PluginProbe
OpenStation: Desktop Windows, Dock & Virtual Desktops for WP Admin / 1.1.12
OpenStation: Desktop Windows, Dock & Virtual Desktops for WP Admin v1.1.12
1.1.12 1.1.11 1.1.10 1.1.9 1.1.8 1.1.7 1.1.6 1.1.5 1.1.4 1.1.3 1.1.2 1.1.1 1.1.0 1.0.1 1.0.0 0.9.8 0.9.7 0.9.6 0.9.4 0.9.5 0.9.3 0.9.2 0.9.1 0.9.0 0.8.9 All 36 releases
← All changes | includes/ai-copilot/search.php +986 -729 0.9.1 → 1.1.12 View file →
@@ -1,18 +1,24 @@
1 1 <?php
2 2 /**
3 - * Desktop Mode — AI Copilot content search via OpenAI tool use.
3 + * OpenStation — AI Copilot content search via the provider tool use.
4 4 *
5 5 * Agentic search loop: the user describes something in natural language and
6 - * the OpenAI agent calls focused tools — search_posts, search_pages,
7 - * search_comments — choosing the right one based on query semantics. Each
8 - * tool runs WordPress's native search (WP_Query `s=` / get_comments
9 - * `search=`) for the keywords the model distils from the request, then
10 - * returns up to 10 matching entities with their real title + content
11 - * excerpt for the model to compare to the user's description. No AI
12 - * pre-analysis is required — every published post/page/comment is findable.
6 + * the agent calls focused tools, choosing the right one based on query
7 + * semantics. Built-in tools: four content-search tools — search_posts,
8 + * search_pages, search_comments, search_comments_by_post — plus
9 + * list_admin_pages (admin navigation catalog), search_wporg_plugins
10 + * (WordPress.org plugin directory), and get_php_error_log (error-log
11 + * tail). Each content-search tool runs WordPress's native search
12 + * (WP_Query `s=` / get_comments `search=`) for the keywords the model
13 + * distils from the request, then returns up to 10 matching entities with
14 + * their real title + content excerpt for the model to compare to the
15 + * user's description. No AI pre-analysis is required — every published
16 + * post/page/comment is findable. The built-in tools are WordPress Abilities
17 + * (see abilities.php); client command tools are advertised alongside them and
18 + * dispatched by the same loop.
13 19 *
14 - * Three tools instead of one parameter:
20 + * Focused tools instead of one routing parameter:
15 21 * - "I remember a comment where someone said congratulations…" → agent
16 22 * calls search_comments without needing a routing parameter.
17 23 * - "I wrote a post about paella in Canarias" → agent calls search_posts.
18 24 * - "Our About page mentions…" → agent calls search_pages.
@@ -18,210 +24,230 @@
18 24 * - "Our About page mentions…" → agent calls search_pages.
19 25 * - Ambiguous queries → agent tries in priority order (posts → pages →
20 26 * comments) following the system-prompt guidance.
21 27 *
22 - * Budget: max DESKTOP_MODE_AI_SEARCH_MAX_ITERATIONS (10) tool-call rounds per
23 - * request × DESKTOP_MODE_AI_SEARCH_BATCH_SIZE (10) items = up to 100 entities.
28 + * Budget: max OPENSTATION_AI_SEARCH_MAX_ITERATIONS (10) tool-call rounds per
29 + * request × OPENSTATION_AI_SEARCH_BATCH_SIZE (10) items = up to 100 entities.
24 30 * When the budget is exhausted the response includes a `continue` object
25 31 * the client uses to resume from the exact offset that was last searched.
26 32 *
27 33 * REST endpoint: POST /desktop-mode/v1/ai/search
28 34 *
29 - * @package WPDesktopMode
35 + * @package OpenStation
30 36 */
31 37
32 38 defined( 'ABSPATH' ) || exit;
33 39
34 40 /** Maximum agentic tool-call iterations per search request. */
35 -const DESKTOP_MODE_AI_SEARCH_MAX_ITERATIONS = 10;
41 +const OPENSTATION_AI_SEARCH_MAX_ITERATIONS = 10;
36 42
37 43 /** Entities fetched per tool-call round. */
38 -const DESKTOP_MODE_AI_SEARCH_BATCH_SIZE = 10;
44 +const OPENSTATION_AI_SEARCH_BATCH_SIZE = 10;
39 45
40 -// ---------------------------------------------------------------------------
41 -// Tool definitions — one per entity type so the model picks semantically
42 -// ---------------------------------------------------------------------------
43 -
44 46 /**
45 - * Returns all three search tools as an array ready for the OpenAI `tools`
46 - * field. Providing three focused tools (rather than one with an entity_type
47 - * parameter) lets the model reason about the query — "someone said X" →
48 - * search_comments; "I published a post about Y" → search_posts — without
49 - * needing an explicit routing hint from the user or the system prompt.
47 + * Returns the catalog of common WordPress admin destinations.
50 48 *
51 - * Each tool schema uses `strict: true` with a single `offset` parameter so
52 - * the model can never hallucinate extra arguments.
49 + * Used by the `list_admin_pages` tool. Each entry has a human title, the
50 + * wp-admin URL (rendered through admin_url() so it respects the site's
51 + * real admin path), a short description, and a Dashicons icon class the
52 + * UI can use when opening the URL in a legacy iframe window.
53 53 *
54 - * @since 0.14.0
54 + * Filterable via `openstation_ai_admin_page_catalog` so third-party
55 + * plugins can contribute their own admin destinations (e.g. a plugin
56 + * adding a top-level menu can surface its settings page here).
55 57 *
56 58 * @return array[]
57 59 */
58 -function desktop_mode_ai_search_tool_definitions() {
59 - // Responses API tool definitions are FLAT — no nested `function` wrapper.
60 - // The `type`, `name`, `description`, and `parameters` sit at the top level.
61 - $query_offset_param = array(
62 - 'type' => 'object',
63 - 'additionalProperties' => false,
64 - 'required' => array( 'query', 'offset' ),
65 - 'properties' => array(
66 - 'query' => array(
67 - 'type' => 'string',
68 - 'description' => 'Keyword search terms matched against the title and content (WordPress native search). Distil the user\'s request to the essential nouns — e.g. for "that post I wrote about making paella" pass "paella". Avoid stop-words and full sentences.',
69 - ),
70 - 'offset' => array(
71 - 'type' => 'integer',
72 - 'description' => 'Zero-based starting position. Use 0 for the first batch, 10 for the second, and so on.',
73 - ),
60 +function openstation_ai_get_admin_page_catalog() {
61 + $catalog = array(
62 + array(
63 + 'title' => __( 'Dashboard', 'desktop-mode' ),
64 + 'url' => admin_url( 'index.php' ),
65 + 'icon' => 'dashicons-dashboard',
66 + 'description' => __( 'The main admin dashboard: activity, drafts, site overview.', 'desktop-mode' ),
74 67 ),
75 - );
76 -
77 - return array(
78 68 array(
79 - 'type' => 'function',
80 - 'name' => 'search_posts',
81 - 'description' => 'Keyword-searches published WordPress blog posts by title and content (WordPress native search). Use this when the user is looking for content they or someone else wrote as a post or article. Pass the key search terms as `query`. Returns up to 10 matching posts with their title, a content excerpt, date, and URLs. If has_more is true, call again with the next offset.',
82 - 'parameters' => $query_offset_param,
69 + 'title' => __( 'All Posts', 'desktop-mode' ),
70 + 'url' => admin_url( 'edit.php' ),
71 + 'icon' => 'dashicons-admin-post',
72 + 'description' => __( 'List, edit, bulk-manage blog posts.', 'desktop-mode' ),
83 73 ),
84 74 array(
85 - 'type' => 'function',
86 - 'name' => 'search_pages',
87 - 'description' => 'Keyword-searches published WordPress pages (About, Contact, Services, Portfolio, etc.) by title and content. Use this when the user is looking for a static page, landing page, or informational page on the site. Pass the key search terms as `query`. Returns up to 10 matching pages with their title, a content excerpt, and URLs. If has_more is true, call again with the next offset.',
88 - 'parameters' => $query_offset_param,
75 + 'title' => __( 'Add New Post', 'desktop-mode' ),
76 + 'url' => admin_url( 'post-new.php' ),
77 + 'icon' => 'dashicons-plus',
78 + 'description' => __( 'Create a new blog post.', 'desktop-mode' ),
89 79 ),
90 80 array(
91 - 'type' => 'function',
92 - 'name' => 'search_comments',
93 - 'description' => 'Keyword-searches approved WordPress comments across ALL posts by their text (WordPress native search). Use this when the user remembers something a reader said but does not know which post it was on. Pass the distinctive words from the comment as `query`. Returns up to 10 matching comments with an excerpt, parent post title, and URLs. If has_more is true, call again with the next offset.',
94 - 'parameters' => $query_offset_param,
81 + 'title' => __( 'Categories', 'desktop-mode' ),
82 + 'url' => admin_url( 'edit-tags.php?taxonomy=category' ),
83 + 'icon' => 'dashicons-category',
84 + 'description' => __( 'Manage post categories: add, rename, merge.', 'desktop-mode' ),
95 85 ),
96 86 array(
97 - 'type' => 'function',
98 - 'name' => 'search_comments_by_post',
99 - 'description' => 'Keyword-searches approved comments on a SPECIFIC post by its WordPress ID. Use this when you have already identified a post (via search_posts) and the user\'s query also mentions something a reader said on that post — e.g. "I remember a comment on my Málaga post asking about the Alcazaba at night." Call search_posts first to find the post ID, then call this tool with that ID and the distinctive words as `query`. Much more precise than search_comments when the parent post is known. If has_more is true, call again with the next offset.',
100 - 'parameters' => array(
101 - 'type' => 'object',
102 - 'additionalProperties' => false,
103 - 'required' => array( 'post_id', 'query', 'offset' ),
104 - 'properties' => array(
105 - 'post_id' => array(
106 - 'type' => 'integer',
107 - 'description' => 'The WordPress ID of the post whose comments should be searched. Obtain this from a prior search_posts call.',
108 - ),
109 - 'query' => array(
110 - 'type' => 'string',
111 - 'description' => 'Keyword search terms matched against the comment text. Pass the distinctive words the user remembers; use an empty string to list the post\'s comments without keyword filtering.',
112 - ),
113 - 'offset' => array(
114 - 'type' => 'integer',
115 - 'description' => 'Zero-based starting position. Use 0 for the first batch, 10 for the second, and so on.',
116 - ),
117 - ),
118 - ),
87 + 'title' => __( 'Tags', 'desktop-mode' ),
88 + 'url' => admin_url( 'edit-tags.php?taxonomy=post_tag' ),
89 + 'icon' => 'dashicons-tag',
90 + 'description' => __( 'Manage post tags.', 'desktop-mode' ),
119 91 ),
120 92 array(
121 - 'type' => 'function',
122 - 'name' => 'list_admin_pages',
123 - 'description' => 'Returns the full catalog of WordPress admin (wp-admin) destinations — pages for managing posts, categories, users, plugins, themes, settings, etc. Call this when the user asks "where can I find X?", "how do I get to Y?", "where are the settings for Z?" — any navigational question about the admin UI. Once you have the catalog, select the 1-3 most relevant entries for the user\'s query and include them in your answer under admin_links with answer_type="navigation". The catalog is small and stable so one call is enough.',
124 - 'parameters' => array(
125 - 'type' => 'object',
126 - 'additionalProperties' => false,
127 - 'required' => array(),
128 - 'properties' => new stdClass(),
129 - ),
93 + 'title' => __( 'All Pages', 'desktop-mode' ),
94 + 'url' => admin_url( 'edit.php?post_type=page' ),
95 + 'icon' => 'dashicons-admin-page',
96 + 'description' => __( 'List and edit static pages (About, Contact, etc.).', 'desktop-mode' ),
130 97 ),
131 98 array(
132 - 'type' => 'function',
133 - 'name' => 'search_wporg_plugins',
134 - 'description' => 'Searches the official WordPress.org plugin directory. Use this when the user asks for a plugin recommendation — e.g. "is there a plugin for SEO?", "find me a backup plugin", "a caching plugin", "form builder". Returns up to 10 plugins with name, description, rating, active install count, and an admin URL that opens the plugin-info / install screen directly. Present the results as admin_links with answer_type="navigation", titled "Plugin Name · 5M+ installs · 4.8★".',
135 - 'parameters' => array(
136 - 'type' => 'object',
137 - 'additionalProperties' => false,
138 - 'required' => array( 'query' ),
139 - 'properties' => array(
140 - 'query' => array(
141 - 'type' => 'string',
142 - 'description' => 'Plain-language search terms — e.g. "seo", "backup", "caching", "woocommerce", "contact form".',
143 - ),
144 - ),
145 - ),
99 + 'title' => __( 'Add New Page', 'desktop-mode' ),
100 + 'url' => admin_url( 'post-new.php?post_type=page' ),
101 + 'icon' => 'dashicons-plus',
102 + 'description' => __( 'Create a new page.', 'desktop-mode' ),
146 103 ),
147 104 array(
148 - 'type' => 'function',
149 - 'name' => 'get_php_error_log',
150 - 'description' => 'Reads the most recent entries from the site\'s PHP error log — typically wp-content/debug.log when WP_DEBUG_LOG is enabled, or the path set by the PHP error_log directive. Use this when the user asks "are there any errors?", "check the logs", "what went wrong?", or is troubleshooting a white screen / 500. Each entry is parsed into { timestamp, level, message } so you can summarise them. Administrators only — the tool returns an error for non-admins.',
151 - 'parameters' => array(
152 - 'type' => 'object',
153 - 'additionalProperties' => false,
154 - 'required' => array( 'lines' ),
155 - 'properties' => array(
156 - 'lines' => array(
157 - 'type' => 'integer',
158 - 'description' => 'How many recent log lines to return (1-500). Use 20-50 for a quick look, 100-200 for wider context.',
159 - ),
160 - ),
161 - ),
105 + 'title' => __( 'Media Library', 'desktop-mode' ),
106 + 'url' => admin_url( 'upload.php' ),
107 + 'icon' => 'dashicons-admin-media',
108 + 'description' => __( 'Browse, upload, and manage images, files, videos.', 'desktop-mode' ),
162 109 ),
110 + array(
111 + 'title' => __( 'Comments', 'desktop-mode' ),
112 + 'url' => admin_url( 'edit-comments.php' ),
113 + 'icon' => 'dashicons-admin-comments',
114 + 'description' => __( 'Moderate and reply to comments on posts and pages.', 'desktop-mode' ),
115 + ),
116 + array(
117 + 'title' => __( 'Themes', 'desktop-mode' ),
118 + 'url' => admin_url( 'themes.php' ),
119 + 'icon' => 'dashicons-admin-appearance',
120 + 'description' => __( 'Change, install, or customize the active theme.', 'desktop-mode' ),
121 + ),
122 + array(
123 + 'title' => __( 'Customize', 'desktop-mode' ),
124 + 'url' => admin_url( 'customize.php' ),
125 + 'icon' => 'dashicons-admin-customizer',
126 + 'description' => __( 'Live-preview theme customisation: colors, fonts, layout.', 'desktop-mode' ),
127 + ),
128 + array(
129 + 'title' => __( 'Widgets', 'desktop-mode' ),
130 + 'url' => admin_url( 'widgets.php' ),
131 + 'icon' => 'dashicons-screenoptions',
132 + 'description' => __( 'Manage sidebar and footer widgets.', 'desktop-mode' ),
133 + ),
134 + array(
135 + 'title' => __( 'Menus', 'desktop-mode' ),
136 + 'url' => admin_url( 'nav-menus.php' ),
137 + 'icon' => 'dashicons-menu',
138 + 'description' => __( 'Create and edit navigation menus.', 'desktop-mode' ),
139 + ),
140 + array(
141 + 'title' => __( 'Plugins', 'desktop-mode' ),
142 + 'url' => admin_url( 'plugins.php' ),
143 + 'icon' => 'dashicons-admin-plugins',
144 + 'description' => __( 'Activate, deactivate, update or delete plugins.', 'desktop-mode' ),
145 + ),
146 + array(
147 + 'title' => __( 'Add New Plugin', 'desktop-mode' ),
148 + 'url' => admin_url( 'plugin-install.php' ),
149 + 'icon' => 'dashicons-plus',
150 + 'description' => __( 'Search and install new plugins from the directory.', 'desktop-mode' ),
151 + ),
152 + array(
153 + 'title' => __( 'Users', 'desktop-mode' ),
154 + 'url' => admin_url( 'users.php' ),
155 + 'icon' => 'dashicons-admin-users',
156 + 'description' => __( 'Manage user accounts and roles.', 'desktop-mode' ),
157 + ),
158 + array(
159 + 'title' => __( 'Add New User', 'desktop-mode' ),
160 + 'url' => admin_url( 'user-new.php' ),
161 + 'icon' => 'dashicons-plus',
162 + 'description' => __( 'Create a new user account.', 'desktop-mode' ),
163 + ),
164 + array(
165 + 'title' => __( 'Your Profile', 'desktop-mode' ),
166 + 'url' => admin_url( 'profile.php' ),
167 + 'icon' => 'dashicons-id',
168 + 'description' => __( 'Edit your own profile, password, admin colour scheme.', 'desktop-mode' ),
169 + ),
170 + array(
171 + 'title' => __( 'General Settings', 'desktop-mode' ),
172 + 'url' => admin_url( 'options-general.php' ),
173 + 'icon' => 'dashicons-admin-settings',
174 + 'description' => __( 'Site title, tagline, URL, timezone, language.', 'desktop-mode' ),
175 + ),
176 + array(
177 + 'title' => __( 'Writing Settings', 'desktop-mode' ),
178 + 'url' => admin_url( 'options-writing.php' ),
179 + 'icon' => 'dashicons-edit',
180 + 'description' => __( 'Default post category, post format, remote publishing.', 'desktop-mode' ),
181 + ),
182 + array(
183 + 'title' => __( 'Reading Settings', 'desktop-mode' ),
184 + 'url' => admin_url( 'options-reading.php' ),
185 + 'icon' => 'dashicons-book',
186 + 'description' => __( 'Homepage, blog posts per page, search-engine visibility.', 'desktop-mode' ),
187 + ),
188 + array(
189 + 'title' => __( 'Discussion Settings', 'desktop-mode' ),
190 + 'url' => admin_url( 'options-discussion.php' ),
191 + 'icon' => 'dashicons-format-chat',
192 + 'description' => __( 'Comment moderation, avatars, email notifications.', 'desktop-mode' ),
193 + ),
194 + array(
195 + 'title' => __( 'Media Settings', 'desktop-mode' ),
196 + 'url' => admin_url( 'options-media.php' ),
197 + 'icon' => 'dashicons-format-image',
198 + 'description' => __( 'Image size settings for thumbnail / medium / large.', 'desktop-mode' ),
199 + ),
200 + array(
201 + 'title' => __( 'Permalinks', 'desktop-mode' ),
202 + 'url' => admin_url( 'options-permalink.php' ),
203 + 'icon' => 'dashicons-admin-links',
204 + 'description' => __( 'URL structure for posts, pages, categories, tags.', 'desktop-mode' ),
205 + ),
206 + array(
207 + 'title' => __( 'Privacy', 'desktop-mode' ),
208 + 'url' => admin_url( 'options-privacy.php' ),
209 + 'icon' => 'dashicons-privacy',
210 + 'description' => __( 'Privacy policy page selection and preview.', 'desktop-mode' ),
211 + ),
212 + array(
213 + 'title' => __( 'Tools', 'desktop-mode' ),
214 + 'url' => admin_url( 'tools.php' ),
215 + 'icon' => 'dashicons-admin-tools',
216 + 'description' => __( 'Built-in site tools.', 'desktop-mode' ),
217 + ),
218 + array(
219 + 'title' => __( 'Import', 'desktop-mode' ),
220 + 'url' => admin_url( 'import.php' ),
221 + 'icon' => 'dashicons-download',
222 + 'description' => __( 'Import content from other platforms (WP, Tumblr, RSS, etc.).', 'desktop-mode' ),
223 + ),
224 + array(
225 + 'title' => __( 'Export', 'desktop-mode' ),
226 + 'url' => admin_url( 'export.php' ),
227 + 'icon' => 'dashicons-upload',
228 + 'description' => __( 'Export all site content as XML.', 'desktop-mode' ),
229 + ),
230 + array(
231 + 'title' => __( 'Site Health', 'desktop-mode' ),
232 + 'url' => admin_url( 'site-health.php' ),
233 + 'icon' => 'dashicons-heart',
234 + 'description' => __( 'Performance and security recommendations for the site.', 'desktop-mode' ),
235 + ),
236 + array(
237 + 'title' => __( 'Updates', 'desktop-mode' ),
238 + 'url' => admin_url( 'update-core.php' ),
239 + 'icon' => 'dashicons-update',
240 + 'description' => __( 'WordPress, theme, and plugin updates.', 'desktop-mode' ),
241 + ),
163 242 );
164 -}
165 243
166 -/**
167 - * Returns the catalog of common WordPress admin destinations.
