PluginProbe
xSpeed Cache: AI-Powered Performance Hub with MCP, Caching & CDN / 1.4.0
xSpeed Cache: AI-Powered Performance Hub with MCP, Caching & CDN v1.4.0
1.4.1 1.4.0 1.3.7 1.3.6 1.3.5 1.3.4 1.3.3 1.3.2 1.3.1 1.3.0 1.2.4 trunk 1.0.0 1.0.1 1.0.2 1.0.3 1.0.4 1.0.5 1.0.6 1.0.7 1.0.8 1.0.9 1.1.0 1.1.1 1.1.2 All 35 releases
← All changes | includes/class-rest-api.php +261 -9 1.1.1 → 1.4.0 View file →
@@ -77,10 +77,42 @@
77 77 'permission_callback' => array( $this, 'permissions' ),
78 78 )
79 79 );
80 80
81 + // Force a fresh static-rewrite probe. The result is otherwise cached
82 + // for five minutes with nothing to invalidate it, so a user who just
83 + // fixed their nginx config had no way to confirm it. (FBS-84012)
81 84 register_rest_route(
82 85 self::NAMESPACE_V1,
86 + '/cache/recheck-rewrite',
87 + array(
88 + 'methods' => 'POST',
89 + 'callback' => array( $this, 'recheck_rewrite' ),
90 + 'permission_callback' => array( $this, 'permissions' ),
91 + )
92 + );
93 +
94 + // The server-side mirror of "I pasted the block". Only meaningful on a
95 + // host where the probe cannot read the rules back — see
96 + // nginx_copied_hash().
97 + register_rest_route(
98 + self::NAMESPACE_V1,
99 + '/cache/nginx-copied-hash',
100 + array(
101 + 'methods' => 'POST',
102 + 'callback' => array( $this, 'nginx_copied_hash' ),
103 + 'permission_callback' => array( $this, 'permissions' ),
104 + 'args' => array(
105 + 'hash' => array(
106 + 'type' => 'string',
107 + 'required' => true,
108 + ),
109 + ),
110 + )
111 + );
112 +
113 + register_rest_route(
114 + self::NAMESPACE_V1,
83 115 '/cache/benchmark',
84 116 array(
85 117 'methods' => 'GET',
86 118 'callback' => array( $this, 'benchmark' ),
@@ -97,10 +129,63 @@
97 129 'permission_callback' => array( $this, 'permissions' ),
98 130 )
99 131 );
100 132
133 + // Drill-downs behind the four dashboard stat cards. Each is a plain
134 + // GET so the same data reaches the CLI and MCP through
135 + // `wp xspeed cache inventory|size|purge-log`.
101 136 register_rest_route(
102 137 self::NAMESPACE_V1,
138 + '/cache/inventory',
139 + array(
140 + 'methods' => 'GET',
141 + 'callback' => array( $this, 'cache_inventory' ),
142 + 'permission_callback' => array( $this, 'permissions' ),
143 + 'args' => array(
144 + 'limit' => array(
145 + 'type' => 'integer',
146 + 'default' => 50,
147 + ),
148 + 'offset' => array(
149 + 'type' => 'integer',
150 + 'default' => 0,
151 + ),
152 + 'fresh' => array(
153 + 'type' => 'boolean',
154 + 'default' => false,
155 + ),
156 + ),
157 + )
158 + );
159 +
160 + register_rest_route(
161 + self::NAMESPACE_V1,
162 + '/cache/size',
163 + array(
164 + 'methods' => 'GET',
165 + 'callback' => array( $this, 'cache_size' ),
166 + 'permission_callback' => array( $this, 'permissions' ),
167 + )
168 + );
169 +
170 + register_rest_route(
171 + self::NAMESPACE_V1,
172 + '/cache/purge-log',
173 + array(
174 + 'methods' => 'GET',
175 + 'callback' => array( $this, 'cache_purge_log' ),
176 + 'permission_callback' => array( $this, 'permissions' ),
177 + 'args' => array(
178 + 'limit' => array(
179 + 'type' => 'integer',
180 + 'default' => 25,
181 + ),
182 + ),
183 + )
184 + );
185 +
186 + register_rest_route(
187 + self::NAMESPACE_V1,
103 188 '/stats/hit-daily',
104 189 array(
105 190 'methods' => 'GET',
106 191 'callback' => array( $this, 'hit_daily' ),
@@ -114,8 +199,17 @@
114 199 array(
115 200 'methods' => 'GET',
116 201 'callback' => array( $this, 'recommendations' ),
117 202 'permission_callback' => array( $this, 'permissions' ),
203 + 'args' => array(
204 + // `contributed` adds the entries other plugins hand in
205 + // through `xspeed_recommendations`. Only the Overview
206 + // card asks for them; see all_with_contributed().
