| @@ -52,10 +52,22 @@ | ||
| 52 | 52 | * the shell can explain the new name once to the people it happened |
| 53 | 53 | * to and to nobody else. Sets user meta and nothing else — see |
| 54 | 54 | * {@see openstation_migrate_flag_rebrand_notice} for why that is a |
| 55 | 55 | * separate migration from 4. |
| 56 | + * - 6: the Trash stopped registering a desktop icon. Removes the | |
| 57 | + * placement the shell had auto-placed for it and closes the hole that | |
| 58 | + * leaves in the icon column. | |
| 59 | + * - 7: seeds a face for every agent that has none. | |
| 60 | + * - 8: retires automatic AI comment scoring. | |
| 61 | + * - 9: repairs the Comment Concierge's misspelled ability slug in every | |
| 62 | + * agent's stored allowlist. | |
| 63 | + * - 10: the first-run stamps and the shell tour. On a site with prior | |
| 64 | + * desktop use, records that the site was enabled before the stamps | |
| 65 | + * existed (`openstation_first_enabled_at` with `at: 0, via: backfill`) | |
| 66 | + * and marks the `shell-tour` intro seen for every prior user, so an | |
| 67 | + * update never greets a veteran with a first-boot tour. | |
| 56 | 68 | */ |
| 57 | -const OPENSTATION_MIGRATION_VERSION = 5; | |
| 69 | +const OPENSTATION_MIGRATION_VERSION = 10; | |
| 58 | 70 | |
| 59 | 71 | /** |
| 60 | 72 | * Option storing the highest migration version that has run. autoload=no. |
| 61 | 73 | * |
| @@ -149,11 +161,293 @@ | ||
| 149 | 161 | |
| 150 | 162 | if ( $from < 5 ) { |
| 151 | 163 | openstation_migrate_flag_rebrand_notice( $from ); |
| 152 | 164 | } |
| 165 | + | |
| 166 | + if ( $from < 6 ) { | |
| 167 | + openstation_migrate_close_recycle_bin_icon_gap(); | |
| 168 | + } | |
| 169 | + | |
| 170 | + if ( $from < 7 ) { | |
| 171 | + openstation_migrate_seed_agent_faces(); | |
| 172 | + } | |
| 173 | + | |
| 174 | + if ( $from < 8 ) { | |
| 175 | + openstation_migrate_remove_comments_ai(); | |
| 176 | + } | |
| 177 | + | |
| 178 | + if ( $from < 9 ) { | |
| 179 | + openstation_migrate_agent_ability_slugs(); | |
| 180 | + } | |
| 181 | + | |
| 182 | + if ( $from < 10 ) { | |
| 183 | + openstation_migrate_first_run_stamps(); | |
| 184 | + } | |
| 153 | 185 | } |
| 154 | 186 | |
| 155 | 187 | /** |
| 188 | + * Migration 9 — repair a misspelled ability slug in stored agent | |
| 189 | + * allowlists. | |
| 190 | + * | |
| 191 | + * The shipped Comment Concierge listed `desktop-mode/search-comments-on-post`, | |
| 192 | + * an ability that was never registered: the real one is | |
| 193 | + * `desktop-mode/search-comments-by-post`. The runner drops an unknown | |
| 194 | + * slug without a word, so every seeded Concierge ran without the one | |
| 195 | + * tool that reads a post's thread. Fixing the definition only reaches | |
| 196 | + * sites that seed from now on; this rewrites the slug in place on every | |
| 197 | + * agent that already stored it, whoever created the agent. | |
| 198 | + * | |
| 199 | + * Reads the meta directly rather than through the agents store, because | |
| 200 | + * that module only loads while the Agents feature is on and an agent | |
| 201 | + * row outlives the flag being turned off. The key is the frozen | |
| 202 | + * `_desktop_mode_agent_abilities`; nothing is renamed. | |
| 203 | + * | |
| 204 | + * @return void | |
| 205 | + */ | |
| 206 | +function openstation_migrate_agent_ability_slugs() { | |
| 207 | + $meta_key = '_desktop_mode_agent_abilities'; | |
| 208 | + $renames = array( | |
