its signature expects.
445 + if ( ( $params['values'][$arg]['type'] ?? null ) === 'array' && is_string( $value ) ) {
446 + $decoded = json_decode( $value, true );
447 + $value = is_array( $decoded ) ? $decoded : array_map( 'trim', explode( ',', trim( $value, "[] \t\n\r" ) ) );
424 448 }
449 + $callArgs[] = $value;
425 450 }
426 451
427 - $params['code'] .= ");\necho print_r(\$mwcode_result, true);";
428 -
429 452 $error = null;
430 453 $output = null;
431 -
454 +
432 455 try {
433 456 ob_start();
434 - eval( $params['code'] );
457 + // $params['code'] holds the function definition (empty if it was already
458 + // defined earlier this request). Declare it, then invoke it as data.
459 + if ( $params['code'] !== '' ) {
460 + eval( $params['code'] );
461 + }
462 + $mwcode_result = call_user_func_array( $params['name'], $callArgs );
463 + echo print_r( $mwcode_result, true );
435 464 $output = ob_get_clean();
436 -
437 - if ( $params['test'] ){
465 +
466 + if ( $params['test'] ) {
438 467 $output = explode( "\n", $output );
439 468 }
440 -
469 +
441 470 } catch ( Throwable $e ) {
442 471 //$this->log('Code Engine: Error executing the function: ' . $e->getMessage());
443 472 $error = new Exception(' Error executing the function, ' . $e->getMessage());
444 473
445 - ob_clean();
474 + if ( ob_get_level() > 0 ) {
475 + ob_end_clean();
476 + }
446 477 } finally {
447 478 restore_error_handler();
448 479 }
449 480
@@ -495,8 +526,132 @@
495 526 return $lint;
496 527 }
497 528
498 529 return null;
530 + }
531 +
532 + /**
533 + * Load the active global snippets (persistent + backend/frontend for this context)
534 + * that haven't already run this request, so on-demand function execution has the same
535 + * always-available helper library a normal page load would. Callable functions are
536 + * typically small wrappers around these globals.
537 + *
538 + * On non-whitelisted REST routes (Workflow Engine, MCP, AI function-calling) the
539 + * plugins_loaded pass blocks global snippets for safety; this restores them for the
540 + * deliberate, authorized act of executing a snippet. The loaded-id registry guarantees
541 + * each global runs at most once per request, so nothing is ever re-declared.
542 + */
543 + function load_global_snippets() {
544 + global $current_mwcode_snippet;
545 + static $done = false;
546 + if ( $done ) {
547 + return;
548 + }
549 + $done = true;
550 +
551 + if ( empty( $this->snippet ) ) {
552 + $this->snippet = new Meow_MWCODE_Modules_Snippet( $this );
553 + }
554 +
555 + $scope = is_admin() ? [ 'backend', 'persistent' ] : [ 'frontend', 'persistent' ];
556 +
557 + $snippets = $this->snippet->select(
558 + null, // offset
559 + -1, // limit (all)
560 + [
561 + [ 'accessor' => 'active', 'value' => 1 ],
562 + [ 'accessor' => 'scope', 'value' => $scope ],
563 + ],
564 + [ 'accessor' => 'priority', 'by' => 'DESC' ]
565 + )['data'] ?? [];
566 +
567 + foreach ( $snippets as $snippet ) {
568 + // Skip globals already executed this request (e.g. by the plugins_loaded pass).
569 + if ( in_array( $snippet['id'], $this->loaded_global_ids ) ) {
570 + continue;
571 + }
572 + $this->loaded_global_ids[] = $snippet['id'];
573 +
574 + $code = $this->snippet->sanitize_code( $snippet['code'] );
575 + $current_mwcode_snippet = $snippet;
576 + try {
577 + ob_start();
578 + eval( $code );
579 + ob_end_clean();
580 + } catch ( Throwable $e ) {
581 + ob_end_clean();
582 + $this->log( "⚠️ Code Engine: Failed to load global snippet \"{$snippet['name']}\": " . $e->getMessage() );
583 + }
584 + }
585 + $current_mwcode_snippet = null;
586 + }
587 +
588 + /**
589 + * Declare every active PHP function snippet in the current request, without
590 + * invoking any of them, so function snippets can call one another.
591 + *
592 + * Function snippets are not auto-loaded on every request (unlike global/backend/
593 + * frontend scopes) — they are meant to run on demand. This is the PHP counterpart
594 + * to get_js_functions_to_push(): it makes the whole library of functions callable
595 + * before a function is executed (via REST, MCP, AI function-calling, Workflow Engine).
596 + *
597 + * Idempotent: a static guard runs the full pass only once per request, and each
598 + * definition is wrapped in function_exists() so nothing is ever redefined.
599 + *
600 + * @param string|null $except Function name to skip (the one run_snippet is about to
601 + * define itself, so edited/test code keeps priority).
602 + */
603 + function define_all_functions( $except = null ) {
604 + static $loaded = false;
605 + if ( $loaded ) {
606 + return;
607 + }
608 + $loaded = true;
609 +
610 + if ( empty( $this->snippet ) ) {
611 + $this->snippet = new Meow_MWCODE_Modules_Snippet( $this );
612 + }
613 +
614 + // One query for every active function snippet (code included), then enrich with
615 + // the function metadata (name + target) the same way run_snippet does.
616 + $snippets = $this->snippet->select(
617 + null, // offset
618 + -1, // limit (all)
619 + [
620 + [ 'accessor' => 'active', 'value' => 1 ],
621 + [ 'accessor' => 'scope', 'value' => 'function' ],
622 + ],
623 + [] // sort
624 + )['data'] ?? [];
625 +
626 + if ( empty( $snippets ) ) {
627 + return;
628 + }
629 +
630 + $this->snippet->get_function_snippets_data( $snippets );
631 +
632 + foreach ( $snippets as $snippet ) {
633 + $name = $snippet['functionName'] ?? '';
634 + $target = strtolower( $snippet['functionTarget'] ?? 'php' );
635 +
636 + // Skip JS functions (pushed to the front-end separately), the function the
637 + // caller will define itself, and anything already declared in this request.
638 + if ( $name === '' || $target === 'js' || $name === $except || function_exists( $name ) ) {
639 + continue;
640 + }
641 +
642 + // Mirror run_snippet()'s non-test handling: drop echo statements, then declare
643 + // (never call) the function, guarded so a later run_snippet() call is a no-op.
644 + $code = $this->snippet->sanitize_code( $snippet['code'] );
645 + $code = preg_replace( '/echo\s+(.+?);/s', '', $code );
646 + $code = "if (!function_exists('{$name}')) {\n{$code}\n}\n";
647 +
648 + try {
649 + eval( $code );
650 + } catch ( Throwable $e ) {
651 + $this->log( "⚠️ Code Engine: Failed to pre-define function \"{$name}\": " . $e->getMessage() );
652 + }
653 + }
499 654 }
500 655
501 656 public function get_js_functions_to_push() {
502 657 $functions = $this->snippet->get_functions();