| @@ -479,10 +479,11 @@ | ||
| 479 | 479 | |
| 480 | 480 | $source = (string) $request['source']; |
| 481 | 481 | |
| 482 | 482 | // Per-agent gate. The route's `permission_callback` cannot run this |
| 483 | - // one: it has no access to the resolved agent, and the capability an | |
| 484 | - // agent requires is a property of that agent's trigger config. | |
| 483 | + // one: it has no access to the resolved agent, and the capabilities an | |
| 484 | + // agent requires are a property of that agent's trigger config. The | |
| 485 | + // gate applies all of them whatever `source` the request names. | |
| 485 | 486 | if ( ! openstation_agent_user_can_invoke_agent( (int) $user->ID, $source ) ) { |
| 486 | 487 | return new WP_Error( |
| 487 | 488 | 'openstation_agents_forbidden', |
| 488 | 489 | __( 'You do not have permission to invoke this agent.', 'desktop-mode' ), |
| @@ -614,9 +615,9 @@ | ||
| 614 | 615 | |
| 615 | 616 | return array( |
| 616 | 617 | 'id' => (int) $user->ID, |
| 617 | 618 | 'slug' => $slug, |
| 618 | - 'name' => (string) $user->display_name, | |
| 619 | + 'name' => openstation_plain_text_title( $user->display_name ), | |
| 619 | 620 | 'description' => openstation_agent_get_description( (int) $user->ID ), |
| 620 | 621 | 'instructions' => openstation_agent_get_instructions( (int) $user->ID ), |
| 621 | 622 | 'role' => $role, |
| 622 | 623 | 'abilities' => openstation_agent_get_abilities( (int) $user->ID ), |