| 209 | + 'desktop-mode/search-comments-on-post' => 'desktop-mode/search-comments-by-post', | |
| 210 | + ); | |
| 211 | + | |
| 212 | + $user_ids = get_users( | |
| 213 | + array( | |
| 214 | + 'fields' => 'ID', | |
| 215 | + 'meta_key' => $meta_key, // phpcs:ignore WordPress.DB.SlowDBQuery.slow_db_query_meta_key -- one-time migration; the key is indexed in usermeta and the scan is guarded to run once. | |
| 216 | + 'meta_compare' => 'EXISTS', | |
| 217 | + ) | |
| 218 | + ); | |
| 219 | + | |
| 220 | + foreach ( $user_ids as $user_id ) { | |
| 221 | + $raw = get_user_meta( (int) $user_id, $meta_key, true ); | |
| 222 | + $slugs = is_string( $raw ) ? json_decode( $raw, true ) : $raw; | |
| 223 | + if ( ! is_array( $slugs ) ) { | |
| 224 | + continue; | |
| 225 | + } | |
| 226 | + | |
| 227 | + $changed = false; | |
| 228 | + foreach ( $slugs as $i => $slug ) { | |
| 229 | + if ( is_string( $slug ) && isset( $renames[ $slug ] ) ) { | |
| 230 | + $slugs[ $i ] = $renames[ $slug ]; | |
| 231 | + $changed = true; | |
| 232 | + } | |
| 233 | + } | |
| 234 | + if ( ! $changed ) { | |
| 235 | + continue; | |
| 236 | + } | |
| 237 | + | |
| 238 | + // Stored as a JSON string, the shape the agents store writes. | |
| 239 | + // Slashed because update_user_meta() unslashes its value. | |
| 240 | + update_user_meta( | |
| 241 | + (int) $user_id, | |
| 242 | + $meta_key, | |
| 243 | + wp_slash( (string) wp_json_encode( array_values( array_unique( $slugs ) ) ) ) | |
| 244 | + ); | |
| 245 | + } | |
| 246 | +} | |
| 247 | + | |
| 248 | +/** | |
| 249 | + * Migration 10 — the first-run stamps meet an install with a past. | |
| 250 | + * | |
| 251 | + * Two facts about a site that already had people in the shell, neither | |
| 252 | + * of which the stamps can learn on their own: | |
| 253 | + * | |
| 254 | + * 1. The site HAS activated. `openstation_first_enabled_at` is written | |
| 255 | + * the first time a user enables from here on, so without this an | |
| 256 | + * old, busy install would look like one nobody ever turned on: the | |
| 257 | + * activation nudge would show to its admins, and the deactivation | |
| 258 | + * funnel would read "never enabled". The stamp is recorded as | |
| 259 | + * `at: 0, via: backfill` — a real moment is not known and is not | |
| 260 | + * invented, and every age computation treats it as unknown. | |
| 261 | + * 2. Its users have already learned the shell. The tour is for a first | |
| 262 | + * boot, and the slug it records lives in the seen-intros registry, | |
| 263 | + * so marking it seen for every prior user is the whole opt-out. | |
| 264 | + * "Reset what's-new dialogs" brings it back for anyone curious. | |
| 265 | + * | |
| 266 | + * On a site with no history both loops are empty, and the runner fires | |
| 267 | + * at activation, where the activation hook that stamps the real install | |
| 268 | + * moment runs right after it. The install stamp is deliberately not | |
| 269 | + * written here: for the in-place update it belongs to the lazy | |
| 270 | + * `admin_init` backfill, which is honest about being a backfill. | |
| 271 | + * | |
| 272 | + * @return void | |
| 273 | + */ | |
| 274 | +function openstation_migrate_first_run_stamps() { | |
| 275 | + $prior_users = openstation_users_with_prior_desktop_use(); | |
| 276 | + if ( empty( $prior_users ) ) { | |
| 277 | + return; | |
| 278 | + } | |
| 279 | + | |
| 280 | + if ( null === openstation_get_first_enabled_stamp() ) { | |
| 281 | + add_option( | |
| 282 | + OPENSTATION_FIRST_ENABLED_AT_OPTION, | |
| 283 | + array( | |