207 + 'include' => array(
208 + 'type' => 'string',
209 + 'enum' => array( '', 'contributed' ),
210 + ),
211 + ),
118 212 )
119 213 );
120 214
121 215 register_rest_route(
@@ -139,8 +233,18 @@
139 233 );
140 234
141 235 register_rest_route(
142 236 self::NAMESPACE_V1,
237 + '/activity',
238 + array(
239 + 'methods' => 'GET',
240 + 'callback' => array( $this, 'activity' ),
241 + 'permission_callback' => array( $this, 'permissions' ),
242 + )
243 + );
244 +
245 + register_rest_route(
246 + self::NAMESPACE_V1,
143 247 '/modules',
144 248 array(
145 249 'methods' => 'GET',
146 250 'callback' => array( $this, 'get_modules' ),
@@ -213,8 +317,20 @@
213 317 return rest_ensure_response( array( 'suggestions' => Pro_Audit::run() ) );
214 318 }
215 319
216 320 /**
321 + * Recent activity-log entries for the Overview activity strip —
322 + * newest-first (settings changes, purges, cache toggles, …).
323 + *
324 + * @param \WP_REST_Request $request Unused.
325 + * @return \WP_REST_Response
326 + */
327 + public function activity( $request ) {
328 + unset( $request );
329 + return rest_ensure_response( array( 'activity' => Activity_Log::entries() ) );
330 + }
331 +
332 + /**
217 333 * Cache before/after benchmark — fetches home_url() twice (with +
218 334 * without the bypass header) and returns side-by-side timings for
219 335 * the dashboard widget.
220 336 */
@@ -252,10 +368,12 @@
252 368 }
253 369
254 370 /** Ranked "next best action" recommendations (issue #48). */
255 371 public function recommendations( $request ) {
256 - unset( $request );
257 - return rest_ensure_response( array( 'recommendations' => Recommendations::all() ) );
372 + $recs = 'contributed' === (string) $request->get_param( 'include' )
373 + ? Recommendations::all_with_contributed()
374 + : Recommendations::all();
375 + return rest_ensure_response( array( 'recommendations' => $recs ) );
258 376 }
259 377
260 378 /** One-click apply of a recommendation's settings fix. */
261 379 public function recommendations_apply( $request ) {
@@ -311,12 +429,25 @@
311 429 if ( $opts['cache_enabled'] && $rewrite_capable ) {
312 430 $probe = Cache::probe_static_rewrite();
313 431 $rewrite_probe = array(
314 432 'active' => (bool) ( $probe['active'] ?? false ),
433 + // Both flags were previously dropped here, so the dashboard
434 + // could not tell "proven inactive" from "no result yet" or
435 + // "probe failed" — and rendered the configure-your-server
436 + // banner for all three. (FBS-84012)
437 + 'pending' => (bool) ( $probe['pending'] ?? false ),
438 + 'inconclusive' => (bool) ( $probe['inconclusive'] ?? false ),
439 + 'reason' => (string) ( $probe['reason'] ?? '' ),
315 440 'server_type' => $server_type,
316 441 'snippet' => Cache::nginx_snippet(),
317 442 'topology' => Server::rewrite_topology(),
318 443 'behind_proxy' => Server::is_behind_proxy(),
444 + // Whether the rules the web server is running are the rules
445 + // these settings generate — `current`, `stale`, `absent` or
446 + // `unknown`, with the hashes both sides compared. Nothing
447 + // else can answer that: the nginx block lives in a server
448 + // config WordPress cannot read. See Cache::rules_state().
449 + 'rules' => Cache::rules_state( $probe ),
319 450 );
320 451 }
321 452
322 453 return rest_ensure_response(
@@ -330,8 +461,13 @@
330 461 'nginx_snippet' => Gzip::nginx_snippet(),
331 462 ),
332 463 'rewrite_probe' => $rewrite_probe,
333 464 'nginx_server_block' => Cache::full_nginx_server_block(),
465 + // What enabling the page cache would do to
466 + // wp-content/advanced-cache.php. The dashboard discloses the
467 + // replacement BEFORE the write when a leftover drop-in is
468 + // already there; see Page_Cache_Detector::dropin_disclosure().
