PluginProbe
NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar / 3.3.3
NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar v3.3.3
3.3.3 3.3.2 3.3.1 3.3.0 3.2.14 3.2.13 3.2.12 3.2.11 3.2.10 3.2.9 3.2.8 3.2.7 trunk 0.2.5.5 0.2.5.6 0.2.5.7 1.0.0 1.0.1 1.0.2 1.0.3 1.1.0 1.1.1 1.1.2 1.1.3 1.1.4 All 158 releases
← All changes | includes/MCP/Server.php +7 -1 3.3.1 → 3.3.3 View file →
@@ -322,9 +322,15 @@
322 322 * @param \WP_REST_Response $resp Response.
323 323 * @return \WP_REST_Response
324 324 */
325 325 protected function with_challenge( $resp ) {
326 - $metadata_url = home_url( '/.well-known/oauth-protected-resource' );
326 + // Our own REST namespace, not `/.well-known/`: that path is shared by the
327 + // whole site, so a plugin hooking `parse_request` earlier than us -- or a
328 + // host that serves `/.well-known/` itself for ACME -- would hand our
329 + // clients another resource's metadata, and RFC 9728 requires an exact
330 + // match. This route is ours alone. The well-known paths keep working for
331 + // clients that construct them directly.
332 + $metadata_url = rest_url( 'notificationx/v1/mcp/oauth/protected-resource' );
327 333 $resp->header( 'WWW-Authenticate', sprintf( 'Bearer resource_metadata="%s"', $metadata_url ) );
328 334 return $resp;
329 335 }
330 336