168 - *
169 - * Used by the `list_admin_pages` tool. Each entry has a human title, the
170 - * wp-admin URL (rendered through admin_url() so it respects the site's
171 - * real admin path), a short description, and a Dashicons icon class the
172 - * UI can use when opening the URL in a legacy iframe window.
173 - *
174 - * Filterable via `desktop_mode_ai_admin_page_catalog` so third-party
175 - * plugins can contribute their own admin destinations (e.g. a plugin
176 - * adding a top-level menu can surface its settings page here).
177 - *
178 - * @since 0.14.0
179 - *
180 - * @return array[]
181 - */
182 -function desktop_mode_ai_get_admin_page_catalog() {
183 - $catalog = array(
184 - array( 'title' => 'Dashboard', 'url' => admin_url( 'index.php' ), 'icon' => 'dashicons-dashboard', 'description' => 'The main admin dashboard — activity, drafts, site overview.' ),
185 - array( 'title' => 'All Posts', 'url' => admin_url( 'edit.php' ), 'icon' => 'dashicons-admin-post', 'description' => 'List, edit, bulk-manage blog posts.' ),
186 - array( 'title' => 'Add New Post', 'url' => admin_url( 'post-new.php' ), 'icon' => 'dashicons-plus', 'description' => 'Create a new blog post.' ),
187 - array( 'title' => 'Categories', 'url' => admin_url( 'edit-tags.php?taxonomy=category' ), 'icon' => 'dashicons-category', 'description' => 'Manage post categories — add, rename, merge.' ),
188 - array( 'title' => 'Tags', 'url' => admin_url( 'edit-tags.php?taxonomy=post_tag' ), 'icon' => 'dashicons-tag', 'description' => 'Manage post tags.' ),
189 - array( 'title' => 'All Pages', 'url' => admin_url( 'edit.php?post_type=page' ), 'icon' => 'dashicons-admin-page', 'description' => 'List and edit static pages (About, Contact, etc.).' ),
190 - array( 'title' => 'Add New Page', 'url' => admin_url( 'post-new.php?post_type=page' ), 'icon' => 'dashicons-plus', 'description' => 'Create a new page.' ),
191 - array( 'title' => 'Media Library', 'url' => admin_url( 'upload.php' ), 'icon' => 'dashicons-admin-media', 'description' => 'Browse, upload, and manage images, files, videos.' ),
192 - array( 'title' => 'Comments', 'url' => admin_url( 'edit-comments.php' ), 'icon' => 'dashicons-admin-comments', 'description' => 'Moderate and reply to comments on posts and pages.' ),
193 - array( 'title' => 'Themes', 'url' => admin_url( 'themes.php' ), 'icon' => 'dashicons-admin-appearance', 'description' => 'Change, install, or customize the active theme.' ),
194 - array( 'title' => 'Customize', 'url' => admin_url( 'customize.php' ), 'icon' => 'dashicons-admin-customizer', 'description' => 'Live-preview theme customisation — colors, fonts, layout.' ),
195 - array( 'title' => 'Widgets', 'url' => admin_url( 'widgets.php' ), 'icon' => 'dashicons-screenoptions', 'description' => 'Manage sidebar and footer widgets.' ),
196 - array( 'title' => 'Menus', 'url' => admin_url( 'nav-menus.php' ), 'icon' => 'dashicons-menu', 'description' => 'Create and edit navigation menus.' ),
197 - array( 'title' => 'Plugins', 'url' => admin_url( 'plugins.php' ), 'icon' => 'dashicons-admin-plugins', 'description' => 'Activate, deactivate, update or delete plugins.' ),
198 - array( 'title' => 'Add New Plugin', 'url' => admin_url( 'plugin-install.php' ), 'icon' => 'dashicons-plus', 'description' => 'Search and install new plugins from the directory.' ),
199 - array( 'title' => 'Users', 'url' => admin_url( 'users.php' ), 'icon' => 'dashicons-admin-users', 'description' => 'Manage user accounts and roles.' ),
200 - array( 'title' => 'Add New User', 'url' => admin_url( 'user-new.php' ), 'icon' => 'dashicons-plus', 'description' => 'Create a new user account.' ),
201 - array( 'title' => 'Your Profile', 'url' => admin_url( 'profile.php' ), 'icon' => 'dashicons-id', 'description' => 'Edit your own profile, password, admin colour scheme.' ),
202 - array( 'title' => 'General Settings', 'url' => admin_url( 'options-general.php' ), 'icon' => 'dashicons-admin-settings', 'description' => 'Site title, tagline, URL, timezone, language.' ),
203 - array( 'title' => 'Writing Settings', 'url' => admin_url( 'options-writing.php' ), 'icon' => 'dashicons-edit', 'description' => 'Default post category, post format, remote publishing.' ),
204 - array( 'title' => 'Reading Settings', 'url' => admin_url( 'options-reading.php' ), 'icon' => 'dashicons-book', 'description' => 'Homepage, blog posts per page, search-engine visibility.' ),
205 - array( 'title' => 'Discussion Settings','url' => admin_url( 'options-discussion.php' ), 'icon' => 'dashicons-format-chat', 'description' => 'Comment moderation, avatars, email notifications.' ),
206 - array( 'title' => 'Media Settings', 'url' => admin_url( 'options-media.php' ), 'icon' => 'dashicons-format-image', 'description' => 'Image size settings for thumbnail / medium / large.' ),
207 - array( 'title' => 'Permalinks', 'url' => admin_url( 'options-permalink.php' ), 'icon' => 'dashicons-admin-links', 'description' => 'URL structure for posts, pages, categories, tags.' ),
208 - array( 'title' => 'Privacy', 'url' => admin_url( 'options-privacy.php' ), 'icon' => 'dashicons-privacy', 'description' => 'Privacy policy page selection and preview.' ),
209 - array( 'title' => 'Tools', 'url' => admin_url( 'tools.php' ), 'icon' => 'dashicons-admin-tools', 'description' => 'Built-in site tools.' ),
210 - array( 'title' => 'Import', 'url' => admin_url( 'import.php' ), 'icon' => 'dashicons-download', 'description' => 'Import content from other platforms (WP, Tumblr, RSS, etc.).' ),
211 - array( 'title' => 'Export', 'url' => admin_url( 'export.php' ), 'icon' => 'dashicons-upload', 'description' => 'Export all site content as XML.' ),
212 - array( 'title' => 'Site Health', 'url' => admin_url( 'site-health.php' ), 'icon' => 'dashicons-heart', 'description' => 'Performance and security recommendations for the site.' ),
213 - array( 'title' => 'Updates', 'url' => admin_url( 'update-core.php' ), 'icon' => 'dashicons-update', 'description' => 'WordPress, theme, and plugin updates.' ),
214 - );
215 -
216 244 /**
217 245 * Filters the wp-admin page catalog surfaced by the AI assistant.
218 246 *
219 - * @since 0.14.0
220 - *
221 247 * @param array[] $catalog Array of entries, each with title/url/icon/description.
222 248 */
223 - return (array) apply_filters( 'desktop_mode_ai_admin_page_catalog', $catalog );
249 + return (array) apply_filters( 'openstation_ai_admin_page_catalog', $catalog );
224 250 }
225 251
226 252 // ---------------------------------------------------------------------------
227 253 // Final-answer JSON Schema
@@ -229,13 +255,11 @@
229 255
230 256 /**
231 257 * JSON Schema for the agent's final structured answer.
232 258 *
233 - * @since 0.14.0
234 - *
235 259 * @return array
236 260 */
237 -function desktop_mode_ai_search_answer_schema() {
261 +function openstation_ai_search_answer_schema() {
238 262 return array(
239 263 'type' => 'object',
240 264 'additionalProperties' => false,
241 265 'required' => array( 'answer_type', 'message', 'entity_id', 'entity_type', 'admin_links' ),
@@ -242,9 +266,9 @@
242 266 'properties' => array(
243 267 'answer_type' => array(
244 268 'type' => 'string',
245 269 'enum' => array( 'entity', 'navigation', 'chat' ),
246 - 'description' => 'Classification of the answer: "entity" when you identified a specific post/page/comment the user was asking about. "navigation" when the user asked where to find something in wp-admin and you are returning admin_links. "chat" for conversational responses that don\'t involve finding content or navigation (e.g. greetings, clarifications, "I couldn\'t find anything").',
270 + 'description' => 'Classification of the answer: "entity" when you identified a specific post/page/comment the user was asking about. "navigation" when you are returning admin_links: wp-admin destinations or plugin install links. "chat" for everything else, including summaries of tool results (error logs, site info), greetings, clarifications and "I couldn\'t find anything".',
247 271 ),
248 272 'message' => array(
249 273 'type' => 'string',
250 274 'description' => 'A friendly, conversational response to show the user. Write in first person like a helpful assistant (e.g. "I found your Málaga post — this one", "Here\'s where you manage categories"). NOT a search-engine sentence ("Match found").',
@@ -257,9 +281,12 @@
257 281 'description' => 'The WordPress ID of the matching entity. Required when answer_type is "entity"; set to null otherwise.',
258 282 ),
259 283 'entity_type' => array(
260 284 'anyOf' => array(
261 - array( 'type' => 'string', 'enum' => array( 'post', 'page', 'comment' ) ),
285 + array(
286 + 'type' => 'string',
287 + 'enum' => array( 'post', 'page', 'comment' ),
288 + ),
262 289 array( 'type' => 'null' ),
263 290 ),
264 291 'description' => 'Type of the matching entity. Required when answer_type is "entity"; set to null otherwise.',
265 292 ),
@@ -299,36 +326,34 @@
299 326 * matched with WordPress's native search; `search_comments_by_post`
300 327 * needs an additional `post_id`. The caller passes the full decoded
301 328 * arguments array so this function can extract whatever it needs.
302 329 *
303 - * @since 0.14.0
304 - *
305 330 * @param string $tool_name Tool function name.
306 331 * @param array $args Decoded arguments from the model's tool call.
307 332 * @return array Tool result payload.
308 333 */
309 -function desktop_mode_ai_search_dispatch_tool( $tool_name, array $args ) {
334 +function openstation_ai_search_dispatch_tool( $tool_name, array $args ) {
310 335 $offset = max( 0, (int) ( $args['offset'] ?? 0 ) );
311 336 $query = isset( $args['query'] ) ? sanitize_text_field( (string) $args['query'] ) : '';
312 337
313 338 switch ( $tool_name ) {
314 339 case 'search_posts':
315 - return desktop_mode_ai_search_fetch_posts( 'post', $query, $offset );
340 + return openstation_ai_search_fetch_posts( 'post', $query, $offset );
316 341 case 'search_pages':
317 - return desktop_mode_ai_search_fetch_posts( 'page', $query, $offset );
342 + return openstation_ai_search_fetch_posts( 'page', $query, $offset );
318 343 case 'search_comments':
319 - return desktop_mode_ai_search_fetch_comments( $query, $offset );
344 + return openstation_ai_search_fetch_comments( $query, $offset );
320 345 case 'search_comments_by_post':
321 346 $post_id = max( 0, (int) ( $args['post_id'] ?? 0 ) );
322 - return desktop_mode_ai_search_fetch_comments_by_post( $post_id, $query, $offset );
347 + return openstation_ai_search_fetch_comments_by_post( $post_id, $query, $offset );
323 348 case 'list_admin_pages':
324 349 return array(
325 350 'tool' => 'list_admin_pages',
326 - 'pages' => desktop_mode_ai_get_admin_page_catalog(),
351 + 'pages' => openstation_ai_get_admin_page_catalog(),
327 352 );
328 353 case 'search_wporg_plugins':
329 354 $q = isset( $args['query'] ) ? sanitize_text_field( (string) $args['query'] ) : '';
330 - return desktop_mode_ai_fetch_wporg_plugins( $q );
355 + return openstation_ai_fetch_wporg_plugins( $q );
331 356 case 'get_php_error_log':
332 357 if ( ! current_user_can( 'manage_options' ) ) {
333 358 return array(
334 359 'tool' => 'get_php_error_log',
@@ -337,9 +362,9 @@
337 362 'entries' => array(),
338 363 );
339 364 }
340 365 $lines = isset( $args['lines'] ) ? max( 1, min( 500, (int) $args['lines'] ) ) : 50;
341 - return desktop_mode_ai_fetch_error_log( $lines );
366 + return openstation_ai_fetch_error_log( $lines );
342 367 }
343 368
344 369 return array(
345 370 'tool' => $tool_name,
@@ -356,11 +381,15 @@
356 381 * Keyword-searches published posts or pages with WordPress's native search
357 382 * (`WP_Query` `s=`), returning data rich enough for the agent to compare
358 383 * AND for the UI to render links.
359 384 *
360 - * No AI analysis is required — every published post/page is searchable.
385 + * No AI analysis is required — every published, non-password-protected post/page is searchable.
361 386 *
362 - * @since 0.14.0
387 + * Password-protected posts are excluded (`has_password => false`): `publish`
388 + * is also the status of a password-protected post, and this tool emits the
389 + * stored body as an excerpt without ever passing through `post_password_required()`.
390 + * Filtering at the query level keeps them out of both `items` and `found_posts`,
391 + * so the `total` counter cannot become an oracle for their contents either.
363 392 *
364 393 * @param string $post_type 'post' | 'page'.
365 394 * @param string $query Keyword search terms (may be empty to list newest).
366 395 * @param int $offset
@@ -365,15 +394,16 @@
365 394 * @param string $query Keyword search terms (may be empty to list newest).
366 395 * @param int $offset
367 396 * @return array
368 397 */
369 -function desktop_mode_ai_search_fetch_posts( $post_type, $query, $offset ) {
398 +function openstation_ai_search_fetch_posts( $post_type, $query, $offset ) {
370 399 $wp_query = new WP_Query(
371 400 array(
372 401 'post_type' => $post_type,
373 402 'post_status' => 'publish',
403 + 'has_password' => false,
374 404 's' => (string) $query,
375 - 'posts_per_page' => DESKTOP_MODE_AI_SEARCH_BATCH_SIZE,
405 + 'posts_per_page' => OPENSTATION_AI_SEARCH_BATCH_SIZE,
376 406 'offset' => $offset,
377 407 'no_found_rows' => false,
378 408 'update_post_term_cache' => false,
379 409 'update_post_meta_cache' => false,
@@ -387,9 +417,9 @@
387 417 'id' => $post->ID,
388 418 'type' => $post->post_type,
389 419 // Comparison data for the model — real title + content excerpt.
390 420 'title' => wp_strip_all_tags( $post->post_title ),
391 - 'excerpt' => desktop_mode_ai_search_excerpt( $post->post_content ),
421 + 'excerpt' => openstation_ai_search_excerpt( $post->post_content ),
392 422 'date' => $post->post_date ? substr( $post->post_date, 0, 10 ) : '',
393 423 // Links — passed through so the UI can link to the entity
394 424 // once the agent identifies a match.
395 425 'url' => (string) get_permalink( $post ),
@@ -405,10 +435,10 @@
405 435 'offset' => $offset,
406 436 'items' => $items,
407 437 'count' => count( $items ),
408 438 'total' => $total,
409 - 'has_more' => ( $offset + DESKTOP_MODE_AI_SEARCH_BATCH_SIZE ) < $total,
410 - 'next_offset' => $offset + DESKTOP_MODE_AI_SEARCH_BATCH_SIZE,
439 + 'has_more' => ( $offset + OPENSTATION_AI_SEARCH_BATCH_SIZE ) < $total,
440 + 'next_offset' => $offset + OPENSTATION_AI_SEARCH_BATCH_SIZE,
411 441 );
412 442 }
413 443
414 444 /**
@@ -413,14 +443,12 @@
413 443
414 444 /**
415 445 * Trims raw post/comment content into a plain-text excerpt for the model.
416 446 *
417 - * @since 0.11.0
418 - *
419 447 * @param string $content Raw post/comment content.
420 448 * @return string
421 449 */
422 -function desktop_mode_ai_search_excerpt( $content ) {
450 +function openstation_ai_search_excerpt( $content ) {
423 451 $text = wp_strip_all_tags( (string) $content );
424 452 $text = preg_replace( '/\s+/', ' ', trim( $text ) );
425 453 return (string) mb_substr( $text, 0, 300 );
426 454 }
@@ -425,20 +453,92 @@
425 453 return (string) mb_substr( $text, 0, 300 );
426 454 }
427 455
428 456 /**
457 + * Whether the current user may read a post the comment tools are about to
458 + * surface.
459 + *
460 + * A comment being `approved` is a moderation decision — it says nothing about
461 + * who may see the discussion. An approved comment can hang on a private,
462 + * draft, or password-protected post the caller cannot reach, so the comment
463 + * search tools must gate on the PARENT POST's visibility before returning the
464 + * comment text or the parent title. Mirrors Core's
465 + * `WP_REST_Comments_Controller::check_read_post_permission()`:
466 + *
467 + * - a password-protected parent needs the password satisfied or `edit_post`.