469 + 'dropin' => Page_Cache_Detector::dropin_disclosure(),
334 470 // Separate Mobile Cache visibility (FBS-83145). `blocking` is
335 471 // true when mobile_separate is what's keeping the device-blind
336 472 // static fast path from installing on a rewrite-capable server;
337 473 // `needs_review` is true when a migration turned it on for us and
@@ -338,9 +474,16 @@
338 474 // the user hasn't confirmed they actually need it. The dashboard
339 475 // renders a callout (+ "Check now" equality probe) from these.
340 476 'mobile_separate' => array(
341 477 'enabled' => ! empty( Settings::get()['cache_enabled'] ) ? (bool) ( Settings_Manager::get( 'cache' )['mobile_separate'] ?? false ) : false,
342 - 'blocking' => $rewrite_capable && 'mobile_separate' === Cache::static_rewrite_block_reason(),
478 + // Gated to servers that HAVE a static fast path — see the
479 + // matching comment in Admin::bootstrap_payload(): on IIS /
480 + // unknown, block_reason still falls through to
481 + // mobile_separate and reporting it as "blocking" would nag
482 + // about a rewrite that does not exist there (#108).
483 + // LiteSpeed joined the capable set with the opt-in (#509).
484 + 'blocking' => ( $rewrite_capable || Server::LITESPEED === $server_type )
485 + && 'mobile_separate' === Cache::static_rewrite_block_reason(),
343 486 'needs_review' => Cache::mobile_separate_needs_review(),
344 487 ),
345 488 )
346 489 );
@@ -364,13 +507,47 @@
364 507 return rest_ensure_response( $updated );
365 508 }
366 509
367 510 public function purge() {
368 - Cache::purge_all();
369 - return rest_ensure_response( array( 'stats' => Cache::get_stats() ) );
511 + // The same core function `wp xspeed purge` runs, so the dashboard
512 + // button and the CLI cannot clear different sets of stores — and the
513 + // per-store report is available here for the UI to surface a store
514 + // that was skipped or refused rather than flashing "cache cleared".
515 + $report = Purge_Runner::run( array( 'all' ), __( 'dashboard', 'xspeed' ) );
516 + return rest_ensure_response(
517 + array(
518 + 'stats' => Cache::get_stats(),
519 + 'report' => $report,
520 + )
521 + );
370 522 }
371 523
372 524 /**
525 + * The "Cached Pages" drill-down: which pages are cached and how old they
526 + * are. Paginated because a busy site's cache is thousands of entries and
527 + * the answer to "is my cache working" doesn't need all of them at once.
528 + */
529 + public function cache_inventory( \WP_REST_Request $request ) {
530 + return rest_ensure_response(
531 + Cache_Inventory::entries(
532 + (int) $request->get_param( 'limit' ),
533 + (int) $request->get_param( 'offset' ),
534 + (bool) $request->get_param( 'fresh' )
535 + )
536 + );
537 + }
538 +
539 + /** The "Cache Size" drill-down: where the bytes actually go. */
540 + public function cache_size() {
541 + return rest_ensure_response( Cache_Inventory::size_breakdown() );
542 + }
543 +
544 + /** The "Last Purge" drill-down: what cleared the cache, when, and why. */
545 + public function cache_purge_log( \WP_REST_Request $request ) {
546 + return rest_ensure_response( Cache_Inventory::purge_log( (int) $request->get_param( 'limit' ) ) );
547 + }
548 +
549 + /**
373 550 * Resolved branding ({name, footer_credit, hide_help_links, logo_svg}).
374 551 * Runs the `xspeed_branding` filter so Pro's white-label override is
375 552 * reflected. Consumed by the dashboard's post-save branding refresh.
376 553 */
@@ -377,8 +554,77 @@
377 554 public function get_branding() {
378 555 return rest_ensure_response( Admin::branding() );
379 556 }
380 557
558 + /**
559 + * Re-run the static-rewrite probe, bypassing the cached result.
560 + *
561 + * Returns the same shape the dashboard bootstrap uses, so the caller can
562 + * swap it straight into state without a second round trip. (FBS-84012)
563 + */
564 + public function recheck_rewrite() {
565 + $raw = Cache::recheck_static_rewrite();
566 + $server_type = Server::detect();
567 +
568 + // Qualify the raw probe against known config refusals. The probe
569 + // fetches its own file from the static tree, which succeeds even when
570 + // no real page is served that way — so an unqualified `active` told
571 + // clients the static path was engaged on sites where it demonstrably
572 + // wasn't. `block_reason` is exposed so a client can act on the
573 + // specific cause rather than re-deriving it. See
574 + // Cache::qualify_rewrite_probe().
