wordpress-workspace-preview-routing-debug

Debug WordPress Workspace Agent preview, edit-mode, authentication, proxy, and URL-routing behavior across simple WordPress.com, Jetpack, and Atomic sites. Use…

npx skills add https://github.com/automattic/workspace --skill wordpress-workspace-preview-routing-debug

WordPress Workspace Preview Routing Debug

Use this skill for preview/auth/editor-mode problems in the WordPress Agent window or detached preview.

Workflow

  1. Ground the report in the current code path.
    • Inspect Sources/WordPressAgentPreviewURLResolver.swift, Sources/WordPressAgentWindowView.swift, Sources/WPCOMClient.swift, and relevant Sources/AppState.swift preview methods.
    • Search with rg -n "preview|frame_nonce|jetpack_frame_nonce|unmapped|Atomic|cookie|requested|effective|private|proxy" Sources.
  2. Preserve the preview trust rules.
    • Show the requested user-facing URL in UI.
    • Do not expose effective preview URLs, frame nonces, auth bootstrap URLs, or private preview details.
    • Reject localhost and private-network URLs.
  3. Check site type and mode.
    • Simple WordPress.com, Jetpack, and Atomic sites can require different preview URL, unmapped-host, nonce, cookie, or read-access handling.
    • Distinguish signed-out view, authenticated preview, and editor mode.
  4. Check proxy and routing overrides.
    • Inspect Sources/NetworkRoutingSettings.swift and the WordPress.com auth-cookie bootstrap in Sources/WPCOMClient.swift.
    • The app has a developer setting to bypass the macOS system proxy for sandbox routing, but the preview cookie-bootstrap flow intentionally uses a one-off direct session because proxy routing has produced wp-login.php 200 responses with empty auth cookies.
    • Keep normal API traffic aligned with the user's network setting unless the code path is specifically browser-cookie infrastructure.
  5. Reproduce with focused signals.
    • Prefer app logs, existing preview loading states, and targeted code inspection before inventing shell-only repros.
    • Verify loading/preparation states, navigation updates, requested-vs-effective URL display, and mode switch behavior.
  6. Keep comments where behavior is non-obvious.
    • Proxy bypass, cookie bootstrap, nonce handling, and URL rewriting deserve concise code comments when changed.

Output

  • Lead with the failing route or trust boundary.
  • Include file references and the specific site/mode assumptions.
  • Recommend tests for public URL, same-site URL, preview URL, editor URL, internal navigation, and rejected private URL.

Mehr Skills von automattic

wp-phpstan
automattic
Verwenden beim Konfigurieren, Ausführen oder Beheben von PHPStan-Statikanalysen in WordPress-Projekten (Plugins/Themes/Websites): phpstan.neon-Setup, Baselines,…
official
wp-playground
automattic
Für WordPress Playground-Workflows: schnelle, wegwerfbare WP-Instanzen im Browser oder lokal über @wp-playground/cli (server, run-blueprint, build-snapshot),…
official
wp-plugin-development
automattic
Verwenden bei der Entwicklung von WordPress-Plugins: Architektur und Hooks, Aktivierung/Deaktivierung/Deinstallation, Admin-UI und Settings API, Datenspeicherung, Cron/Aufgaben, Sicherheit…
official
wp-project-triage
automattic
Verwenden Sie, wenn Sie eine deterministische Inspektion eines WordPress-Repositorys (Plugin/Theme/Block-Theme/WP-Core/Gutenberg/Full-Site) benötigen, einschließlich Tooling/Tests/Version…
official
wp-rest-api
automattic
Verwenden beim Erstellen, Erweitern oder Debuggen von WordPress-REST-API-Endpunkten/-Routen: register_rest_route, WP_REST_Controller/Controller-Klassen, Schema/Argumente…
official
wp-wpcli-and-ops
automattic
Verwenden bei der Arbeit mit WP-CLI (wp) für WordPress-Operationen: sicheres Suchen/Ersetzen, DB-Export/Import, Plugin/Theme/Benutzer/Inhaltsverwaltung, Cron, Cache leeren,…
official
wpds
automattic
Verwenden beim Erstellen von Benutzeroberflächen, die das WordPress Design System (WPDS) und dessen Komponenten, Tokens, Patterns usw. nutzen.
official
woocommerce-finalize
automattic
Vorab-Code-Gesundheits- und Rückverfolgbarkeitsaudit für WooCommerce-Plugins. Wird nach der Code-Überprüfung ausgeführt – konzentriert sich auf toten Code, Duplikate, strukturelle Komplexität und…
official