468 + * `post_password_required()` honours the `wp-postpass` cookie Core's
469 + * password form sets, and that is deliberate Core parity, not a gap: the
470 + * cookie only exists because the caller already entered the correct
471 + * password, and Core's comments controller reads the same cookie. The
472 + * ability itself has no password input, so a caller who never unlocked
473 + * the post front-end is refused;
474 + * - a publicly viewable parent (public status AND viewable post type) is
475 + * readable by anyone the ability admits;
476 + * - a parent whose post TYPE is not viewable (an internal/admin-only CPT)
477 + * needs `edit_post` — `read_post` cannot stand in, because a public status
478 + * resolves it to plain `read` whatever the type's visibility, which is how
479 + * Core's REST layer needs its own post-type gate too;
480 + * - any other parent (private, draft, pending, …) needs `read_post`.
481 + *
482 + * @param int|WP_Post $post Post ID or object.
483 + * @return bool
484 + */
485 +function openstation_ai_can_read_post( $post ) {
486 + // An id of 0 must stay unreadable: get_post( 0 ) falls back to the global
487 + // $post, which would judge an orphaned comment against an unrelated post.
488 + if ( is_numeric( $post ) && (int) $post <= 0 ) {
489 + return false;
490 + }
491 +
492 + $post = get_post( $post );
493 + if ( ! $post instanceof WP_Post ) {
494 + return false;
495 + }
496 +
497 + if ( post_password_required( $post ) && ! current_user_can( 'edit_post', $post->ID ) ) {
498 + return false;
499 + }
500 +
501 + if ( is_post_publicly_viewable( $post ) ) {
502 + return true;
503 + }
504 +
505 + $post_type = get_post_type_object( $post->post_type );
506 + if ( ! $post_type || ! is_post_type_viewable( $post_type ) ) {
507 + return current_user_can( 'edit_post', $post->ID );
508 + }
509 +
510 + return current_user_can( 'read_post', $post->ID );
511 +}
512 +
513 +/**
514 + * Whether the current user may read the post a comment is attached to.
515 + *
516 + * Used to drop comments on posts the caller cannot see from the comment
517 + * search results. See {@see openstation_ai_can_read_post()}.
518 + *
519 + * @param int|WP_Comment $comment Comment ID or object.
520 + * @return bool
521 + */
522 +function openstation_ai_can_read_comment_parent( $comment ) {
523 + $comment = get_comment( $comment );
524 + if ( ! $comment instanceof WP_Comment ) {
525 + return false;
526 + }
527 + return openstation_ai_can_read_post( (int) $comment->comment_post_ID );
528 +}
529 +
530 +/**
429 531 * Keyword-searches approved comments across all posts with WordPress's
430 532 * native comment search (`get_comments` `search=`).
431 533 *
432 534 * No AI analysis is required — every approved comment is searchable.
433 535 *
434 - * @since 0.14.0
435 - *
436 536 * @param string $query Keyword search terms (may be empty to list newest).
437 537 * @param int $offset
438 538 * @return array
439 539 */
440 -function desktop_mode_ai_search_fetch_comments( $query, $offset ) {
540 +function openstation_ai_search_fetch_comments( $query, $offset ) {
441 541 $base_args = array(
442 542 'status' => 'approve',
443 543 'type' => 'comment',
444 544 'search' => (string) $query,
@@ -443,32 +543,55 @@
443 543 'type' => 'comment',
444 544 'search' => (string) $query,
445 545 );
446 546
447 - $comments = get_comments( array_merge( $base_args, array(
448 - 'number' => DESKTOP_MODE_AI_SEARCH_BATCH_SIZE,
449 - 'offset' => $offset,
450 - 'count' => false,
451 - ) ) );
547 + $comments = get_comments(
548 + array_merge(
549 + $base_args,
550 + array(
551 + 'number' => OPENSTATION_AI_SEARCH_BATCH_SIZE,
552 + 'offset' => $offset,
553 + 'count' => false,
554 + )
555 + )
556 + );
452 557
453 558 $total = (int) get_comments( array_merge( $base_args, array( 'count' => true ) ) );
454 559
455 560 // Prime the parent posts in a single query so the per-comment
456 561 // get_post() calls below are cache hits, not N+1 round-trips.
457 - $parent_ids = array_unique( array_map(
458 - static function ( $c ) {
459 - return (int) $c->comment_post_ID;
460 - },
461 - $comments
462 - ) );
562 + $parent_ids = array_unique(
563 + array_map(
564 + static function ( $c ) {
565 + return (int) $c->comment_post_ID;
566 + },
567 + $comments
568 + )
569 + );
463 570 if ( $parent_ids ) {
464 571 _prime_post_caches( $parent_ids, false, false );
465 572 }
466 573
574 + // "Approved" is a moderation decision, not a visibility one: drop comments
575 + // whose parent post the caller cannot read (private / draft / password /
576 + // internal CPT), so the comment text and the parent title never leak. See
577 + // openstation_ai_can_read_comment_parent().
578 + //
579 + // This runs per row, after the batch, and that is the price of gating on
580 + // per-caller readability: an Administrator reads comments on private
581 + // posts and a reader who entered a post password reads that post's
582 + // discussion, neither of which a single `post_status` or `has_password`
583 + // query var can express. `total` therefore counts rows this caller does
584 + // not get, and a batch can come back short. The alternative — a blanket
585 + // publish-only, no-password query — would be exact and would also hide
586 + // those discussions from the people entitled to them.
587 + $comments = array_values( array_filter( $comments, 'openstation_ai_can_read_comment_parent' ) );
588 +
467 589 $items = array();
468 590 foreach ( $comments as $comment ) {
591 + // Readable, per the filter above.
469 592 $parent_post = get_post( $comment->comment_post_ID );
470 - $parent_title = $parent_post ? wp_strip_all_tags( $parent_post->post_title ) : '';
593 + $parent_title = wp_strip_all_tags( $parent_post->post_title );
471 594
472 595 $items[] = array(
473 596 'id' => (int) $comment->comment_ID,
474 597 'type' => 'comment',
@@ -473,14 +596,14 @@
473 596 'id' => (int) $comment->comment_ID,
474 597 'type' => 'comment',
475 598 // Comparison data — real comment text + parent post title.
476 599 'post_title' => $parent_title,
477 - 'excerpt' => desktop_mode_ai_search_excerpt( $comment->comment_content ),
600 + 'excerpt' => openstation_ai_search_excerpt( $comment->comment_content ),
478 601 // Links.
479 602 'url' => (string) get_comment_link( $comment ),
480 603 'edit_url' => admin_url( 'comment.php?action=editcomment&c=' . (int) $comment->comment_ID ),
481 604 'post_id' => (int) $comment->comment_post_ID,
482 - 'post_url' => $parent_post ? (string) get_permalink( $parent_post ) : '',
605 + 'post_url' => (string) get_permalink( $parent_post ),
483 606 );
484 607 }
485 608
486 609 return array(
@@ -489,10 +612,10 @@
489 612 'offset' => $offset,
490 613 'items' => $items,
491 614 'count' => count( $items ),
492 615 'total' => $total,
493 - 'has_more' => ( $offset + DESKTOP_MODE_AI_SEARCH_BATCH_SIZE ) < $total,
494 - 'next_offset' => $offset + DESKTOP_MODE_AI_SEARCH_BATCH_SIZE,
616 + 'has_more' => ( $offset + OPENSTATION_AI_SEARCH_BATCH_SIZE ) < $total,
617 + 'next_offset' => $offset + OPENSTATION_AI_SEARCH_BATCH_SIZE,
495 618 );
496 619 }
497 620
498 621 // ---------------------------------------------------------------------------
@@ -506,16 +629,14 @@
506 629 * identifying a post via `search_posts`, giving it a scoped, precise set of
507 630 * comments to compare against the user's description. An empty `$query`
508 631 * lists the post's comments without keyword filtering.
509 632 *
510 - * @since 0.14.0
511 - *
512 633 * @param int $post_id The WordPress post ID.
513 634 * @param string $query Keyword search terms (may be empty).
514 635 * @param int $offset
515 636 * @return array Tool result payload.
516 637 */
517 -function desktop_mode_ai_search_fetch_comments_by_post( $post_id, $query, $offset ) {
638 +function openstation_ai_search_fetch_comments_by_post( $post_id, $query, $offset ) {
518 639 $post_id = (int) $post_id;
519 640
520 641 if ( $post_id <= 0 ) {
521 642 return array(
@@ -529,8 +650,25 @@
529 650 'error' => 'post_id must be a positive integer.',
530 651 );
531 652 }
532 653
654 + // The model picks the post id, so it is untrusted the same way an entity
655 + // id is. Comments inherit their parent's reach: a thread on a private,
656 + // draft, password-protected or internal-CPT post is not this user's to
657 + // read, and the envelope below would otherwise echo its title back.
658 + if ( ! openstation_ai_can_read_post( $post_id ) ) {
659 + return array(
660 + 'tool' => 'search_comments_by_post',
661 + 'post_id' => $post_id,
662 + 'offset' => $offset,
663 + 'items' => array(),
664 + 'count' => 0,
665 + 'total' => 0,
666 + 'has_more' => false,
667 + 'error' => 'Post not found or not readable.',
668 + );
669 + }
670 +
533 671 $base_args = array(
534 672 'post_id' => $post_id,
535 673 'status' => 'approve',
536 674 'type' => 'comment',
@@ -536,18 +674,24 @@
536 674 'type' => 'comment',
537 675 'search' => (string) $query,
538 676 );
539 677
540 - $comments = get_comments( array_merge( $base_args, array(
541 - 'number' => DESKTOP_MODE_AI_SEARCH_BATCH_SIZE,
542 - 'offset' => $offset,
543 - 'count' => false,
544 - ) ) );
678 + $comments = get_comments(
679 + array_merge(
680 + $base_args,
681 + array(
682 + 'number' => OPENSTATION_AI_SEARCH_BATCH_SIZE,
683 + 'offset' => $offset,
684 + 'count' => false,
685 + )
686 + )
687 + );
545 688
546 689 $total = (int) get_comments( array_merge( $base_args, array( 'count' => true ) ) );
547 690
691 + // Readable, per the gate above.
548 692 $parent_post = get_post( $post_id );
549 - $parent_title = $parent_post ? wp_strip_all_tags( $parent_post->post_title ) : '';
693 + $parent_title = wp_strip_all_tags( $parent_post->post_title );
550 694
551 695 $items = array();
552 696 foreach ( $comments as $comment ) {
553 697 $items[] = array(
@@ -554,9 +698,9 @@
554 698 'id' => (int) $comment->comment_ID,
555 699 'type' => 'comment',
556 700 'post_id' => $post_id,
557 701 'post_title' => $parent_title,
558 - 'excerpt' => desktop_mode_ai_search_excerpt( $comment->comment_content ),
702 + 'excerpt' => openstation_ai_search_excerpt( $comment->comment_content ),
559 703 'url' => (string) get_comment_link( $comment ),
560 704 'edit_url' => admin_url( 'comment.php?action=editcomment&c=' . (int) $comment->comment_ID ),
561 705 );
562 706 }
@@ -569,10 +713,10 @@
569 713 'offset' => $offset,
570 714 'items' => $items,
571 715 'count' => count( $items ),
572 716 'total' => $total,
573 - 'has_more' => ( $offset + DESKTOP_MODE_AI_SEARCH_BATCH_SIZE ) < $total,
574 - 'next_offset' => $offset + DESKTOP_MODE_AI_SEARCH_BATCH_SIZE,
717 + 'has_more' => ( $offset + OPENSTATION_AI_SEARCH_BATCH_SIZE ) < $total,
718 + 'next_offset' => $offset + OPENSTATION_AI_SEARCH_BATCH_SIZE,
575 719 );
576 720 }
577 721
578 722 // ---------------------------------------------------------------------------
@@ -587,53 +731,100 @@
587 731 * required. Comments opportunistically surface the `spam` / `harmful`
588 732 * verdict when the comment-moderation analysis happens to have run, but
589 733 * its absence never blocks the entity from being returned.
590 734 *
591 - * @since 0.14.0
735 + * The id arrives from the MODEL's final answer, and model output is
736 + * untrusted — a search turn can be driven by attacker-controlled content, so
737 + * an injected instruction could name an entity the search tools never
738 + * surfaced. Hydration therefore re-checks readability itself instead of
739 + * trusting that the id came out of a filtered tool result: posts/pages go
740 + * through {@see openstation_ai_can_read_post()}, and so does a comment's
741 + * PARENT, because the comment record carries that post's title and permalink
742 + * — approval is a moderation decision, not a visibility one, and an approved
743 + * comment outlives its post being switched to private or back to draft.
744 + * Reading an unapproved comment needs `edit_comment`, mirroring Core's
745 + * `WP_REST_Comments_Controller::check_read_permission()`; the AI moderation
746 + * verdicts and the wp-admin edit link are narrower still. Unreadable ids
747 + * resolve to null, indistinguishable from nonexistent ones.
592 748 *
593 749 * @param string $entity_type 'post' | 'page' | 'comment'.
594 750 * @param int $entity_id
595 751 * @return array|null
596 752 */
597 -function desktop_mode_ai_search_build_entity( $entity_type, $entity_id ) {
753 +function openstation_ai_search_build_entity( $entity_type, $entity_id ) {
598 754 $entity_id = (int) $entity_id;
599 755
600 756 if ( in_array( $entity_type, array( 'post', 'page' ), true ) ) {
601 757 $post = get_post( $entity_id );
602 - if ( ! $post instanceof WP_Post ) {
758 +
759 + // The id must resolve to an actual post or page. The gate below answers
760 + // type visibility on its own, so this is the contract rather than the
761 + // lock: the record's `type` is what the client renders the card from,
762 + // and post/page is what the search tools surface. A viewable CPT row
763 + // would pass the gate and still have no card to land in.
764 + if ( ! $post instanceof WP_Post || ! in_array( $post->post_type, array( 'post', 'page' ), true ) ) {
603 765 return null;
604 766 }
767 +
768 + if ( ! openstation_ai_can_read_post( $post ) ) {
769 + return null;
770 + }
771 +
605 772 return array(
606 773 'id' => $entity_id,
607 774 'type' => $post->post_type,
608 - 'title' => wp_strip_all_tags( $post->post_title ),
775 + 'title' => openstation_plain_text_title( $post->post_title ),
609 776 'status' => $post->post_status,
610 777 'date' => $post->post_date ? substr( $post->post_date, 0, 10 ) : '',
611 778 'url' => (string) get_permalink( $post ),
612 779 'edit_url' => (string) get_edit_post_link( $entity_id, 'raw' ),
613 - 'excerpt' => desktop_mode_ai_search_excerpt( $post->post_content ),
780 + 'excerpt' => openstation_ai_search_excerpt( $post->post_content ),
614 781 );
615 782 }
616 783
617 784 if ( 'comment' === $entity_type ) {
618 785 $comment = get_comment( $entity_id );
619 - if ( ! $comment instanceof WP_Comment ) {
786 +
787 + // The parent's reach bounds the comment's: approval is a moderation
788 + // decision, not a visibility one, and this record carries the parent's
789 + // title and permalink — so without this check, naming a comment id
790 + // would walk straight around the post branch's gate above.
791 + if ( ! $comment instanceof WP_Comment || ! openstation_ai_can_read_comment_parent( $comment ) ) {
620 792 return null;
621 793 }
622 - $meta = desktop_mode_ai_get_meta( 'comment', $entity_id );
623 - $parent_post = get_post( $comment->comment_post_ID );
624 - return array(
794 +
795 + // Reading an unapproved comment is an editor's business, per Core's
796 + // WP_REST_Comments_Controller::check_read_permission().
797 + if ( '1' !== (string) $comment->comment_approved && ! current_user_can( 'edit_comment', $entity_id ) ) {
798 + return null;
799 + }
800 +
801 + // The AI verdicts are the moderation queue's data, so they follow the
802 + // moderation capability rather than the per-comment edit one.
803 + $can_moderate = current_user_can( 'moderate_comments' );
804 + $parent_post = get_post( (int) $comment->comment_post_ID );
805 +
806 + $meta = $can_moderate ? openstation_ai_get_meta( 'comment', $entity_id ) : null;
807 + $entity = array(
625 808 'id' => $entity_id,
626 809 'type' => 'comment',
627 - 'excerpt' => desktop_mode_ai_search_excerpt( $comment->comment_content ),
810 + 'excerpt' => openstation_ai_search_excerpt( $comment->comment_content ),
628 811 'post_id' => (int) $comment->comment_post_ID,
629 - 'post_title' => $parent_post ? wp_strip_all_tags( $parent_post->post_title ) : '',
630 - 'post_url' => $parent_post ? (string) get_permalink( $parent_post ) : '',
812 + 'post_title' => openstation_plain_text_title( $parent_post->post_title ),
813 + 'post_url' => (string) get_permalink( $parent_post ),
631 814 'url' => (string) get_comment_link( $comment ),
632 - 'edit_url' => admin_url( 'comment.php?action=editcomment&c=' . $entity_id ),
633 - 'harmful' => $meta ? (bool) ( $meta['harmful'] ?? false ) : false,
634 - 'spam' => $meta ? (bool) ( $meta['spam'] ?? false ) : false,
815 + 'edit_url' => current_user_can( 'edit_comment', $entity_id )
816 + ? admin_url( 'comment.php?action=editcomment&c=' . $entity_id )
817 + : '',
635 818 );
819 +
820 + // Moderation verdicts are for moderators only.
821 + if ( $can_moderate ) {
822 + $entity['harmful'] = $meta ? (bool) ( $meta['harmful'] ?? false ) : false;
823 + $entity['spam'] = $meta ? (bool) ( $meta['spam'] ?? false ) : false;
824 + }
825 +
826 + return $entity;
636 827 }
637 828
638 829 return null;
639 830 }
@@ -642,31 +833,173 @@
642 833 // Agentic search loop
643 834 // ---------------------------------------------------------------------------
644 835
645 836 /**
646 - * Returns a friendly progress message for a tool name — surfaced to the
647 - * client via SSE so the user sees "Looking through your posts…" rather
648 - * than the raw tool call.
837 + * Returns the label for the "keep looking" button on an exhausted search.
649 838 *
650 - * @since 0.14.0
839 + * One full sentence per resumable tool: a noun interpolated into a shared
840 + * template cannot be translated.
651 841 *
652 - * @param string $tool_name
842 + * @param string $resume_tool Tool the client would resume from.
843 + * @param int $from_item 1-based index of the next item to search.