575 + $probe = Cache::qualify_rewrite_probe( $raw );
576 +
577 + return rest_ensure_response(
578 + array(
579 + 'active' => $probe['active'],
580 + 'pending' => (bool) ( $raw['pending'] ?? false ),
581 + 'inconclusive' => $probe['inconclusive'],
582 + 'reason' => $probe['reason'],
583 + 'block_reason' => $probe['block_reason'],
584 + 'server_type' => $server_type,
585 + 'snippet' => Cache::nginx_snippet(),
586 + 'topology' => Server::rewrite_topology(),
587 + 'behind_proxy' => Server::is_behind_proxy(),
588 + // The whole reason to re-run the probe is usually that the
589 + // user just pasted the block, so this is where they most need
590 + // to be told whether the installed rules are the current ones.
591 + // It was only ever on /status before, which the CLI and MCP
592 + // recheck paths never call. See Cache::rules_state().
593 + 'rules' => $probe['rules'],
594 + )
595 + );
596 + }
597 +
598 + /**
599 + * Remember that this admin copied the current rules block.
600 + *
601 + * The mirror of the panel's own localStorage note, for the one case that
602 + * note cannot cover: a host where the probe returns `unknown` — blocked
603 + * loopback, or a CDN answering it — and a second admin, or the same admin
604 + * on another machine, is otherwise told to paste a block that is already
605 + * installed. Stored per user because it is a claim a person made.
606 + *
607 + * The hash is the rules marker, and a value that is not one is refused
608 + * rather than stored: the mirror is only useful while it holds something
609 + * rules_marker_expected() could also produce.
610 + */
611 + public function nginx_copied_hash( \WP_REST_Request $request ) {
612 + $params = (array) $request->get_json_params();
613 + $hash = isset( $params['hash'] ) ? (string) $params['hash'] : (string) $request->get_param( 'hash' );
614 +
615 + $stored = Cache::remember_rules_copied( $hash );
616 + if ( null === $stored ) {
617 + return new \WP_Error(
618 + 'xspeed_invalid_rules_hash',
619 + __( 'That is not a rules marker this site could have generated.', 'xspeed' ),
620 + array( 'status' => 400 )
621 + );
622 + }
623 +
624 + return rest_ensure_response( array( 'copied' => $stored ) );
625 + }
626 +
381 627 public function toggle_cache( \WP_REST_Request $request ) {
382 628 $params = $request->get_json_params();
383 629 $enabled = isset( $params['enabled'] ) ? (bool) $params['enabled'] : false;
384 630
@@ -386,9 +632,9 @@
386 632 // permission_callback above already enforced current_user_can(
387 633 // 'manage_options' ); the REST nonce is verified by core via the
388 634 // X-WP-Nonce header.
389 635 $state = Cache::toggle( $enabled );
390 - $updated = Settings::update( array( 'cache_enabled' => $state['enabled'] ) );
636 + $updated = Settings::get();
391 637
392 638 // Recompute the unified nginx block AFTER cache_enabled is persisted.
393 639 // Cache::toggle() computes it inline, but cache_enabled isn't written
394 640 // until the Settings::update() above — so the block inside $state
@@ -398,11 +644,17 @@
398 644 $state['nginx_server_block'] = Cache::full_nginx_server_block();
399 645
400 646 return rest_ensure_response(
401 647 array(
402 - 'enabled' => $updated['cache_enabled'],
403 - 'stats' => Cache::get_stats(),
404 - 'install_state' => $state,
648 + 'enabled' => $updated['cache_enabled'],
649 + // Surfaced at the top level so the dashboard can explain a
650 + // refusal rather than silently snapping the toggle back:
651 + // Cache::toggle() writes nothing when another plugin owns the
652 + // drop-in or WP_CACHE is in a shape we must not rewrite.
653 + 'blocked' => ! empty( $state['blocked'] ),
654 + 'blocked_reason' => $state['blocked_reason'] ?? null,
655 + 'stats' => Cache::get_stats(),
656 + 'install_state' => $state,
405 657 )
406 658 );
407 659 }
408 660 }