| 284 | + 'at' => 0, | |
| 285 | + 'via' => 'backfill', | |
| 286 | + ), | |
| 287 | + '', | |
| 288 | + false | |
| 289 | + ); | |
| 290 | + } | |
| 291 | + | |
| 292 | + foreach ( $prior_users as $user_id ) { | |
| 293 | + openstation_mark_intro_seen( $user_id, OPENSTATION_SHELL_TOUR_INTRO_SLUG ); | |
| 294 | + } | |
| 295 | +} | |
| 296 | + | |
| 297 | +/** | |
| 298 | + * Migration 7 — give the agents that predate faces a seed to grow one | |
| 299 | + * from. | |
| 300 | + * | |
| 301 | + * Agents used to share a single grey robot glyph. They now carry a Mio | |
| 302 | + * look, and an agent created from here on gets a seed at birth. The | |
| 303 | + * ones already on the site do not, and without a seed there is nothing | |
| 304 | + * to derive a face from. | |
| 305 | + * | |
| 306 | + * **This writes the seed and stops.** It does not write the face. The | |
| 307 | + * face comes from `randomMioLook()`, which lives in TypeScript, and | |
| 308 | + * porting it is exactly the wrong trade: it is a taste filter with a | |
| 309 | + * dozen judgment calls in it, pinned by `mio-randomize.test.ts`, and a | |
| 310 | + * PHP twin of it would drift with nothing watching. So the shell fills | |
| 311 | + * the looks in on its next paint of the Agents section, rolling each | |
| 312 | + * one from the seed written here. | |
| 313 | + * | |
| 314 | + * That is a client writing on the server's behalf, which is worth | |
| 315 | + * naming rather than slipping past. It is safe because it is entirely | |
| 316 | + * derived: the seed is `crc32` of the login, so two admins racing the | |
| 317 | + * backfill produce byte-identical faces, and running it twice changes | |
| 318 | + * nothing. | |
| 319 | + * | |
| 320 | + * The five shipped agents are unaffected: their faces are written out | |
| 321 | + * in `default-definitions.php` and were never rolled. | |
| 322 | + * | |
| 323 | + * @return void | |
| 324 | + */ | |
| 325 | +function openstation_migrate_seed_agent_faces() { | |
| 326 | + // Agents is behind a feature flag, so on a site that has never | |
| 327 | + // turned it on there is nothing to seed, and none of the module's | |
| 328 | + // functions exist to call. A site that turns it on later creates | |
| 329 | + // its agents through `openstation_agent_create`, which seeds them | |
| 330 | + // at birth, so nothing is missed by returning here. | |
| 331 | + if ( | |
| 332 | + ! function_exists( 'openstation_agent_get_agents' ) | |
| 333 | + || ! function_exists( 'openstation_agent_get_face_seed' ) | |
| 334 | + || ! defined( 'OPENSTATION_AGENT_FACE_SEED_META' ) | |
| 335 | + ) { | |
| 336 | + return; | |
| 337 | + } | |
| 338 | + | |
| 339 | + foreach ( openstation_agent_get_agents() as $agent ) { | |
| 340 | + $user_id = isset( $agent->ID ) ? (int) $agent->ID : 0; | |
| 341 | + if ( $user_id <= 0 ) { | |
| 342 | + continue; | |
| 343 | + } | |
| 344 | + if ( openstation_agent_get_face_seed( $user_id ) > 0 ) { | |
| 345 | + continue; | |
| 346 | + } | |
| 347 | + update_user_meta( | |
| 348 | + $user_id, | |
| 349 | + OPENSTATION_AGENT_FACE_SEED_META, | |
| 350 | + crc32( (string) $agent->user_login ) | |
| 351 | + ); | |
| 352 | + } | |
| 353 | +} | |
| 354 | + | |
| 355 | +/** | |
| 356 | + * Grid the desktop auto-placer lays icons out on: 16px of padding, a | |
| 357 | + * 96px column, a 110px row. Mirrored from `src/desktop-files/grid.ts` | |
| 358 | + * via {@see openstation_files_auto_place_orphans}, which is what wrote | |