653 844 * @return string
654 845 */
655 -function desktop_mode_ai_progress_message( $tool_name ) {
656 - switch ( $tool_name ) {
657 - case 'search_posts': return 'Looking through your posts…';
658 - case 'search_pages': return 'Checking your pages…';
659 - case 'search_comments': return 'Reading through comments…';
660 - case 'search_comments_by_post': return 'Scanning comments on that post…';
661 - case 'list_admin_pages': return 'Finding the right admin page…';
662 - case 'search_wporg_plugins': return 'Searching the WordPress.org plugin directory…';
663 - case 'get_php_error_log': return 'Tailing the PHP error log…';
846 +function openstation_ai_continue_label( $resume_tool, $from_item ) {
847 + switch ( $resume_tool ) {
848 + case 'search_pages':
849 + /* translators: %d: 1-based index of the next page to search. */
850 + return sprintf( __( 'Continue searching in pages (from item %d)', 'desktop-mode' ), $from_item );
851 + case 'search_comments':
852 + /* translators: %d: 1-based index of the next comment to search. */
853 + return sprintf( __( 'Continue searching in comments (from item %d)', 'desktop-mode' ), $from_item );
854 + default:
855 + /* translators: %d: 1-based index of the next post to search. */
856 + return sprintf( __( 'Continue searching in posts (from item %d)', 'desktop-mode' ), $from_item );
664 857 }
665 - return 'Thinking…';
666 858 }
667 859
668 860 /**
861 + * Returns the tools a client may resume an exhausted search from.
862 + *
863 + * Single source of truth for every `resume_tool` allowlist: the REST
864 + * arg sanitizer and the `$initial_tool` validation inside
865 + * `openstation_ai_run_search()`. `search_comments_by_post` is
866 + * deliberately absent: the `continue` payload carries no `post_id`, so
867 + * it cannot truly resume — exhausted runs map it to `search_comments`
868 + * when building the `continue` object.
869 + *
870 + * @return string[] Tool names.
871 + */
872 +function openstation_ai_search_resumable_tools() {
873 + return array( 'search_posts', 'search_pages', 'search_comments' );
874 +}
875 +
876 +/**
877 + * Projects a tool's `parameters` schema onto the provider-supported subset.
878 + *
879 + * The Abilities API (and plugin-supplied tools) may use the full breadth of JSON
880 + * Schema, but the provider's tool-schema validator does not — and it rejects the
881 + * whole request, not just the offending tool, so ONE tool with a
882 + * legal-but-unsupported schema makes the entire assistant return a 400 before the
883 + * model runs. Three shapes that are valid JSON Schema, but rejected here, have
884 + * been seen in the wild (see the linked issue):
885 + *
886 + * 1. `type` as an array, e.g. ['object','null'] — an ability's GET/null
887 + * run-path. The provider wants the literal string "object" at the top level.
888 + * 2. A top-level `oneOf` / `anyOf` / `allOf`, e.g. "post_id OR slug". Rejected
889 + * with "does not support oneOf, allOf, or anyOf at the top level".
890 + * 3. `properties` as an empty PHP array, which encodes to JSON as `[]` where an
891 + * object schema needs `{}`.
892 + *
893 + * This reshapes only the copy advertised to the model. The ability itself is
894 + * untouched: `WP_Ability::execute()` still validates arguments against the real
895 + * schema and `permission_callback` still gates execution, so nothing loses
896 + * enforcement — the model is simply told the constraint in prose (the tool
897 + * description) instead of in a schema construct the provider can't parse. Only
898 + * the TOP level is constrained; a combinator nested inside a property is a real
899 + * constraint the provider accepts, so it is left intact.
900 + *
901 + * @param mixed $schema A tool parameters schema (array), or empty/non-array.
902 + * @return array A provider-safe object schema for a tool `parameters` block.
903 + */
904 +function openstation_ai_normalize_tool_schema( $schema ) {
905 + if ( ! is_array( $schema ) || empty( $schema ) ) {
906 + return array(
907 + 'type' => 'object',
908 + 'properties' => (object) array(),
909 + );
910 + }
911 +
912 + // Recursively drop the WordPress-only arg-schema keys
913 + // (`sanitize_callback` / `validate_callback` / `arg_options`) —
914 + // see the helper's docblock for why this must run at every depth.
915 + $schema = openstation_ai_strip_wp_schema_keys( $schema );
916 +
917 + // Top-level tool parameters must be the literal "object", never a union.
918 + $schema['type'] = 'object';
919 +
920 + // Strip top-level combinators — the provider rejects them outright, and one
921 + // such tool 400s the whole request. Nested combinators are left alone.
922 + unset( $schema['oneOf'], $schema['allOf'], $schema['anyOf'] );
923 +
924 + // An empty PHP array encodes as `[]`; an object schema's properties need `{}`.
925 + // A schema with no `properties` at all (e.g. one whose only content was a
926 + // stripped top-level combinator) gets an empty object for the same reason.
927 + if ( ! isset( $schema['properties'] ) || array() === $schema['properties'] ) {
928 + $schema['properties'] = (object) array();
929 + }
930 +
931 + return $schema;
932 +}
933 +
934 +/**
935 + * Recursively removes the WordPress-only arg-schema keys from a tool schema.
936 + *
937 + * WordPress arg schemas legally extend JSON Schema with PHP-callable keys —
938 + * `sanitize_callback`, `validate_callback`, and (on meta args) `arg_options`.
939 + * Abilities registered from REST arg definitions carry them at every property
940 + * level, and providers that validate tool schemas strictly reject any unknown
941 + * field ("Invalid JSON payload received. Unknown name \"sanitize_callback\""),
942 + * 400-ing the whole request over one property.
943 + *
944 + * The walk is structure-aware, not a blind key sweep: maps under `properties` /
945 + * `patternProperties` are keyed by PROPERTY NAME, so a property that happens to
946 + * be called `sanitize_callback` is preserved — only its schema value is
947 + * cleaned. Recursion covers every position a subschema can occupy: property
948 + * values, `items` (single schema or tuple list), array-shaped
949 + * `additionalProperties`, and nested `oneOf` / `allOf` / `anyOf` branches
950 + * (which are kept — only the TOP level of the tool schema strips combinators).
951 + *
952 + * @param array $schema A tool parameters (sub)schema.
953 + * @return array The schema without WP-only keys, at any depth.
954 + */
955 +function openstation_ai_strip_wp_schema_keys( array $schema ) {
956 + unset( $schema['sanitize_callback'], $schema['validate_callback'], $schema['arg_options'] );
957 +
958 + foreach ( array( 'properties', 'patternProperties' ) as $map_key ) {
959 + if ( isset( $schema[ $map_key ] ) && is_array( $schema[ $map_key ] ) ) {
960 + foreach ( $schema[ $map_key ] as $name => $sub ) {
961 + if ( is_array( $sub ) ) {
962 + $schema[ $map_key ][ $name ] = openstation_ai_strip_wp_schema_keys( $sub );
963 + }
964 + }
965 + }
966 + }
967 +
968 + if ( isset( $schema['items'] ) && is_array( $schema['items'] ) ) {
969 + $items = $schema['items'];
970 + $is_list = array_keys( $items ) === range( 0, count( $items ) - 1 );
971 + if ( $is_list && array() !== $items ) {
972 + // Tuple form — a list of schemas.
973 + foreach ( $items as $i => $sub ) {
974 + if ( is_array( $sub ) ) {
975 + $items[ $i ] = openstation_ai_strip_wp_schema_keys( $sub );
976 + }
977 + }
978 + $schema['items'] = $items;
979 + } else {
980 + $schema['items'] = openstation_ai_strip_wp_schema_keys( $items );
981 + }
982 + }
983 +
984 + if ( isset( $schema['additionalProperties'] ) && is_array( $schema['additionalProperties'] ) ) {
985 + $schema['additionalProperties'] = openstation_ai_strip_wp_schema_keys( $schema['additionalProperties'] );
986 + }
987 +
988 + foreach ( array( 'oneOf', 'allOf', 'anyOf' ) as $combinator ) {
989 + if ( isset( $schema[ $combinator ] ) && is_array( $schema[ $combinator ] ) ) {
990 + foreach ( $schema[ $combinator ] as $i => $sub ) {
991 + if ( is_array( $sub ) ) {
992 + $schema[ $combinator ][ $i ] = openstation_ai_strip_wp_schema_keys( $sub );
993 + }
994 + }
995 + }
996 + }
997 +
998 + return $schema;
999 +}
1000 +
1001 +/**
669 1002 * Runs the agentic content-search loop.
670 1003 *
671 1004 * The model receives focused tools — search_posts, search_pages,
672 1005 * search_comments, search_comments_by_post — and a system prompt that
@@ -678,29 +1011,15 @@
678 1011 * For continuation runs ($initial_tool + $start_offset > 0), the system
679 1012 * message primes the agent to resume from the last searched position with
680 1013 * the same keywords.
681 1014 *
682 - * @since 0.14.0
683 - *
684 - * @param string $api_key OpenAI API key.
685 1015 * @param string $query User's natural-language search.
686 1016 * @param string|null $initial_tool Tool name to resume from, or null for fresh search.
687 1017 * @param int $start_offset Offset to resume from (0 for fresh).
688 - * @param callable|null $on_progress Optional progress emitter for SSE ticks.
689 1018 * @param array $extra Extensibility context (command tools, prompt overrides, …).
690 1019 * @return array|WP_Error
691 1020 */
692 -function desktop_mode_ai_run_search( $api_key, $query, $initial_tool = null, $start_offset = 0, $on_progress = null, array $extra = array() ) {
693 - /**
694 - * Progress emitter — sends a tick to the caller if they provided a
695 - * callable; no-op otherwise. Callers use this to render real-time
696 - * status to the user via SSE.
697 - */
698 - $emit = static function ( array $event ) use ( $on_progress ) {
699 - if ( is_callable( $on_progress ) ) {
700 - $on_progress( $event );
701 - }
702 - };
1021 +function openstation_ai_run_search( $query, $initial_tool = null, $start_offset = 0, array $extra = array() ) {
703 1022 $start_offset = max( 0, (int) $start_offset );
704 1023 $search_tools = array( 'search_posts', 'search_pages', 'search_comments', 'search_comments_by_post' );
705 1024 $valid_tools = array_merge(
706 1025 $search_tools,
@@ -712,11 +1031,11 @@
712 1031 // tools from the server-side registry, system-prompt overrides, and a
713 1032 // per-call request_id for observability fanout.
714 1033 // -----------------------------------------------------------------------
715 1034 $user_id = isset( $extra['user_id'] ) ? (int) $extra['user_id'] : get_current_user_id();
716 - $request_id = isset( $extra['request_id'] ) && is_string( $extra['request_id'] ) && $extra['request_id'] !== ''
1035 + $request_id = isset( $extra['request_id'] ) && is_string( $extra['request_id'] ) && '' !== $extra['request_id']
717 1036 ? (string) $extra['request_id']
718 - : ( function_exists( 'wp_generate_uuid4' ) ? wp_generate_uuid4() : uniqid( 'desktop_mode_ai_', true ) );
1037 + : ( function_exists( 'wp_generate_uuid4' ) ? wp_generate_uuid4() : uniqid( 'openstation_ai_', true ) );
719 1038 $command_tools_raw = isset( $extra['command_tools'] ) && is_array( $extra['command_tools'] ) ? $extra['command_tools'] : array();
720 1039 $system_prompt_text = isset( $extra['system_prompt_text'] ) && is_string( $extra['system_prompt_text'] ) ? $extra['system_prompt_text'] : '';
721 1040 $system_prompt_mode = isset( $extra['system_prompt_mode'] ) && in_array( $extra['system_prompt_mode'], array( 'append', 'replace' ), true )
722 1041 ? (string) $extra['system_prompt_mode']
@@ -723,14 +1042,12 @@
723 1042 : 'append';
724 1043
725 1044 /**
726 1045 * Fires once per `/ai/search` invocation, after validation and
727 - * before any OpenAI call. First anchor in the observability trio
728 - * (`desktop_mode_ai_search_started` / `desktop_mode_ai_tool_called`
729 - * / `desktop_mode_ai_search_completed`).
1046 + * before any the provider call. First anchor in the observability trio
1047 + * (`openstation_ai_search_started` / `openstation_ai_tool_called`
1048 + * / `openstation_ai_search_completed`).
730 1049 *
731 - * @since 0.17.0
732 - *
733 1050 * @param array $context {
734 1051 * @type string $query User query.
735 1052 * @type int $user_id
736 1053 * @type string $request_id UUID correlating the whole run.
@@ -736,9 +1053,9 @@
736 1053 * @type string $request_id UUID correlating the whole run.
737 1054 * }
738 1055 */
739 1056 do_action(
740 - 'desktop_mode_ai_search_started',
1057 + 'openstation_ai_search_started',
741 1058 array(
742 1059 'query' => $query,
743 1060 'user_id' => $user_id,
744 1061 'request_id' => $request_id,
@@ -744,9 +1061,9 @@
744 1061 'request_id' => $request_id,
745 1062 )
746 1063 );
747 1064
748 - if ( $initial_tool !== null && ! in_array( $initial_tool, $search_tools, true ) ) {
1065 + if ( null !== $initial_tool && ! in_array( $initial_tool, openstation_ai_search_resumable_tools(), true ) ) {
749 1066 $initial_tool = null;
750 1067 }
751 1068
752 1069 // When resuming a previous exhausted run, prime the model with the
@@ -752,9 +1069,9 @@
752 1069 // When resuming a previous exhausted run, prime the model with the
753 1070 // starting position so it doesn't waste iterations on already-searched
754 1071 // content.
755 1072 $continuation_note = '';
756 - if ( $initial_tool !== null && ( $start_offset > 0 || $initial_tool !== 'search_posts' ) ) {
1073 + if ( null !== $initial_tool && ( $start_offset > 0 || 'search_posts' !== $initial_tool ) ) {
757 1074 $continuation_note = sprintf(
758 1075 "\n\nNote: This is a continuation of a previous search. Begin with %s using the same search keywords at offset=%d and work forward.",
759 1076 $initial_tool,
760 1077 $start_offset
@@ -767,29 +1084,30 @@
767 1084 1. **Find content** they've written (posts, pages, comments) by describing it in natural language.
768 1085 2. **Navigate wp-admin** when they ask where to find something (\"where are the categories?\", \"how do I manage users?\").
769 1086 3. **Recommend plugins** from the official WordPress.org directory when they need extra functionality.
770 1087 4. **Check the site's error log** when they're troubleshooting something.
771 -5. **Chat** — if the request doesn't fit the above, just answer conversationally.
1088 +5. **Answer anything else your tools can** — you may have more tools than the ones named here (WordPress and other plugins register their own, e.g. site / user / environment / version info). Your actual tool list is authoritative: whenever a tool can answer the request, call it and summarise the result, even if it isn't named here.
1089 +6. **Chat** — only when no tool fits, answer conversationally.
772 1090
773 1091 Tone: warm, concise, helpful. First person (\"I found this post…\", \"Here's where you'll find that…\"). Not a search engine tone — no \"Match found\" or robot phrasing.
774 1092
775 -Tools:
776 -- search_posts / search_pages / search_comments / search_comments_by_post(post_id, query, offset): keyword content-lookup tools backed by WordPress's native search. Distil the user's description into the essential search keywords and pass them as `query` (e.g. \"that long post about making paella\" → query \"paella\"). Inspect the returned title + excerpt and stop once you find a good match. If has_more is true and nothing matched, call the same tool with next_offset (reuse the same query), or try different keywords. When the query mentions BOTH a post and a comment on that post, call search_posts first to identify the post, THEN search_comments_by_post with the ID. If keyword search returns nothing, broaden or simplify the keywords before giving up.
777 -- list_admin_pages: returns the full catalog of wp-admin destinations. Call once per navigation query, then select the 1-3 most relevant entries.
778 -- search_wporg_plugins(query): searches the official WordPress.org plugin directory. Use when the user asks for a plugin recommendation (\"a plugin for X\", \"is there a plugin that does Y?\"). Returns up to 10 plugins with ratings, install counts, and admin install URLs. Present the best 3-5 as admin_links with titles like \"Plugin Name · 5M+ installs · 4.8★\" (rating is 0-100, divide by 20 to get stars).
779 -- get_php_error_log(lines): reads the tail of the site's PHP error log. Admin-only (the tool itself checks). Use when the user asks \"any errors?\", \"check the logs\", \"what's broken?\", troubleshooting. Each entry has { timestamp, level, message }. Summarise the most important errors (Fatal > Warning > Notice) in your message; don't copy-paste everything.
1093 +How to work the tools (your actual tool list is authoritative; use any tool that fits the request):
1094 +- Content lookups: stop once a returned title and excerpt clearly match. If nothing matched, page on with the next offset or try broader, simpler keywords before telling the user you found nothing.
1095 +- Plugin recommendations: present the best 3-5 as admin_links titled like \"Plugin Name · 5M+ installs · 4.8★\".
1096 +- Error logs: summarise the most important errors first (fatal, then warnings, then notices) instead of copying entries.
780 1097
781 1098 Choosing which track:
782 1099 - \"I remember a post/page/comment about X\" → the corresponding search_* tool.
783 -- \"where can I find X?\" / \"how do I manage Y?\" → list_admin_pages.
1100 +- \"where can I find X?\", \"how do I manage Y?\", \"create/add/new …\", \"take me to …\", \"open …\", \"switch/activate …\", or any navigate/do intent → list_admin_pages, then suggest the 1-3 best destinations as admin_links (answer_type \"navigation\"). You suggest the link; the user opens it — never assume it's opened.
784 1101 - \"plugin for X\" / \"recommend a plugin\" → search_wporg_plugins → present as admin_links.
785 1102 - \"any errors?\" / \"check logs\" / troubleshooting → get_php_error_log → summarise in chat.
1103 +- Any other factual question about the site (its version, PHP/environment, the current user, or anything one of your other tools covers) → call that tool, then summarise its result with answer_type \"chat\".
786 1104 - Greeting, unclear, or chit-chat → answer_type \"chat\" with a brief helpful message (no tools needed).
787 1105
788 1106 Always return one of three answer_type values in the structured output:
789 1107 - \"entity\": you identified a single post/page/comment. Fill entity_id + entity_type. admin_links = null.
790 1108 - \"navigation\": you're recommending admin pages OR plugin install links. Fill admin_links. entity_id + entity_type = null.
791 -- \"chat\": you're answering conversationally — including log summaries, greetings, \"nothing found\" answers. entity_id + entity_type + admin_links all null.
1109 +- \"chat\": you're answering conversationally — including results summarised from any tool (error logs, environment/version info, other plugins' tools), greetings, and \"nothing found\" answers. entity_id + entity_type + admin_links all null.
792 1110
793 1111 The message field is always a friendly sentence or two shown directly to the user. Make it sound like a person, not a log line.
794 1112 ";
795 1113
@@ -799,12 +1117,13 @@
799 1117
800 1118 // -----------------------------------------------------------------------
801 1119 // System-prompt extensibility. All three layers — appendix filter,
802 1120 // client override (append/replace with capability gate), and final
803 - // transform — live in `desktop_mode_ai_compose_instructions()` so the
1121 + // transform — live in `openstation_ai_compose_instructions()` so the
804 1122 // primary run and the follow-up leg stay in lockstep. See the
805 - // helper for the order of application; see the filter docblocks
806 - // below for the public contract on each extension point.
