| 1 |
<?php |
| 2 |
/** |
| 3 |
* `templately/auth-status` — report whether this site has a connected |
| 4 |
* Templately account for the acting user (spec 041-mcp-abilities, Auth Tools |
| 5 |
* addendum). |
| 6 |
* |
| 7 |
* Reads `Templately\Utils\Options` user meta directly for the explicitly |
| 8 |
* resolved acting user, rather than proxying `Templately\API\Login:: |
| 9 |
* is_signed()`. That route's own `permission_check()` requires an |
| 10 |
* *already-valid* api_key resolved through `Options`' internal singleton |
| 11 |
* user-id cache — which is captured once, early in plugin bootstrap, before |
| 12 |
* an MCP/REST request's Application-Password auth has resolved (see |
| 13 |
* MCP/CLAUDE.md's Options-singleton gotcha). That makes `is-signed` unusable |
| 14 |
* as a status check in this transport: the very thing being checked (a |
| 15 |
* valid key) is also what the route requires to answer at all. |
| 16 |
* |
| 17 |
* @package Templately\Modules\McpAbilities\Abilities |
| 18 |
*/ |
| 19 |
|
| 20 |
namespace Templately\Modules\McpAbilities\Abilities; |
| 21 |
|
| 22 |
use Templately\Modules\McpCore\Registry\ToolDescriptor; |
| 23 |
use Templately\Modules\McpCore\Support\Permissions; |
| 24 |
use Templately\Utils\Options; |
| 25 |
|
| 26 |
class AuthStatusAbility { |
| 27 |
|
| 28 |
const ID = 'templately/auth-status'; |
| 29 |
|
| 30 |
public static function descriptor(): array { |
| 31 |
return [ |
| 32 |
'id' => self::ID, |
| 33 |
'label' => __( 'Check Templately Auth Status', 'templately' ), |
| 34 |
'description' => __( 'Report whether this site has a connected Templately account for the acting user.', 'templately' ), |
| 35 |
'input_schema' => [ |
| 36 |
'type' => 'object', |
| 37 |
'properties' => (object) [], |
| 38 |
'additionalProperties' => false, |
| 39 |
], |
| 40 |
'output_schema' => [ |
| 41 |
'type' => 'object', |
| 42 |
], |
| 43 |
'execute_callback' => [ self::class, 'execute' ], |
| 44 |
'permission_callback' => [ Permissions::class, 'can_use_abilities' ], |
| 45 |
'access_level' => ToolDescriptor::ACCESS_READ, |
| 46 |
'annotations' => [ 'readonly' => true, 'destructive' => false, 'idempotent' => true ], |
| 47 |
]; |
| 48 |
} |
| 49 |
|
| 50 |
/** |
| 51 |
* @param array $input |
| 52 |
* @return array |
| 53 |
*/ |
| 54 |
public static function execute( array $input ): array { |
| 55 |
$user_id = get_current_user_id(); |
| 56 |
$options = Options::get_instance(); |
| 57 |
|
| 58 |
$api_key = $options->get( 'api_key', false, $user_id ); |
| 59 |
$user = $options->get( 'user', null, $user_id ); |
| 60 |
|
| 61 |
if ( empty( $api_key ) || empty( $user ) ) { |
| 62 |
return [ 'connected' => false, 'user' => null ]; |
| 63 |
} |
| 64 |
|
| 65 |
return [ |
| 66 |
'connected' => true, |
| 67 |
'user' => [ |
| 68 |
'id' => $user['id'] ?? null, |
| 69 |
'name' => $user['name'] ?? null, |
| 70 |
'email' => $user['email'] ?? null, |
| 71 |
'plan' => $user['plan'] ?? null, |
| 72 |
'is_verified' => $user['is_verified'] ?? false, |
| 73 |
'is_company_user' => $user['is_company_user'] ?? false, |
| 74 |
], |
| 75 |
]; |
| 76 |
} |
| 77 |
} |
| 78 |
|