| 359 | + * the coordinates this migration edits. | |
| 360 | + */ | |
| 361 | +const OPENSTATION_DESKTOP_GRID_ROW_H = 110; | |
| 362 | + | |
| 363 | +/** | |
| 364 | + * Migration 6 — take back the Trash's desktop icon, and close the hole. | |
| 365 | + * | |
| 366 | + * The bin used to register a desktop icon, and every viewer's first | |
| 367 | + * hydrate auto-placed it into the icon column. Now that the | |
| 368 | + * registration is gone the placement is dead weight: it is no longer | |
| 369 | + * served (`OpenStation_Shortcut_File::can_read()` is false without a | |
| 370 | + * registry entry), so the tile has already vanished on its own. What it | |
| 371 | + * leaves behind is an empty cell with the icons that were under it | |
| 372 | + * still sitting where they were. | |
| 373 | + * | |
| 374 | + * So: delete the row, and pull everything below it in the same column | |
| 375 | + * up by one. Same column only, because the auto-placer fills | |
| 376 | + * column-major, so a column is the run the bin was part of. This does | |
| 377 | + * move tiles a user may have arranged, which is the point — the shell | |
| 378 | + * put that icon there and the shell is taking it away, so the shell | |
| 379 | + * tidies up after itself rather than leaving a gap nobody chose. | |
| 380 | + * | |
| 381 | + * A user who wants the bin back on the wallpaper picks "On the desktop" | |
| 382 | + * in Preferences → Navigation, which promotes the dock tile and never | |
| 383 | + * touches these rows. | |
| 384 | + * | |
| 385 | + * @return void | |
| 386 | + */ | |
| 387 | +function openstation_migrate_close_recycle_bin_icon_gap() { | |
| 388 | + global $wpdb; | |
| 389 | + | |
| 390 | + if ( ! function_exists( 'openstation_files_table_names' ) ) { | |
| 391 | + return; | |
| 392 | + } | |
| 393 | + $tables = openstation_files_table_names(); | |
| 394 | + $tbl = $tables['placements']; | |
| 395 | + | |
| 396 | + // The files schema installs lazily, so a site that never opened | |
| 397 | + // the desktop has no table to migrate. | |
| 398 | + $table_exists = (int) $wpdb->get_var( | |
| 399 | + $wpdb->prepare( | |
| 400 | + 'SELECT COUNT(*) FROM INFORMATION_SCHEMA.TABLES | |
| 401 | + WHERE TABLE_SCHEMA = DATABASE() AND TABLE_NAME = %s', | |
| 402 | + $tbl | |
| 403 | + ) | |
| 404 | + ); | |
| 405 | + if ( 0 === $table_exists ) { | |
| 406 | + return; | |
| 407 | + } | |
| 408 | + | |
| 409 | + // Shift first, delete second: the derived table has to still find | |
| 410 | + // the bin's own row to know which cell is being vacated. It is | |
| 411 | + // materialized before the update runs, so reading and writing the | |
| 412 | + // same table in one statement is fine here. | |
| 413 | + // | |
| 414 | + // The UNIQUE index on (owner_id, parent_id, file_type, file_ref) | |
| 415 | + // guarantees at most one bin row per owner, so no row can be | |
| 416 | + // shifted twice. | |
| 417 | + $wpdb->query( | |
| 418 | + $wpdb->prepare( | |
| 419 | + // phpcs:ignore WordPress.DB.PreparedSQL.InterpolatedNotPrepared -- table name, not user input. | |
| 420 | + "UPDATE `{$tbl}` AS p | |
| 421 | + INNER JOIN ( | |
| 422 | + SELECT owner_id, x, y FROM `{$tbl}` | |
| 423 | + WHERE parent_id = 0 | |
| 424 | + AND file_type = 'shortcut' | |
| 425 | + AND file_ref = %s | |
| 426 | + ) AS bin | |
| 427 | + ON p.owner_id = bin.owner_id | |
| 428 | + AND p.x = bin.x | |
| 429 | + AND p.y > bin.y | |
| 430 | + SET p.y = p.y - %d | |
| 431 | + WHERE p.parent_id = 0 | |
| 432 | + AND p.trashed_at_ms IS NULL", | |