1123 + // helper for the order of application; the filter docblocks at its
1124 + // `apply_filters()` call sites carry the public contract on each
1125 + // extension point.
807 1126 // -----------------------------------------------------------------------
808 1127 $prompt_context = array(
809 1128 'query' => $query,
810 1129 'user_id' => $user_id,
@@ -810,68 +1129,54 @@
810 1129 'user_id' => $user_id,
811 1130 'request_id' => $request_id,
812 1131 );
813 1132
814 - /**
815 - * Short-circuit extension — appended to the built-in instructions
816 - * verbatim. Use this when a plugin just wants to add domain
817 - * context (room list, product catalogue, company jargon) without
818 - * restructuring the core rules. Fires for both the primary
819 - * `/ai/search` run and the follow-up composed-reply leg.
820 - *
821 - * @since 0.17.0
822 - *
823 - * @param string $appendix Accumulated appendix. Default empty.
824 - * @param array $context { query, user_id, request_id, client_override, phase? }.
825 - */
826 -
827 - /**
828 - * Capability required for a client to send
829 - * `system_prompt: { mode: 'replace' }`. Defaults to `manage_options`
830 - * — replacing the whole prompt can effectively hijack the
831 - * assistant, so it's admin-only out of the box.
832 - *
833 - * @since 0.17.0
834 - *
835 - * @param string $capability Default `manage_options`.
836 - * @param array $context
837 - */
838 -
839 - /**
840 - * Final transform pass. Fires after the built-in instructions,
841 - * server appendix, and client override have all been composed.
842 - *
843 - * @since 0.17.0
844 - *
845 - * @param string $instructions Composed system prompt.
846 - * @param array $context
847 - */
848 - $instructions = desktop_mode_ai_compose_instructions(
1133 + $instructions = openstation_ai_compose_instructions(
849 1134 $instructions,
850 1135 $prompt_context,
851 - array( 'text' => $system_prompt_text, 'mode' => $system_prompt_mode )
1136 + array(
1137 + 'text' => $system_prompt_text,
1138 + 'mode' => $system_prompt_mode,
1139 + )
852 1140 );
853 1141
854 1142 // -----------------------------------------------------------------------
855 - // Tool assembly — built-in search/navigation + PHP-registered +
856 - // client-supplied command tools.
1143 + // Tool assembly — built-in search/navigation abilities + client-supplied
1144 + // command tools.
1145 + //
1146 + // Built-in tools are WordPress Abilities API abilities. Each is advertised
1147 + // to the model as a function declaration named after the ability (namespace
1148 + // stripped), and $ability_by_tool maps that name back to the ability so the
1149 + // agent loop can resolve + execute() it (permission + input/output
1150 + // validation happen inside execute()).
857 1151 // -----------------------------------------------------------------------
858 - $builtin_tools = desktop_mode_ai_search_tool_definitions();
1152 + $ability_by_tool = array();
1153 + $builtin_tools = array();
859 1154
860 - // PHP-registered tools (capability-filtered for the current user).
861 - $registered_entries = function_exists( 'desktop_mode_get_registered_ai_tools_for_user' )
862 - ? desktop_mode_get_registered_ai_tools_for_user( $user_id )
863 - : array();
1155 + foreach ( openstation_ai_search_ability_names() as $ability_name ) {
1156 + $ability = function_exists( 'wp_get_ability' ) ? wp_get_ability( $ability_name ) : null;
1157 + if ( ! $ability instanceof WP_Ability ) {
1158 + continue;
1159 + }
864 1160
865 - // Track registered + command tool maps so the agent loop can
866 - // dispatch without re-walking the registry on every iteration.
867 - $registered_by_name = array();
868 - foreach ( $registered_entries as $entry ) {
869 - $registered_by_name[ (string) $entry['name'] ] = $entry;
1161 + $tool_name = openstation_ai_ability_tool_name( $ability_name );
1162 + $ability_by_tool[ $tool_name ] = $ability_name;
1163 + $valid_tools[] = $tool_name;
1164 +
1165 + $input_schema = $ability->get_input_schema();
1166 + $builtin_tools[] = array(
1167 + 'type' => 'function',
1168 + 'name' => $tool_name,
1169 + 'description' => (string) $ability->get_description(),
1170 + 'parameters' => ! empty( $input_schema )
1171 + ? $input_schema
1172 + : array(
1173 + 'type' => 'object',
1174 + 'properties' => (object) array(),
1175 + ),
1176 + );
870 1177 }
871 1178
872 - $registered_defs = array_map( 'desktop_mode_ai_tool_entry_to_definition', $registered_entries );
873 -
874 1179 // Command tools — namespaced as `command_<slug>` on the server so
875 1180 // they can't collide with built-in tool names. Each takes a single
876 1181 // optional `args` string arg (matches the slash-command contract
877 1182 // where args are a single string the plugin's `run()` parses).
@@ -882,9 +1187,9 @@
882 1187 if ( ! is_array( $cmd ) ) {
883 1188 continue;
884 1189 }
885 1190 $slug = isset( $cmd['slug'] ) ? (string) $cmd['slug'] : '';
886 - if ( $slug === '' || ! preg_match( '/^[a-z0-9_\-]+$/', $slug ) ) {
1191 + if ( '' === $slug || ! preg_match( '/^[a-z0-9_\-]+$/', $slug ) ) {
887 1192 continue;
888 1193 }
889 1194 /**
890 1195 * Per-tool filter on the client-supplied command list. Return
@@ -890,10 +1195,8 @@
890 1195 * Per-tool filter on the client-supplied command list. Return
891 1196 * `false` to drop a command entirely before it reaches the
892 1197 * model — the right hook for per-role / per-command gating.
893 1198 *
894 - * @since 0.17.0
895 - *
896 1199 * @param bool|array $allowed Either the (possibly mutated) command
897 1200 * tool entry, or `false` to drop it.
898 1201 * @param string $slug Command slug.
899 1202 * @param array $context { user_id, request_id }.
@@ -898,12 +1201,15 @@
898 1201 * @param string $slug Command slug.
899 1202 * @param array $context { user_id, request_id }.
900 1203 */
901 1204 $allowed = apply_filters(
902 - 'desktop_mode_ai_command_allowed',
1205 + 'openstation_ai_command_allowed',
903 1206 $cmd,
904 1207 $slug,
905 - array( 'user_id' => $user_id, 'request_id' => $request_id )
1208 + array(
1209 + 'user_id' => $user_id,
1210 + 'request_id' => $request_id,
1211 + )
906 1212 );
907 1213 if ( false === $allowed || ! is_array( $allowed ) ) {
908 1214 continue;
909 1215 }
@@ -917,13 +1223,13 @@
917 1223 'type' => 'function',
918 1224 'name' => $tool_name,
919 1225 'description' => trim( $label . ( '' !== $description ? ' — ' . $description : '' ) ),
920 1226 'parameters' => array(
921 - 'type' => 'object',
922 - 'properties' => array(
1227 + 'type' => 'object',
1228 + 'properties' => array(
923 1229 'args' => array(
924 1230 'type' => 'string',
925 - 'description' => $hint !== ''
1231 + 'description' => '' !== $hint
926 1232 ? sprintf( 'Arguments for this command. Hint: %s', $hint )
927 1233 : 'Arguments for this command. Leave empty when the command takes none.',
928 1234 ),
929 1235 ),
@@ -937,45 +1243,56 @@
937 1243 * Transform the command-tool subset before merging with the
938 1244 * built-in + registered tools. Useful for bulk gating, renaming,
939 1245 * or injecting synthetic command tools.
940 1246 *
941 - * @since 0.17.0
942 - *
943 1247 * @param array $command_defs Command tool definitions.
944 1248 * @param array $context { user_id, request_id }.
945 1249 */
946 1250 $command_defs = (array) apply_filters(
947 - 'desktop_mode_ai_command_tools',
1251 + 'openstation_ai_command_tools',
948 1252 $command_defs,
949 - array( 'user_id' => $user_id, 'request_id' => $request_id )
1253 + array(
1254 + 'user_id' => $user_id,
1255 + 'request_id' => $request_id,
1256 + )
950 1257 );
951 1258
952 - $tools = array_merge( $builtin_tools, $registered_defs, $command_defs );
1259 + $tools = array_merge( $builtin_tools, $command_defs );
953 1260
954 1261 /**
955 - * Transform the full tool list (built-in + PHP-registered + command)
956 - * just before it goes to OpenAI. Fires once per run — changes apply
957 - * to every iteration in the agent loop.
1262 + * Transform the full tool list (built-in abilities + command tools) just
1263 + * before it goes to the provider. Fires once per run — changes apply to
1264 + * every iteration in the agent loop.
958 1265 *
959 - * @since 0.17.0
960 - *
961 - * @param array $tools Full OpenAI tool definitions array.
1266 + * @param array $tools Full the provider tool definitions array.
962 1267 * @param array $context { user_id, request_id, query }.
963 1268 */
964 1269 $tools = (array) apply_filters(
965 - 'desktop_mode_ai_tools',
1270 + 'openstation_ai_tools',
966 1271 $tools,
967 - array( 'user_id' => $user_id, 'request_id' => $request_id, 'query' => $query )
1272 + array(
1273 + 'user_id' => $user_id,
1274 + 'request_id' => $request_id,
1275 + 'query' => $query,
1276 + )
968 1277 );
969 1278
970 - // Widen the permitted-tools list to include everything we just
971 - // assembled — the agent loop rejects any `function_call` whose
972 - // name isn't in here.
973 - foreach ( $registered_defs as $def ) {
974 - if ( isset( $def['name'] ) ) {
975 - $valid_tools[] = (string) $def['name'];
1279 + // Normalize every tool's schema onto the provider-supported subset, AFTER the
1280 + // filter so it covers the complete list the provider will receive — built-in
1281 + // abilities, command tools, and anything a plugin injected. One tool with a
1282 + // legal-but-unsupported schema otherwise 400s the entire request, not just its
1283 + // own tool. Only the model-facing copy is reshaped; abilities still validate
1284 + // arguments against their real schema in execute(). Idempotent, so a plugin
1285 + // that already normalizes on the filter above is unaffected.
1286 + foreach ( $tools as $ti => $tool ) {
1287 + if ( is_array( $tool ) && isset( $tool['parameters'] ) ) {
1288 + $tools[ $ti ]['parameters'] = openstation_ai_normalize_tool_schema( $tool['parameters'] );
976 1289 }
977 1290 }
1291 +
1292 + // Widen the permitted-tools list with the command tools — the agent loop
1293 + // rejects any `function_call` whose name isn't in here (built-in ability
1294 + // names were added above).
978 1295 foreach ( $command_defs as $def ) {
979 1296 if ( isset( $def['name'] ) ) {
980 1297 $valid_tools[] = (string) $def['name'];
981 1298 }
@@ -980,76 +1297,76 @@
980 1297 $valid_tools[] = (string) $def['name'];
981 1298 }
982 1299 }
983 1300
984 - $text_format = array(
985 - 'type' => 'json_schema',
986 - 'name' => 'search_answer',
987 - 'strict' => true,
988 - 'schema' => desktop_mode_ai_search_answer_schema(),
989 - );
1301 + $answer_schema = openstation_ai_search_answer_schema();
990 1302
991 - $emit( array( 'phase' => 'start', 'message' => 'Thinking about your question…' ) );
992 -
993 1303 // -----------------------------------------------------------------------
994 - // First call — user query as input, instructions as system guidance.
995 - // Dispatched through the active provider (default: OpenAI). State is
996 - // opaque to the loop — providers stash whatever continuation token
997 - // they need (OpenAI: previous_response_id; others may use nothing).
1304 + // First call — user query as the sole message, instructions as system
1305 + // guidance. Generation routes through the WordPress AI Client; the tools
1306 + // are advertised as function declarations and dispatched by this loop.
1307 + // The full ordered conversation is rebuilt and re-sent each turn.
998 1308 // -----------------------------------------------------------------------
999 - $turn_input = desktop_mode_ai_provider_make_turn_input( $user_id, 'user_message', $query );
1000 - if ( is_wp_error( $turn_input ) ) {
1001 - return $turn_input;
1002 - }
1309 + $messages = array( openstation_ai_user_text_message( $query ) );
1003 1310
1004 - $turn = desktop_mode_ai_provider_agentic_call(
1005 - $user_id,
1006 - $api_key,
1007 - $turn_input,
1008 - $tools,
1009 - $text_format,
1010 - $instructions,
1011 - null
1311 + $generation_context = array(
1312 + 'source' => 'ai-copilot/search',
1313 + 'request_id' => $request_id,
1012 1314 );
1013 1315
1316 + $turn = openstation_ai_client_generate( $user_id, $messages, $tools, $answer_schema, $instructions, $generation_context );
1317 +
1014 1318 if ( is_wp_error( $turn ) ) {
1015 1319 return $turn;
1016 1320 }
1017 1321
1018 - $state = $turn['next_state'];
1019 1322 $last_tool = $initial_tool ?? 'search_posts';
1020 1323 $last_offset = $start_offset;
1021 1324 $last_has_more = true;
1022 1325 $iterations = 0;
1023 1326
1327 + // Accumulate token usage across every turn and remember the last model the
1328 + // AI Client resolved, for the `openstation_ai_search_completed` payload.
1329 + $total_usage = array(
1330 + 'prompt' => 0,
1331 + 'completion' => 0,
1332 + 'total' => 0,
1333 + );
1334 + $last_model = null;
1335 + $accrue_usage = static function ( $turn ) use ( &$total_usage, &$last_model ) {
1336 + if ( ! is_array( $turn ) ) {
1337 + return;
1338 + }
1339 + if ( isset( $turn['usage'] ) && is_array( $turn['usage'] ) ) {
1340 + $total_usage['prompt'] += (int) ( $turn['usage']['prompt'] ?? 0 );
1341 + $total_usage['completion'] += (int) ( $turn['usage']['completion'] ?? 0 );
1342 + $total_usage['total'] += (int) ( $turn['usage']['total'] ?? 0 );
1343 + }
1344 + if ( isset( $turn['model'] ) && is_array( $turn['model'] ) ) {
1345 + $last_model = $turn['model'];
1346 + }
1347 + };
1348 + $accrue_usage( $turn );
1349 +
1024 1350 // -----------------------------------------------------------------------
1025 1351 // Agentic loop — each iteration either executes tool calls or returns
1026 - // the final answer. We use `previous_response_id` so OpenAI manages the
1027 - // conversation state; we only send what's new each turn.
1352 + // the final answer. The full ordered conversation (user query, assistant
1353 + // turns, tool results) is accumulated in $messages and re-sent each turn.
1028 1354 // -----------------------------------------------------------------------
1029 - for ( $i = 0; $i < DESKTOP_MODE_AI_SEARCH_MAX_ITERATIONS; $i++ ) {
1355 + for ( $i = 0; $i < OPENSTATION_AI_SEARCH_MAX_ITERATIONS; $i++ ) {
1030 1356 $function_calls = is_array( $turn['function_calls'] ?? null ) ? $turn['function_calls'] : array();
1031 1357
1032 1358 // No tool calls in this response → final answer.
1033 1359 if ( empty( $function_calls ) ) {
1034 - $emit( array( 'phase' => 'composing', 'message' => 'Putting together your answer…' ) );
1035 - $text = $turn['text'] ?? null;
1036 - if ( ! is_string( $text ) ) {
1037 - // Log the raw output so mismatches in the provider response
1038 - // shape are visible without having to re-run with a debugger.
1039 - $raw = is_array( $turn['raw'] ?? null ) ? $turn['raw'] : array();
1040 - // phpcs:ignore WordPress.PHP.DevelopmentFunctions.error_log_error_log
1041 - error_log( '[WP Desktop Mode AI] Unexpected output shape: ' . wp_json_encode( $raw ) );
1042 - return new WP_Error(
1043 - 'desktop_mode_ai_empty',
1044 - 'AI provider returned no text in the final turn.',
1045 - array( 'raw' => $raw )
1046 - );
1047 - }
1360 + // A toolless turn with no extractable text never reaches here:
1361 + // openstation_ai_client_generate() returns
1362 + // `openstation_ai_empty_answer` for that case, handled with the
1363 + // other generation errors above.
1364 + $text = (string) ( $turn['text'] ?? '' );
1048 1365
1049 1366 $answer = json_decode( $text, true );
1050 1367 if ( ! is_array( $answer ) ) {
1051 - return new WP_Error( 'desktop_mode_ai_result_parse', 'Could not parse structured search answer.' );
1368 + return new WP_Error( 'openstation_ai_result_parse', __( 'Could not parse structured search answer.', 'desktop-mode' ) );
1052 1369 }
1053 1370
1054 1371 $answer_type = isset( $answer['answer_type'] ) && in_array( $answer['answer_type'], array( 'entity', 'navigation', 'chat' ), true )
1055 1372 ? (string) $answer['answer_type']
@@ -1063,9 +1380,9 @@
1063 1380 ? $answer['admin_links'] : null;
1064 1381
1065 1382 $entity = null;
1066 1383 if ( 'entity' === $answer_type && $entity_id && $entity_type ) {
1067 - $entity = desktop_mode_ai_search_build_entity( $entity_type, $entity_id );
1384 + $entity = openstation_ai_search_build_entity( $entity_type, $entity_id );
1068 1385 }
1069 1386
1070 1387 $final = array(
1071 1388 'answer_type' => $answer_type,
@@ -1082,21 +1399,23 @@
1082 1399 * Final transform hook — fires right before the HTTP
1083 1400 * response is returned. Plugins can rewrite `message`,
1084 1401 * inject `admin_links`, coerce `answer_type`, etc.
1085 1402 *
1086 - * @since 0.17.0
1087 - *
1088 1403 * @param array $answer Final answer payload.
1089 1404 * @param array $context { query, user_id, request_id }.
1090 1405 */
1091 1406 $final = (array) apply_filters(
1092 - 'desktop_mode_ai_answer',
1407 + 'openstation_ai_answer',
1093 1408 $final,
1094 - array( 'query' => $query, 'user_id' => $user_id, 'request_id' => $request_id )
1409 + array(
1410 + 'query' => $query,
1411 + 'user_id' => $user_id,
1412 + 'request_id' => $request_id,
1413 + )
1095 1414 );
1096 1415
1097 1416 do_action(
1098 - 'desktop_mode_ai_search_completed',
1417 + 'openstation_ai_search_completed',
1099 1418 array(
1100 1419 'query' => $query,
1101 1420 'user_id' => $user_id,
1102 1421 'request_id' => $request_id,
@@ -1101,8 +1420,10 @@
1101 1420 'user_id' => $user_id,
1102 1421 'request_id' => $request_id,
1103 1422 'answer_type' => $final['answer_type'] ?? 'chat',
1104 1423 'iterations' => $final['iterations'] ?? 0,
1424 + 'usage' => $total_usage,
1425 + 'model' => $last_model,
1105 1426 )
1106 1427 );
1107 1428
1108 1429 return $final;
@@ -1113,9 +1434,9 @@
1113 1434 //
1114 1435 // If the model emitted `command_<slug>`, we return immediately with
1115 1436 // `answer_type: 'tool_call'` — the client owns the command's `run()`
1116 1437 // function (lives in plugin JS) and executes it locally. We do NOT
1117 - // send anything else back to OpenAI this turn — would burn tokens
1438 + // send anything else back to the provider this turn — would burn tokens
1118 1439 // for a no-op second response.
1119 1440 // -------------------------------------------------------------------
1120 1441 $command_tool_call = null;
1121 1442 foreach ( $function_calls as $fc ) {
@@ -1120,11 +1441,10 @@
1120 1441 $command_tool_call = null;
1121 1442 foreach ( $function_calls as $fc ) {
1122 1443 $name = (string) ( $fc['name'] ?? '' );
1123 1444 if ( isset( $command_tools_by_name[ $name ] ) ) {
1124 - $decoded = is_array( json_decode( $fc['arguments'] ?? '{}', true ) )
1125 - ? json_decode( $fc['arguments'], true )
1126 - : array();
1445 + $raw = json_decode( $fc['arguments'] ?? '{}', true );
1446 + $decoded = is_array( $raw ) ? $raw : array();
1127 1447 $command_tool_call = array(
1128 1448 'slug' => $command_tools_by_name[ $name ]['slug'],
1129 1449 'args' => isset( $decoded['args'] ) ? (string) $decoded['args'] : '',
1130 1450 );
@@ -1130,11 +1450,11 @@
1130 1450 );
1131 1451 break;
1132 1452 }
1133 1453 }
1134 - if ( $command_tool_call !== null ) {
1454 + if ( null !== $command_tool_call ) {
1135 1455 do_action(
1136 - 'desktop_mode_ai_tool_called',
1456 + 'openstation_ai_tool_called',
1137 1457 array(
1138 1458 'tool_name' => 'command_' . $command_tool_call['slug'],
1139 1459 'args' => array( 'args' => $command_tool_call['args'] ),
1140 1460 'user_id' => $user_id,
@@ -1154,15 +1474,19 @@
1154 1474 'request_id' => $request_id,
1155 1475 );
1156 1476
1157 1477 $final = (array) apply_filters(
1158 - 'desktop_mode_ai_answer',
1478 + 'openstation_ai_answer',
1159 1479 $final,
1160 - array( 'query' => $query, 'user_id' => $user_id, 'request_id' => $request_id )
1480 + array(
1481 + 'query' => $query,
1482 + 'user_id' => $user_id,
1483 + 'request_id' => $request_id,
1484 + )
1161 1485 );
1162 1486
1163 1487 do_action(
1164 - 'desktop_mode_ai_search_completed',
1488 + 'openstation_ai_search_completed',
1165 1489 array(
1166 1490 'query' => $query,
1167 1491 'user_id' => $user_id,
1168 1492 'request_id' => $request_id,
@@ -1167,8 +1491,10 @@
1167 1491 'user_id' => $user_id,
1168 1492 'request_id' => $request_id,
1169 1493 'answer_type' => 'tool_call',
1170 1494 'iterations' => $final['iterations'] ?? 0,
1495 + 'usage' => $total_usage,
1496 + 'model' => $last_model,
1171 1497 )
1172 1498 );
1173 1499
1174 1500 return $final;
@@ -1173,12 +1499,11 @@
1173 1499
1174 1500 return $final;
1175 1501 }
1176 1502
1177 - // Execute each tool call and collect results in the registry's
1178 - // normalized shape — `{ call_id, output (json string) }`. The
1179 - // provider's `make_turn_input('tool_results', …)` reshapes them
1180 - // for the underlying API.
1503 + // Execute each tool call and collect results as
1504 + // `{ call_id, name, response }` — turned into FunctionResponse parts
1505 + // for the next turn by openstation_ai_tool_result_message().
1181 1506 $tool_outputs = array();
1182 1507 foreach ( $function_calls as $fc ) {
1183 1508 $tool_name = $fc['name'] ?? '';
1184 1509 $call_id = $fc['call_id'] ?? '';
@@ -1184,36 +1509,21 @@
1184 1509 $call_id = $fc['call_id'] ?? '';
1185 1510
1186 1511 if ( ! in_array( $tool_name, $valid_tools, true ) ) {
1187 1512 $tool_outputs[] = array(
1188 - 'call_id' => $call_id,
1189 - 'output' => wp_json_encode( array( 'error' => "Unknown tool '{$tool_name}'." ) ),
1513 + 'call_id' => $call_id,
1514 + 'name' => $tool_name,
1515 + 'response' => array( 'error' => "Unknown tool '{$tool_name}'." ),
1190 1516 );
1191 1517 continue;
1192 1518 }
1193 1519
1194 - $args = is_array( json_decode( $fc['arguments'] ?? '{}', true ) )
1195 - ? json_decode( $fc['arguments'], true )
1196 - : array();
1520 + $raw = json_decode( $fc['arguments'] ?? '{}', true );
1521 + $args = is_array( $raw ) ? $raw : array();
1197 1522 $offset = max( 0, (int) ( $args['offset'] ?? 0 ) );
1198 1523
1199 - // Registered PHP-dispatched tool — handler lives in the
1200 - // plugin's `desktop_mode_register_ai_tool()` entry. Capability
1201 - // was already checked at list-assembly time.
1202 - $is_registered = isset( $registered_by_name[ $tool_name ] );
1203 -
1204 - $progress_msg = $is_registered
1205 - ? ( (string) ( $registered_by_name[ $tool_name ]['progress_message'] ?? '' ) ?: 'Working…' )
1206 - : desktop_mode_ai_progress_message( $tool_name );
1207 -
1208 - $emit( array(
1209 - 'phase' => 'tool_call',
1210 - 'tool' => $tool_name,
1211 - 'message' => $progress_msg,
1212 - ) );
1213 -
1214 1524 do_action(
1215 - 'desktop_mode_ai_tool_called',
1525 + 'openstation_ai_tool_called',
1216 1526 array(
1217 1527 'tool_name' => $tool_name,
1218 1528 'args' => $args,
1219 1529 'user_id' => $user_id,
@@ -1220,27 +1530,52 @@
1220 1530 'request_id' => $request_id,
1221 1531 )
1222 1532 );
1223 1533
1224 - if ( $is_registered ) {
1225 - $batch = desktop_mode_ai_invoke_registered_tool(
1226 - $registered_by_name[ $tool_name ],
1227 - $args,
1228 - $user_id
1534 + // Resolve + run the ability. execute() runs the permission_callback
1535 + // and validates input/output; a denial or bad input comes back as a
1536 + // WP_Error, which we surface to the model as a clean tool error
1537 + // (never a fatal) and report on the observability channel.
1538 + $ability = isset( $ability_by_tool[ $tool_name ] ) ? wp_get_ability( $ability_by_tool[ $tool_name ] ) : null;
1539 + if ( $ability instanceof WP_Ability ) {
1540 + // Abilities that declare no input schema (e.g. Core's
1541 + // get-*-info) reject any non-null input, so pass null when
1542 + // there's no schema; otherwise hand over the decoded args.
1543 + $input = empty( $ability->get_input_schema() ) ? null : $args;
1544 + $result = $ability->execute( $input );
1545 + } else {
1546 + $result = new WP_Error( 'openstation_ai_unknown_ability', sprintf( 'Ability for tool "%s" is unavailable.', $tool_name ) );
1547 + }
1548 +
1549 + if ( is_wp_error( $result ) ) {
1550 + do_action(
1551 + 'openstation_ai_search_error',
1552 + array(
1553 + 'stage' => 'tool_execute',
1554 + 'tool_name' => $tool_name,
1555 + 'error' => $result->get_error_code(),
1556 + 'message' => $result->get_error_message(),
1557 + 'user_id' => $user_id,
1558 + 'request_id' => $request_id,
1559 + )
1229 1560 );
1561 + $batch = array(
1562 + 'error' => $result->get_error_message(),
1563 + 'error_code' => $result->get_error_code(),
1564 + );
1230 1565 } else {
1231 - $batch = desktop_mode_ai_search_dispatch_tool( $tool_name, $args );
1232 - $last_tool = $tool_name;
1233 - $last_offset = $offset;
1234 - $last_has_more = (bool) ( $batch['has_more'] ?? false );
1566 + $batch = is_array( $result ) ? $result : array( 'result' => $result );
1235 1567 }
1236 1568
1569 + $last_tool = $tool_name;
1570 + $last_offset = $offset;
1571 + $last_has_more = (bool) ( $batch['has_more'] ?? false );
1572 +
1237 1573 /**
1238 - * Transform a tool result before it goes back to the
1239 - * model. Fires for every tool, built-in and registered.
1574 + * Transform a tool result before it goes back to the model.
1575 + * Fires for every ability-dispatched tool (including error
1576 + * envelopes from a failed execute()).
1240 1577 *
1241 - * @since 0.17.0
1242 - *
1243 1578 * @param array $batch Tool result payload.
1244 1579 * @param string $tool_name Tool function name.
1245 1580 * @param array $args Decoded args from the call.
1246 1581 * @param array $context { user_id, request_id }.
@@ -1245,47 +1580,38 @@
1245 1580 * @param array $args Decoded args from the call.
1246 1581 * @param array $context { user_id, request_id }.
1247 1582 */
1248 1583 $batch = (array) apply_filters(
1249 - 'desktop_mode_ai_tool_result',
1584 + 'openstation_ai_tool_result',
1250 1585 $batch,
1251 1586 $tool_name,
1252 1587 $args,
1253 - array( 'user_id' => $user_id, 'request_id' => $request_id )
1588 + array(
1589 + 'user_id' => $user_id,
1590 + 'request_id' => $request_id,
1591 + )
1254 1592 );
1255 1593
1256 1594 $tool_outputs[] = array(
1257 - 'call_id' => $call_id,
1258 - 'output' => wp_json_encode( $batch ),
1595 + 'call_id' => $call_id,
1596 + 'name' => $tool_name,
1597 + 'response' => $batch,
1259 1598 );
1260 1599 }
1261 1600
1262 - $iterations++;
1601 + ++$iterations;
1263 1602
1264 - // Next turn — only send the tool results. Providers that support
1265 - // server-side context chaining (OpenAI's previous_response_id)
1266 - // use the opaque $state we threaded through; others can read
1267 - // the tool results and append them to whatever history they keep.
1268 - $turn_input = desktop_mode_ai_provider_make_turn_input( $user_id, 'tool_results', $tool_outputs );
1269 - if ( is_wp_error( $turn_input ) ) {
1270 - return $turn_input;
1271 - }
1603 + // Next turn — append the assistant's tool-call turn and our tool
1604 + // results to the conversation, then regenerate with the full history.
1605 + $messages[] = $turn['message'];
1606 + $messages[] = openstation_ai_tool_result_message( $tool_outputs );
1272 1607
1273 - $turn = desktop_mode_ai_provider_agentic_call(
1274 - $user_id,
1275 - $api_key,
1276 - $turn_input,
1277 - $tools,
1278 - $text_format,
1279 - '',
1280 - $state
1281 - );
1608 + $turn = openstation_ai_client_generate( $user_id, $messages, $tools, $answer_schema, $instructions, $generation_context );
1282 1609
1283 1610 if ( is_wp_error( $turn ) ) {
1284 1611 return $turn;
1285 1612 }
1286 -
1287 - $state = $turn['next_state'] ?? $state;
1613 + $accrue_usage( $turn );
1288 1614 }
1289 1615
1290 1616 // -----------------------------------------------------------------------
1291 1617 // Budget exhausted before a final answer.
@@ -1291,24 +1617,27 @@
1291 1617 // Budget exhausted before a final answer.
1292 1618 // -----------------------------------------------------------------------
1293 1619 $continue = null;
1294 1620 if ( $last_has_more ) {
1295 - $next_offset = $last_offset + DESKTOP_MODE_AI_SEARCH_BATCH_SIZE;
1296 - $type_label = str_replace( 'search_', '', $last_tool ) . 's';
1621 + $next_offset = $last_offset + OPENSTATION_AI_SEARCH_BATCH_SIZE;
1622 + // `search_comments_by_post` cannot resume — the continue payload
1623 + // carries no post_id — so fall back to plain comment search,
1624 + // keeping `tool` inside openstation_ai_search_resumable_tools().
1625 + $resume_tool = 'search_comments_by_post' === $last_tool ? 'search_comments' : $last_tool;
1297 1626 $continue = array(
1298 - 'tool' => $last_tool,
1299 - 'entity_type' => rtrim( str_replace( 'search_', '', $last_tool ), 's' ),
1627 + 'tool' => $resume_tool,
1628 + 'entity_type' => rtrim( str_replace( 'search_', '', $resume_tool ), 's' ),
1300 1629 'offset' => $next_offset,
1301 - 'label' => sprintf( 'Continue searching in %s (from item %d)', $type_label, $next_offset + 1 ),
1630 + 'label' => openstation_ai_continue_label( $resume_tool, $next_offset + 1 ),
1302 1631 );
1303 1632 }
1304 1633
1305 1634 $final = array(
1306 1635 'answer_type' => 'chat',
1307 - 'message' => 'I searched 100 items without finding a clear match. Want me to keep looking further?',
1636 + 'message' => __( 'I searched 100 items without finding a clear match. Want me to keep looking further?', 'desktop-mode' ),
1308 1637 'entity' => null,
1309 1638 'admin_links' => null,
1310 - 'iterations' => DESKTOP_MODE_AI_SEARCH_MAX_ITERATIONS,
1639 + 'iterations' => OPENSTATION_AI_SEARCH_MAX_ITERATIONS,
1311 1640 'exhausted' => ! $last_has_more,
1312 1641 'continue' => $continue,
1313 1642 'request_id' => $request_id,
1314 1643 );
@@ -1313,21 +1642,27 @@
1313 1642 'request_id' => $request_id,
1314 1643 );
1315 1644
1316 1645 $final = (array) apply_filters(
1317 - 'desktop_mode_ai_answer',
1646 + 'openstation_ai_answer',
1318 1647 $final,
1319 - array( 'query' => $query, 'user_id' => $user_id, 'request_id' => $request_id )
1648 + array(
1649 + 'query' => $query,
1650 + 'user_id' => $user_id,
1651 + 'request_id' => $request_id,
1652 + )
1320 1653 );
1321 1654
1322 1655 do_action(
1323 - 'desktop_mode_ai_search_completed',
1656 + 'openstation_ai_search_completed',
1324 1657 array(
1325 1658 'query' => $query,
1326 1659 'user_id' => $user_id,
1327 1660 'request_id' => $request_id,
1328 1661 'answer_type' => 'chat',
1329 - 'iterations' => DESKTOP_MODE_AI_SEARCH_MAX_ITERATIONS,
1662 + 'iterations' => OPENSTATION_AI_SEARCH_MAX_ITERATIONS,
1663 + 'usage' => $total_usage,
1664 + 'model' => $last_model,
1330 1665 )
1331 1666 );
1332 1667
1333 1668 return $final;
@@ -1340,18 +1675,17 @@
1340 1675 * keeps the voice consistent across legs and removes a class of drift
1341 1676 * bug where the two paths's prompt-assembly drifts apart.
1342 1677 *
1343 1678 * Applies three layers in order:
1344 - * 1. `desktop_mode_ai_system_prompt_appendix` — stacking filter;
1679 + * 1. `openstation_ai_system_prompt_appendix` — stacking filter;
1345 1680 * every plugin's return is concatenated.
1346 1681 * 2. Client override — `system_prompt_text` + `system_prompt_mode`.
1347 1682 * `append` always allowed; `replace` gated on
1348 - * `desktop_mode_ai_system_prompt_replace_capability`. Non-permitted
1683 + * `openstation_ai_system_prompt_replace_capability`. Non-permitted
1349 1684 * `replace` downgrades to `append` so the caller's text is
1350 1685 * preserved rather than dropped.
1351 - * 3. `desktop_mode_ai_system_prompt` — final transform pass.
1686 + * 3. `openstation_ai_system_prompt` — final transform pass.
1352 1687 *
1353 - * @since 0.17.0
1354 1688 * @internal
1355 1689 *
1356 1690 * @param string $core Built-in instructions for this phase
1357 1691 * (agent loop / follow-up summariser).
@@ -1359,9 +1693,9 @@
1359 1693 * @param array $client { text, mode } client override; either field
1360 1694 * empty means no override.
1361 1695 * @return string Composed system prompt.
1362 1696 */
1363 -function desktop_mode_ai_compose_instructions( $core, array $context, array $client = array() ) {
1697 +function openstation_ai_compose_instructions( $core, array $context, array $client = array() ) {
1364 1698 $instructions = (string) $core;
1365 1699 $user_id = isset( $context['user_id'] ) ? (int) $context['user_id'] : 0;
1366 1700
1367 1701 $client_text = isset( $client['text'] ) && is_string( $client['text'] ) ? $client['text'] : '';
@@ -1368,13 +1702,22 @@
1368 1702 $client_mode = isset( $client['mode'] ) && in_array( $client['mode'], array( 'append', 'replace' ), true )
1369 1703 ? (string) $client['mode']
1370 1704 : 'append';
1371 1705
1372 - $ctx_for_filter = $context;
1706 + $ctx_for_filter = $context;
1373 1707 $ctx_for_filter['client_override'] = '' !== $client_text ? $client_mode : null;
1374 1708
1375 - /** @see desktop_mode_ai_system_prompt_appendix — documented at primary call site. */
1376 - $server_appendix = (string) apply_filters( 'desktop_mode_ai_system_prompt_appendix', '', $ctx_for_filter );
1709 + /**
1710 + * Short-circuit extension — appended to the built-in instructions
1711 + * verbatim. Use this when a plugin just wants to add domain
1712 + * context (room list, product catalogue, company jargon) without
1713 + * restructuring the core rules. Fires for both the primary
1714 + * `/ai/search` run and the follow-up composed-reply leg.
1715 + *
1716 + * @param string $appendix Accumulated appendix. Default empty.
1717 + * @param array $context { query, user_id, request_id, client_override, phase? }.
1718 + */
1719 + $server_appendix = (string) apply_filters( 'openstation_ai_system_prompt_appendix', '', $ctx_for_filter );
1377 1720 if ( '' !== $server_appendix ) {
1378 1721 $instructions .= "\n\n" . $server_appendix;
1379 1722 }
1380 1723
@@ -1379,11 +1722,19 @@
1379 1722 }
1380 1723
1381 1724 if ( '' !== $client_text ) {
1382 1725 if ( 'replace' === $client_mode ) {
1383 - /** @see desktop_mode_ai_system_prompt_replace_capability — documented at primary call site. */
1726 + /**
1727 + * Capability required for a client to send
1728 + * `system_prompt: { mode: 'replace' }`. Defaults to `manage_options`
1729 + * — replacing the whole prompt can effectively hijack the
1730 + * assistant, so it's admin-only out of the box.