| 433 | + 'desktop-mode-recycle-bin', | |
| 434 | + OPENSTATION_DESKTOP_GRID_ROW_H | |
| 435 | + ) | |
| 436 | + ); | |
| 437 | + | |
| 438 | + $wpdb->delete( | |
| 439 | + $tbl, | |
| 440 | + array( | |
| 441 | + 'parent_id' => 0, | |
| 442 | + 'file_type' => 'shortcut', | |
| 443 | + 'file_ref' => 'desktop-mode-recycle-bin', | |
| 444 | + ), | |
| 445 | + array( '%d', '%s', '%s' ) | |
| 446 | + ); | |
| 447 | +} | |
| 448 | + | |
| 449 | +/** | |
| 156 | 450 | * User meta marking someone as a Desktop Mode user from before the rebrand. |
| 157 | 451 | * |
| 158 | 452 | * Present and truthy => the shell offers this user the one-off rebrand |
| 159 | 453 | * announcement, once. Absent => they never used the plugin under its old |
| @@ -190,9 +484,9 @@ | ||
| 190 | 484 | array_merge( |
| 191 | 485 | get_users( |
| 192 | 486 | array( |
| 193 | 487 | 'fields' => 'ID', |
| 194 | - 'meta_key' => 'desktop_mode_mode', // phpcs:ignore WordPress.DB.SlowDBQuery.slow_db_query_meta_key -- runs once per install; the key is indexed in usermeta and both callers are guarded to a single pass. | |
| 488 | + 'meta_key' => 'desktop_mode_mode', // phpcs:ignore WordPress.DB.SlowDBQuery.slow_db_query_meta_key -- the key is indexed in usermeta; the migration callers run once per install, and the deactivation feedback route once per admin submission. | |
| 195 | 489 | 'meta_compare' => 'EXISTS', |
| 196 | 490 | ) |
| 197 | 491 | ), |
| 198 | 492 | get_users( |
| @@ -451,8 +745,33 @@ | ||
| 451 | 745 | wp_unschedule_hook( 'desktop_mode_ai_analyze_term' ); |
| 452 | 746 | } |
| 453 | 747 | |
| 454 | 748 | /** |
| 749 | + * Migration 8 — retire the "Score new comments with AI" feature. | |
| 750 | + * | |
| 751 | + * Automatic AI scoring of incoming comments was removed: nothing | |
| 752 | + * schedules `desktop_mode_ai_analyze_comment` any more, and the | |
| 753 | + * `desktop_mode_comments_ai_moderation` option no longer gates | |
| 754 | + * anything. Queued single-events would simply no-op, but we clear | |
| 755 | + * them so the cron array stays tidy and `wp cron event list` doesn't | |
| 756 | + * show an orphaned hook. | |
| 757 | + * | |
| 758 | + * The option row is dropped too — unlike a frozen identifier that | |
| 759 | + * still has a reader, this one has none left, so leaving it would | |
| 760 | + * only strand a value no code consults. | |
| 761 | + * | |
| 762 | + * Existing `_desktop_mode_ai_analysis` comment meta is left in place | |
| 763 | + * (hidden, harmless, and still what the on-demand | |
| 764 | + * `desktop-mode/analyze-comment` ability writes). | |
| 765 | + * | |
| 766 | + * @return void | |
| 767 | + */ | |
| 768 | +function openstation_migrate_remove_comments_ai() { | |
| 769 | + wp_unschedule_hook( 'desktop_mode_ai_analyze_comment' ); | |
| 770 | + delete_option( 'desktop_mode_comments_ai_moderation' ); | |
| 771 | +} | |
| 772 | + | |
| 773 | +/** | |
| 455 | 774 | * Migration 3 — delete self-managed AI credentials. |
| 456 | 775 | * |
| 457 | 776 | * WordPress 7.0 owns provider credentials (Settings → Connectors), so the |
| 458 | 777 | * copilot no longer stores keys of its own. Remove the platform key option and |
| @@ -498,4 +817,7 @@ | ||
| 498 | 817 | |
| 499 | 818 | openstation_save_os_settings( (int) $user_id, $raw ); |
| 500 | 819 | } |
| 501 | 820 | } |
| 821 | + | |
| 822 | +// Presence owns a verified checkpoint so failures never advance unrelated migrations. | |
| 823 | +add_action( 'admin_init', 'openstation_presence_migration_tick', 20 ); | |