1731 + *
1732 + * @param string $capability Default `manage_options`.
1733 + * @param array $context
1734 + */
1384 1735 $required_cap = (string) apply_filters(
1385 - 'desktop_mode_ai_system_prompt_replace_capability',
1736 + 'openstation_ai_system_prompt_replace_capability',
1386 1737 'manage_options',
1387 1738 $ctx_for_filter
1388 1739 );
1389 1740 if ( '' === $required_cap || ( $user_id > 0 && user_can( $user_id, $required_cap ) ) ) {
@@ -1397,10 +1748,16 @@
1397 1748 $instructions .= "\n\n" . $client_text;
1398 1749 }
1399 1750 }
1400 1751
1401 - /** @see desktop_mode_ai_system_prompt — documented at primary call site. */
1402 - return (string) apply_filters( 'desktop_mode_ai_system_prompt', $instructions, $ctx_for_filter );
1752 + /**
1753 + * Final transform pass. Fires after the built-in instructions,
1754 + * server appendix, and client override have all been composed.
1755 + *
1756 + * @param string $instructions Composed system prompt.
1757 + * @param array $context
1758 + */
1759 + return (string) apply_filters( 'openstation_ai_system_prompt', $instructions, $ctx_for_filter );
1403 1760 }
1404 1761
1405 1762 /**
1406 1763 * Compose a natural-language reply describing the outcome of a
@@ -1407,38 +1764,35 @@
1407 1764 * client-dispatched command invocation.
1408 1765 *
1409 1766 * Called by the REST endpoint when the client sends `follow_up` —
1410 1767 * the second leg of the opt-in agentic flow triggered by
1411 - * `wp.desktop.ai.ask( q, { tools: 'aiCallable', followUp: true } )`.
1768 + * `wp.os.ai.ask( q, { tools: 'aiCallable', followUp: true } )`.
1412 1769 *
1413 1770 * Single-turn, no tools, no structured-output schema — the model
1414 1771 * sees the original query + a summary of what happened and writes a
1415 1772 * one/two-sentence reply in the voice of the system prompt. We reuse
1416 1773 * the same system-prompt pipeline as the main search so plugins
1417 - * appending instructions via `desktop_mode_ai_system_prompt_appendix`
1774 + * appending instructions via `openstation_ai_system_prompt_appendix`
1418 1775 * see consistent voice across the two legs.
1419 1776 *
1420 - * @since 0.17.0
1421 - *
1422 - * @param string $api_key OpenAI API key.
1423 1777 * @param string $query Original user query.
1424 1778 * @param array $tool { slug, args } — what ran.
1425 1779 * @param array $outcome Tool result payload. Opaque — JSON-encoded
1426 1780 * into the model's context so it can reason
1427 1781 * about whatever shape the plugin returned.
1428 - * @param array $extra Same shape as `desktop_mode_ai_run_search`'s
1782 + * @param array $extra Same shape as `openstation_ai_run_search`'s
1429 1783 * `$extra` — carries user_id, request_id,
1430 1784 * system-prompt overrides.
1431 1785 * @return array|WP_Error `{ answer_type: 'chat', message, … }` or error.
1432 1786 */
1433 -function desktop_mode_ai_run_followup( $api_key, $query, array $tool, array $outcome, array $extra = array() ) {
1787 +function openstation_ai_run_followup( $query, array $tool, array $outcome, array $extra = array() ) {
1434 1788 $user_id = isset( $extra['user_id'] ) ? (int) $extra['user_id'] : get_current_user_id();
1435 - $request_id = isset( $extra['request_id'] ) && is_string( $extra['request_id'] ) && $extra['request_id'] !== ''
1789 + $request_id = isset( $extra['request_id'] ) && is_string( $extra['request_id'] ) && '' !== $extra['request_id']
1436 1790 ? (string) $extra['request_id']
1437 - : ( function_exists( 'wp_generate_uuid4' ) ? wp_generate_uuid4() : uniqid( 'desktop_mode_ai_', true ) );
1791 + : ( function_exists( 'wp_generate_uuid4' ) ? wp_generate_uuid4() : uniqid( 'openstation_ai_', true ) );
1438 1792
1439 1793 do_action(
1440 - 'desktop_mode_ai_search_started',
1794 + 'openstation_ai_search_started',
1441 1795 array(
1442 1796 'query' => $query,
1443 1797 'user_id' => $user_id,
1444 1798 'request_id' => $request_id,
@@ -1448,19 +1802,19 @@
1448 1802
1449 1803 // Mirror the main search's system-prompt layering so voice stays
1450 1804 // consistent between the two legs. We build a simpler core-
1451 1805 // instructions block — no tool guidance, since this run has none.
1452 - $instructions = "
1806 + $instructions = '
1453 1807 You are the same friendly WordPress assistant that just dispatched a command on behalf of the user. You now have the result of that command.
1454 1808
1455 -Write a SHORT reply (one or two sentences, first person, warm and conversational) describing what happened. Match the voice the site owner set in their system prompt — do not restart small talk, just confirm what you did.
1809 +Write a short reply (one or two sentences, first person, warm and conversational) describing what happened. Match the voice the site owner set in their system prompt — do not restart small talk, just confirm what you did.
1456 1810
1457 1811 Rules:
1458 -- If the outcome looks successful, confirm plainly. Example: \"Done — your office light is on now.\"
1812 +- If the outcome looks successful, confirm plainly. Example: "Done — your office light is on now."
1459 1813 - If the outcome looks like an error (has an `error` field, a failure message, or obviously negative content), apologise briefly and paraphrase what went wrong. Do not invent details the outcome did not include.
1460 -- Do NOT recommend the user try something else unless the outcome explicitly suggests it.
1461 -- Do NOT describe the tool mechanism (\"I called command_turn_light\") — the user only cares about the real-world effect.
1462 -";
1814 +- Suggest a next step only when the outcome itself suggests one.
1815 +- Describe the real-world effect, not the tool mechanism ("I called command_turn_light").
1816 +';
1463 1817
1464 1818 $system_prompt_text = isset( $extra['system_prompt_text'] ) && is_string( $extra['system_prompt_text'] ) ? $extra['system_prompt_text'] : '';
1465 1819 $system_prompt_mode = isset( $extra['system_prompt_mode'] ) && in_array( $extra['system_prompt_mode'], array( 'append', 'replace' ), true )
1466 1820 ? (string) $extra['system_prompt_mode']
@@ -1465,9 +1819,9 @@
1465 1819 $system_prompt_mode = isset( $extra['system_prompt_mode'] ) && in_array( $extra['system_prompt_mode'], array( 'append', 'replace' ), true )
1466 1820 ? (string) $extra['system_prompt_mode']
1467 1821 : 'append';
1468 1822
1469 - $instructions = desktop_mode_ai_compose_instructions(
1823 + $instructions = openstation_ai_compose_instructions(
1470 1824 $instructions,
1471 1825 array(
1472 1826 'query' => $query,
1473 1827 'user_id' => $user_id,
@@ -1473,9 +1827,12 @@
1473 1827 'user_id' => $user_id,
1474 1828 'request_id' => $request_id,
1475 1829 'phase' => 'follow_up',
1476 1830 ),
1477 - array( 'text' => $system_prompt_text, 'mode' => $system_prompt_mode )
1831 + array(
1832 + 'text' => $system_prompt_text,
1833 + 'mode' => $system_prompt_mode,
1834 + )
1478 1835 );
1479 1836
1480 1837 $slug = isset( $tool['slug'] ) ? (string) $tool['slug'] : '';
1481 1838 $tool_args = isset( $tool['args'] ) ? (string) $tool['args'] : '';
@@ -1484,9 +1841,9 @@
1484 1841 $outcome_json = '""';
1485 1842 }
1486 1843
1487 1844 // Bound the outcome payload so a malicious or buggy plugin that
1488 - // returns a 5MB blob can't inflate OpenAI token usage without
1845 + // returns a 5MB blob can't inflate the provider token usage without
1489 1846 // bound. 4 KB is enough for a status string, a small result list,
1490 1847 // or a short error envelope — anything bigger gets truncated with
1491 1848 // a marker so the model knows the tail was dropped.
1492 1849 //
@@ -1491,12 +1848,12 @@
1491 1848 // a marker so the model knows the tail was dropped.
1492 1849 //
1493 1850 // `mb_*` variants so truncation on a multibyte boundary
1494 1851 // (Japanese / emoji / accented UTF-8) can't produce invalid JSON
1495 - // that OpenAI would reject. Falls back to byte-level substr when
1852 + // that the provider would reject. Falls back to byte-level substr when
1496 1853 // mbstring is unavailable (rare but possible on minimal PHP
1497 1854 // builds).
1498 - $max_outcome_len = (int) apply_filters( 'desktop_mode_ai_followup_outcome_max_chars', 4000 );
1855 + $max_outcome_len = (int) apply_filters( 'openstation_ai_followup_outcome_max_chars', 4000 );
1499 1856 if ( $max_outcome_len > 0 ) {
1500 1857 $has_mbstring = function_exists( 'mb_strlen' ) && function_exists( 'mb_substr' );
1501 1858 $current_len = $has_mbstring
1502 1859 ? mb_strlen( $outcome_json, 'UTF-8' )
@@ -1501,9 +1858,9 @@
1501 1858 $current_len = $has_mbstring
1502 1859 ? mb_strlen( $outcome_json, 'UTF-8' )
1503 1860 : strlen( $outcome_json );
1504 1861 if ( $current_len > $max_outcome_len ) {
1505 - $outcome_json = $has_mbstring
1862 + $outcome_json = $has_mbstring
1506 1863 ? mb_substr( $outcome_json, 0, $max_outcome_len, 'UTF-8' )
1507 1864 : substr( $outcome_json, 0, $max_outcome_len );
1508 1865 $outcome_json .= '…[truncated]';
1509 1866 }
@@ -1517,35 +1874,41 @@
1517 1874 $outcome_json
1518 1875 );
1519 1876
1520 1877 do_action(
1521 - 'desktop_mode_ai_tool_called',
1878 + 'openstation_ai_tool_called',
1522 1879 array(
1523 1880 'tool_name' => 'followup_summarise',
1524 - 'args' => array( 'slug' => $slug, 'tool_args' => $tool_args ),
1881 + 'args' => array(
1882 + 'slug' => $slug,
1883 + 'tool_args' => $tool_args,
1884 + ),
1525 1885 'user_id' => $user_id,
1526 1886 'request_id' => $request_id,
1527 1887 )
1528 1888 );
1529 1889
1530 - $turn_input = desktop_mode_ai_provider_make_turn_input( $user_id, 'user_message', $user_message );
1531 - if ( is_wp_error( $turn_input ) ) {
1532 - return $turn_input;
1533 - }
1534 -
1535 - $turn = desktop_mode_ai_provider_agentic_call(
1890 + $turn = openstation_ai_client_generate(
1536 1891 $user_id,
1537 - $api_key,
1538 - $turn_input,
1539 - array(), // no tools — we want a plain reply
1540 - null, // no JSON schema — free-form text
1892 + array( openstation_ai_user_text_message( $user_message ) ),
1893 + array(), // no tools — we want a plain reply
1894 + null, // no JSON schema — free-form text
1541 1895 $instructions,
1542 - null
1896 + array(
1897 + 'source' => 'ai-copilot/followup',
1898 + 'request_id' => $request_id,
1899 + )
1543 1900 );
1544 1901
1545 - if ( is_wp_error( $turn ) ) {
1902 + // `openstation_ai_empty_answer` is the one generation error this path
1903 + // deliberately absorbs: the command DID run, so a text-less summary turn
1904 + // degrades to the generic confirmation below instead of surfacing as a
1905 + // failure of the command itself.
1906 + $empty_answer = is_wp_error( $turn ) && 'openstation_ai_empty_answer' === $turn->get_error_code();
1907 +
1908 + if ( is_wp_error( $turn ) && ! $empty_answer ) {
1546 1909 do_action(
1547 - 'desktop_mode_ai_search_error',
1910 + 'openstation_ai_search_error',
1548 1911 array(
1549 1912 'code' => $turn->get_error_code(),
1550 1913 'message' => $turn->get_error_message(),
1551 1914 'data' => $turn->get_error_data(),
@@ -1556,12 +1919,12 @@
1556 1919 );
1557 1920 return $turn;
1558 1921 }
1559 1922
1560 - $text = $turn['text'] ?? null;
1923 + $text = $empty_answer ? null : ( $turn['text'] ?? null );
1561 1924 $fallback = false;
1562 1925 if ( ! is_string( $text ) || '' === trim( $text ) ) {
1563 - // Graceful degrade — if OpenAI returned nothing usable, fall
1926 + // Graceful degrade — if the provider returned nothing usable, fall
1564 1927 // back to a generic confirmation so the caller always has a
1565 1928 // message to show. Better than returning an error and losing
1566 1929 // the fact that the command *did* run. We flag the degrade so
1567 1930 // observability subscribers can distinguish a deliberate
@@ -1578,14 +1941,17 @@
1578 1941 'iterations' => 1,
1579 1942 'exhausted' => false,
1580 1943 'continue' => null,
1581 1944 'request_id' => $request_id,
1582 - 'tool' => array( 'slug' => $slug, 'args' => $tool_args ),
1945 + 'tool' => array(
1946 + 'slug' => $slug,
1947 + 'args' => $tool_args,
1948 + ),
1583 1949 'fallback' => $fallback,
1584 1950 );
1585 1951
1586 1952 $final = (array) apply_filters(
1587 - 'desktop_mode_ai_answer',
1953 + 'openstation_ai_answer',
1588 1954 $final,
1589 1955 array(
1590 1956 'query' => $query,
1591 1957 'user_id' => $user_id,
@@ -1594,9 +1960,9 @@
1594 1960 )
1595 1961 );
1596 1962
1597 1963 do_action(
1598 - 'desktop_mode_ai_search_completed',
1964 + 'openstation_ai_search_completed',
1599 1965 array(
1600 1966 'query' => $query,
1601 1967 'user_id' => $user_id,
1602 1968 'request_id' => $request_id,
@@ -1615,21 +1981,19 @@
1615 1981 // ---------------------------------------------------------------------------
1616 1982
1617 1983 /**
1618 1984 * Registers the AI search REST route.
1619 - *
1620 - * @since 0.14.0
1621 1985 */
1622 -function desktop_mode_register_ai_search_rest_route() {
1986 +function openstation_register_ai_search_rest_route() {
1623 1987 register_rest_route(
1624 1988 'desktop-mode/v1',
1625 1989 '/ai/search',
1626 1990 array(
1627 1991 'methods' => WP_REST_Server::CREATABLE,
1628 - 'callback' => 'desktop_mode_rest_ai_search',
1629 - 'permission_callback' => 'desktop_mode_rest_ai_search_permission',
1992 + 'callback' => 'openstation_rest_ai_search',
1993 + 'permission_callback' => 'openstation_rest_ai_search_permission',
1630 1994 'args' => array(
1631 - 'query' => array(
1995 + 'query' => array(
1632 1996 'required' => true,
1633 1997 'type' => 'string',
1634 1998 'sanitize_callback' => 'sanitize_text_field',
1635 1999 'validate_callback' => static function ( $v ) {
@@ -1639,18 +2003,18 @@
1639 2003 // `resume_tool` + `start_offset` are only set when the
1640 2004 // client is continuing a previous search from the `continue`
1641 2005 // object returned by an exhausted run. Fresh searches leave
1642 2006 // both unset — the agent picks tools from query semantics.
1643 - 'resume_tool' => array(
2007 + 'resume_tool' => array(
1644 2008 'required' => false,
1645 2009 'type' => array( 'string', 'null' ),
1646 2010 'default' => null,
1647 2011 'sanitize_callback' => static function ( $v ) {
1648 - return in_array( $v, array( 'search_posts', 'search_pages', 'search_comments' ), true )
2012 + return in_array( $v, openstation_ai_search_resumable_tools(), true )
1649 2013 ? $v : null;
1650 - },
2014 + },
1651 2015 ),
1652 - 'start_offset' => array(
2016 + 'start_offset' => array(
1653 2017 'required' => false,
1654 2018 'type' => 'integer',
1655 2019 'default' => 0,
1656 2020 'sanitize_callback' => 'absint',
@@ -1659,9 +2023,9 @@
1659 2023 // opted in as AI tools. Each entry: { slug, label, description?, hint? }.
1660 2024 // The slug is namespaced server-side as `command_<slug>`
1661 2025 // and any tool_call the model emits with that name short-
1662 2026 // circuits back to the client for local dispatch.
1663 - 'command_tools' => array(
2027 + 'command_tools' => array(
1664 2028 'required' => false,
1665 2029 'type' => 'array',
1666 2030 'default' => array(),
1667 2031 'items' => array(
@@ -1674,12 +2038,12 @@
1674 2038 ),
1675 2039 ),
1676 2040 ),
1677 2041 // Free-form system-prompt override.
1678 - // mode: 'append' → concatenated onto the built-in prompt (safe for everyone)
1679 - // mode: 'replace' → replaces the built-in prompt entirely, gated on
1680 - // `desktop_mode_ai_system_prompt_replace_capability`
1681 - // (default `manage_options`).
2042 + // mode: 'append' → concatenated onto the built-in prompt (safe for everyone)
2043 + // mode: 'replace' → replaces the built-in prompt entirely, gated on
2044 + // `openstation_ai_system_prompt_replace_capability`
2045 + // (default `manage_options`).
1682 2046 'system_prompt_text' => array(
1683 2047 'required' => false,
1684 2048 'type' => 'string',
1685 2049 'default' => '',
@@ -1694,11 +2058,11 @@
1694 2058 ),
1695 2059 // Follow-up leg of the agentic command-dispatch flow.
1696 2060 // When present, the endpoint SKIPS the agent loop entirely
1697 2061 // and runs a single-turn "summarise this outcome" call
1698 - // through OpenAI instead. The client sends this on the
2062 + // through the provider instead. The client sends this on the
1699 2063 // second leg of `ask( q, { tools: 'aiCallable', followUp: true } )`.
1700 - 'follow_up' => array(
2064 + 'follow_up' => array(
1701 2065 'required' => false,
1702 2066 'type' => array( 'object', 'null' ),
1703 2067 'default' => null,
1704 2068 ),
@@ -1705,32 +2069,46 @@
1705 2069 ),
1706 2070 )
1707 2071 );
1708 2072 }
1709 -add_action( 'rest_api_init', 'desktop_mode_register_ai_search_rest_route' );
2073 +add_action( 'rest_api_init', 'openstation_register_ai_search_rest_route' );
1710 2074
1711 2075 /**
1712 2076 * Permission callback.
1713 2077 *
1714 - * @since 0.14.0
1715 - *
1716 2078 * @return bool|WP_Error
1717 2079 */
1718 -function desktop_mode_rest_ai_search_permission() {
2080 +function openstation_rest_ai_search_permission() {
1719 2081 if ( ! is_user_logged_in() || ! current_user_can( 'read' ) ) {
1720 2082 return new WP_Error(
1721 - 'desktop_mode_ai_forbidden',
1722 - 'You must be logged in to use the AI search.',
2083 + 'openstation_ai_forbidden',
2084 + __( 'You must be logged in to use the AI assistant.', 'desktop-mode' ),
1723 2085 array( 'status' => 403 )
1724 2086 );
1725 2087 }
1726 - if ( ! desktop_mode_ai_is_enabled( get_current_user_id() ) ) {
2088 + if ( ! openstation_ai_is_available() ) {
1727 2089 return new WP_Error(
1728 - 'desktop_mode_ai_disabled',
1729 - 'AI features are not enabled. Enable them in OS Settings → AI Settings.',
1730 - array( 'status' => 403 )
2090 + 'openstation_ai_unavailable',
2091 + __( 'The AI assistant is unavailable on this site.', 'desktop-mode' ),
2092 + array( 'status' => 503 )
1731 2093 );
1732 2094 }
2095 + if ( ! openstation_ai_is_enabled( get_current_user_id() ) ) {
2096 + // The message names the tab for consumers that only get text (a REST
2097 + // client, `wp.os.ai.ask()`). `settings_tab` names it again as data,
2098 + // so the overlay can offer a one-click link without parsing prose.
2099 + return new WP_Error(
2100 + 'openstation_ai_disabled',
2101 + __(
2102 + 'The AI assistant is turned off. Enable it in OpenStation Preferences → Features.',
2103 + 'desktop-mode'
2104 + ),
2105 + array(
2106 + 'status' => 403,
2107 + 'settings_tab' => 'features',
2108 + )
2109 + );
2110 + }
1733 2111 return true;
1734 2112 }
1735 2113
1736 2114 /**
@@ -1735,16 +2113,19 @@
1735 2113
1736 2114 /**
1737 2115 * POST /desktop-mode/v1/ai/search
1738 2116 *
1739 - * @since 0.14.0
1740 - *
1741 2117 * @param WP_REST_Request $request
1742 2118 * @return WP_REST_Response|WP_Error
1743 2119 */
1744 -function desktop_mode_rest_ai_search( WP_REST_Request $request ) {
2120 +function openstation_rest_ai_search( WP_REST_Request $request ) {
2121 + // The agent loop runs up to OPENSTATION_AI_SEARCH_MAX_ITERATIONS model
2122 + // round-trips, each with a tool call, which overruns a default 30s
2123 + // max_execution_time. The streaming endpoint used to raise this; it is
2124 + // the only path now, so it carries the limit.
2125 + @set_time_limit( 120 ); // phpcs:ignore
2126 +
1745 2127 $user_id = get_current_user_id();
1746 - $api_key = desktop_mode_ai_get_api_key( $user_id );
1747 2128 $query = $request->get_param( 'query' );
1748 2129 $resume_tool = $request->get_param( 'resume_tool' );
1749 2130 $start_offset = $request->get_param( 'start_offset' );
1750 2131
@@ -1754,9 +2135,9 @@
1754 2135 }
1755 2136
1756 2137 $extra = array(
1757 2138 'user_id' => $user_id,
1758 - 'request_id' => function_exists( 'wp_generate_uuid4' ) ? wp_generate_uuid4() : uniqid( 'desktop_mode_ai_', true ),
2139 + 'request_id' => function_exists( 'wp_generate_uuid4' ) ? wp_generate_uuid4() : uniqid( 'openstation_ai_', true ),
1759 2140 'command_tools' => $command_tools,
1760 2141 'system_prompt_text' => (string) $request->get_param( 'system_prompt_text' ),
1761 2142 'system_prompt_mode' => (string) $request->get_param( 'system_prompt_mode' ),
1762 2143 );
@@ -1765,15 +2146,13 @@
1765 2146 * Last-mile filter on the whole `/ai/search` request bundle.
1766 2147 * Plugins get one hook to rewrite query, swap tools, or inject
1767 2148 * metadata before the agent loop starts.
1768 2149 *
1769 - * @since 0.17.0
1770 - *
1771 2150 * @param array $extra Extended context (mutable).
1772 2151 * @param array $core Core request params { query, resume_tool, start_offset }.
1773 2152 */
1774 2153 $extra = (array) apply_filters(
1775 - 'desktop_mode_ai_request',
2154 + 'openstation_ai_request',
1776 2155 $extra,
1777 2156 array(
1778 2157 'query' => $query,
1779 2158 'resume_tool' => $resume_tool,
@@ -1787,17 +2166,17 @@
1787 2166 $tool = $follow_up['tool'];
1788 2167 $outcome = isset( $follow_up['result'] )
1789 2168 ? ( is_array( $follow_up['result'] ) ? $follow_up['result'] : array( 'value' => $follow_up['result'] ) )
1790 2169 : array();
1791 - $result = desktop_mode_ai_run_followup( $api_key, $query, $tool, $outcome, $extra );
2170 + $result = openstation_ai_run_followup( $query, $tool, $outcome, $extra );
1792 2171 } else {
1793 - $result = desktop_mode_ai_run_search( $api_key, $query, $resume_tool, $start_offset, null, $extra );
2172 + $result = openstation_ai_run_search( $query, $resume_tool, $start_offset, $extra );
1794 2173 }
1795 2174
1796 2175 if ( is_wp_error( $result ) ) {
1797 2176 $request_id = isset( $extra['request_id'] ) ? (string) $extra['request_id'] : '';
1798 2177 do_action(
1799 - 'desktop_mode_ai_search_error',
2178 + 'openstation_ai_search_error',
1800 2179 array(
1801 2180 'code' => $result->get_error_code(),
1802 2181 'message' => $result->get_error_message(),
1803 2182 'data' => $result->get_error_data(),
@@ -1819,16 +2198,14 @@
1819 2198
1820 2199 /**
1821 2200 * Search the WordPress.org plugin directory.
1822 2201 *
1823 - * @since 0.14.0
1824 - *
1825 2202 * @param string $query Search terms.
1826 2203 * @return array Tool result payload ready for the model.
1827 2204 */
1828 -function desktop_mode_ai_fetch_wporg_plugins( $query ) {
2205 +function openstation_ai_fetch_wporg_plugins( $query ) {
1829 2206 $query = trim( (string) $query );
1830 - if ( $query === '' ) {
2207 + if ( '' === $query ) {
1831 2208 return array(
1832 2209 'tool' => 'search_wporg_plugins',
1833 2210 'query' => '',
1834 2211 'results' => array(),
@@ -1838,9 +2215,9 @@
1838 2215 }
1839 2216
1840 2217 // Transient cache to protect the w.org API from repeated queries
1841 2218 // within the same conversation.
1842 - $cache_key = 'desktop_mode_ai_plugins_' . md5( strtolower( $query ) );
2219 + $cache_key = 'openstation_ai_plugins_' . md5( strtolower( $query ) );
1843 2220 $cached = get_transient( $cache_key );
1844 2221 if ( is_array( $cached ) ) {
1845 2222 return $cached;
1846 2223 }
@@ -1897,9 +2274,9 @@
1897 2274 // Normalise — plugins_api sometimes returns arrays, sometimes objects.
1898 2275 $p = (array) $p;
1899 2276
1900 2277 $slug = isset( $p['slug'] ) ? (string) $p['slug'] : '';
1901 - if ( $slug === '' ) {
2278 + if ( '' === $slug ) {
1902 2279 continue;
1903 2280 }
1904 2281
1905 2282 $icon = '';
@@ -1926,8 +2303,9 @@
1926 2303 'short_description' => wp_strip_all_tags( $p['short_description'] ?? '' ),
1927 2304 'version' => (string) ( $p['version'] ?? '' ),
1928 2305 'author' => wp_strip_all_tags( $p['author'] ?? '' ),
1929 2306 'rating' => (int) ( $p['rating'] ?? 0 ), // 0-100
2307 + 'stars' => round( ( (int) ( $p['rating'] ?? 0 ) ) / 20, 1 ), // 0-5, as wordpress.org shows it
1930 2308 'num_ratings' => (int) ( $p['num_ratings'] ?? 0 ),
1931 2309 'active_installs' => (int) ( $p['active_installs'] ?? 0 ),
1932 2310 'last_updated' => (string) ( $p['last_updated'] ?? '' ),
1933 2311 'requires' => (string) ( $p['requires'] ?? '' ),
@@ -1965,20 +2343,18 @@
1965 2343 * falls back to the PHP ini `error_log` directive. If neither points at
1966 2344 * a readable file the tool reports log_available=false rather than
1967 2345 * throwing.
1968 2346 *
1969 - * @since 0.14.0
1970 - *
1971 2347 * @param int $lines Number of lines to return (clamped 1-500 by caller).
1972 2348 * @return array
1973 2349 */
1974 -function desktop_mode_ai_fetch_error_log( $lines = 50 ) {
2350 +function openstation_ai_fetch_error_log( $lines = 50 ) {
1975 2351 $candidates = array();
1976 2352 if ( defined( 'WP_CONTENT_DIR' ) ) {
1977 2353 $candidates[] = WP_CONTENT_DIR . '/debug.log';
1978 2354 }
1979 2355 $ini_log = (string) ini_get( 'error_log' );
1980 - if ( $ini_log !== '' && 'syslog' !== $ini_log ) {
2356 + if ( '' !== $ini_log && 'syslog' !== $ini_log ) {
1981 2357 $candidates[] = $ini_log;
1982 2358 }
1983 2359
1984 2360 /**
@@ -1984,13 +2360,11 @@
1984 2360 /**
1985 2361 * Filter the list of log-file paths to probe in order. Plugins that
1986 2362 * redirect errors somewhere non-standard can add their path here.
1987 2363 *
1988 - * @since 0.14.0
1989 - *
1990 2364 * @param string[] $candidates File paths, in probe order.
1991 2365 */
1992 - $candidates = (array) apply_filters( 'desktop_mode_ai_error_log_candidates', $candidates );
2366 + $candidates = (array) apply_filters( 'openstation_ai_error_log_candidates', $candidates );
1993 2367
1994 2368 $log_path = '';
1995 2369 foreach ( $candidates as $path ) {
1996 2370 if ( is_string( $path ) && is_file( $path ) && is_readable( $path ) ) {
@@ -1998,9 +2372,9 @@
1998 2372 break;
1999 2373 }
2000 2374 }
2001 2375
2002 - if ( $log_path === '' ) {
2376 + if ( '' === $log_path ) {
2003 2377 return array(
2004 2378 'tool' => 'get_php_error_log',
2005 2379 'log_available' => false,
2006 2380 'message' => 'No readable error log found. Enable WP_DEBUG_LOG in wp-config.php or set php_value error_log.',
@@ -2009,17 +2383,17 @@
2009 2383 'count' => 0,
2010 2384 );
2011 2385 }
2012 2386
2013 - $tail = desktop_mode_ai_tail_file( $log_path, $lines );
2387 + $tail = openstation_ai_tail_file( $log_path, $lines );
2014 2388
2015 2389 $entries = array();
2016 2390 foreach ( $tail as $line ) {
2017 2391 $line = trim( $line );
2018 - if ( $line === '' ) {
2392 + if ( '' === $line ) {
2019 2393 continue;
2020 2394 }
2021 - $entries[] = desktop_mode_ai_parse_log_line( $line );
2395 + $entries[] = openstation_ai_parse_log_line( $line );
2022 2396 }
2023 2397
2024 2398 return array(
2025 2399 'tool' => 'get_php_error_log',
@@ -2036,16 +2410,14 @@
2036 2410 * PHP's default format is `[<date>] <prefix>: <message>` where the
2037 2411 * prefix is usually "PHP Fatal error", "PHP Warning", etc. Falls back
2038 2412 * to a raw line when the format doesn't match.
2039 2413 *
2040 - * @since 0.14.0
2041 - *
2042 2414 * @param string $line
2043 2415 * @return array
2044 2416 */
2045 -function desktop_mode_ai_parse_log_line( $line ) {
2417 +function openstation_ai_parse_log_line( $line ) {
2046 2418 // Cap individual messages so a runaway stack trace doesn't balloon
2047 - // the payload sent to OpenAI.
2419 + // the payload sent to the provider.
2048 2420 $line = mb_substr( $line, 0, 600 );
2049 2421
2050 2422 $entry = array(
2051 2423 'timestamp' => '',
@@ -2073,15 +2445,13 @@
2073 2445 * slices off the trailing N+1 entries. Realistic error logs sit
2074 2446 * in the kilobyte range when admins look at them; if a site routinely
2075 2447 * lets logs grow into tens of MB, that's the symptom, not this read.
2076 2448 *
2077 - * @since 0.14.0
2078 - *
2079 2449 * @param string $path Absolute path to the file.
2080 2450 * @param int $lines
2081 2451 * @return string[] Lines in original order (oldest first).
2082 2452 */
2083 -function desktop_mode_ai_tail_file( $path, $lines ) {
2453 +function openstation_ai_tail_file( $path, $lines ) {
2084 2454 if ( ! function_exists( 'WP_Filesystem' ) ) {
2085 2455 require_once ABSPATH . 'wp-admin/includes/file.php';
2086 2456 }
2087 2457 WP_Filesystem();
@@ -2101,117 +2471,4 @@
2101 2471 }
2102 2472
2103 2473 return array_slice( $all, -1 * ( $lines + 1 ) );
2104 2474 }
2105 -
2106 -// ---------------------------------------------------------------------------
2107 -// Streaming endpoint (Server-Sent Events)
2108 -//
2109 -// EventSource can't send POST or custom headers, so we ride admin-ajax.php
2110 -// which handles cookie-based auth natively. The nonce goes in the URL.
2111 -// Output buffering is forcibly disabled and every emit is flushed so the
2112 -// browser receives progress ticks in real time.
2113 -// ---------------------------------------------------------------------------
2114 -
2115 -/**
2116 - * admin-ajax handler for the streaming search endpoint.
2117 - *
2118 - * URL: /wp-admin/admin-ajax.php?action=desktop_mode_ai_search_stream
2119 - * &nonce=<rest_nonce>
2120 - * &query=<user question>
2121 - * &resume_tool=<search_posts|…> (optional)
2122 - * &start_offset=<int> (optional)
2123 - *
2124 - * Emits SSE events:
2125 - * data: { "event": "progress", "phase": "tool_call", "message": "…" }
2126 - * data: { "event": "done", "result": { … } }
2127 - * data: { "event": "error", "message": "…" }
2128 - *
2129 - * @since 0.14.0
2130 - */
2131 -function desktop_mode_ai_ajax_search_stream() {
2132 - $nonce = isset( $_GET['nonce'] ) ? sanitize_text_field( wp_unslash( $_GET['nonce'] ) ) : '';
2133 - if ( ! wp_verify_nonce( $nonce, 'wp_rest' ) ) {
2134 - status_header( 403 );
2135 - exit;
2136 - }
2137 - if ( ! is_user_logged_in() || ! current_user_can( 'read' ) ) {
2138 - status_header( 403 );
2139 - exit;
2140 - }
2141 - $user_id = get_current_user_id();
2142 - if ( ! desktop_mode_ai_is_enabled( $user_id ) ) {
2143 - status_header( 403 );
2144 - exit;
2145 - }
2146 -
2147 - $query = isset( $_GET['query'] ) ? sanitize_text_field( wp_unslash( $_GET['query'] ) ) : ''; // phpcs:ignore WordPress.Security
2148 - if ( trim( $query ) === '' ) {
2149 - status_header( 400 );
2150 - exit;
2151 - }
2152 -
2153 - $resume_tool = isset( $_GET['resume_tool'] ) ? sanitize_key( wp_unslash( $_GET['resume_tool'] ) ) : null; // phpcs:ignore WordPress.Security
2154 - $start_offset = isset( $_GET['start_offset'] ) ? absint( $_GET['start_offset'] ) : 0; // phpcs:ignore WordPress.Security
2155 - if ( $resume_tool !== null && ! in_array( $resume_tool, array( 'search_posts', 'search_pages', 'search_comments', 'search_comments_by_post' ), true ) ) {
2156 - $resume_tool = null;
2157 - }
2158 -
2159 - // SSE headers — tell nginx to stop buffering, tell the browser this is
2160 - // a persistent event stream.
2161 - header( 'Content-Type: text/event-stream; charset=utf-8' );
2162 - header( 'Cache-Control: no-cache, no-store, must-revalidate' );
2163 - header( 'X-Accel-Buffering: no' );
2164 - header( 'Connection: keep-alive' );
2165 -
2166 - // Let other requests from this user proceed (release session lock).
2167 - if ( session_status() === PHP_SESSION_ACTIVE ) {
2168 - session_write_close();
2169 - }
2170 -
2171 - // Kill any output buffers PHP set up, otherwise nothing flushes until
2172 - // the request ends — which defeats the whole point of streaming.
2173 - while ( ob_get_level() > 0 ) {
2174 - @ob_end_flush(); // phpcs:ignore
2175 - }
2176 - @ini_set( 'output_buffering', 'off' ); // phpcs:ignore
2177 - @ini_set( 'zlib.output_compression', 'off' ); // phpcs:ignore
2178 - @set_time_limit( 120 ); // phpcs:ignore
2179 -
2180 - $emit = static function ( array $payload ) {
2181 - echo 'data: ' . wp_json_encode( $payload ) . "\n\n";
2182 - @ob_flush(); // phpcs:ignore
2183 - flush();
2184 - };
2185 -
2186 - // Initial tick so the EventSource opens immediately and the JS can
2187 - // start showing "Thinking…" without waiting for the first OpenAI call.
2188 - $emit( array( 'event' => 'open' ) );
2189 -
2190 - $api_key = desktop_mode_ai_get_api_key( $user_id );
2191 -
2192 - $result = desktop_mode_ai_run_search(
2193 - $api_key,
2194 - $query,
2195 - $resume_tool,
2196 - $start_offset,
2197 - function ( $progress ) use ( $emit ) {
2198 - $emit( array_merge( array( 'event' => 'progress' ), $progress ) );
2199 - }
2200 - );
2201 -
2202 - if ( is_wp_error( $result ) ) {
2203 - $emit( array(
2204 - 'event' => 'error',
2205 - 'message' => $result->get_error_message(),
2206 - 'code' => $result->get_error_code(),
2207 - ) );
2208 - } else {
2209 - $emit( array(
2210 - 'event' => 'done',
2211 - 'result' => $result,
2212 - ) );
2213 - }
2214 -
2215 - exit;
2216 -}
2217 -add_action( 'wp_ajax_desktop_mode_ai_search_stream', 'desktop_mode_ai_ajax_search_stream' );