feat(v3.12.0): media pipeline, AI image generation, capability probe, companion v2.9.0
Three-month batch sync from internal repo (~80 commits) covering Tracks F.5a, F.7e, F.8, F.17, F.18, F.X. WordPress media pipeline - Pillow-based optimization, AI image generation (OpenAI / Stability / Replicate / Google Nano Banana / OpenRouter), chunked + resumable uploads, bulk delete/reassign, idempotent retries. Capability discovery (F.7e) - Per-site credential probe + adapters for WordPress / WooCommerce / Gitea, tier-fit unions granted ∪ roles, capability badge UI with HTMX partial re-check, install hint in every companion-unreachable error. Companion plugin overhaul - Renamed wordpress-plugin/airano-mcp-seo-bridge → wordpress-plugin/airano-mcp-bridge. - Eight new endpoints: /capabilities, /bulk-meta, /export, /cache-purge, /transient-flush, /site-health, /audit-hook, /upload-and-attach. - wp.org Plugin Check pass: i18n, WP_Filesystem, scheme allowlist on audit-hook URL. Other - Gitea ergonomics (F.17): batch files, tree, search, compare, releases, fork. - Opportunistic bcrypt upgrade for legacy SHA-256 admin keys (F.8). - n8n refactor: structured errors, capability probe, missing tools backfilled. - Idempotency-Key dedup for AI media upload retries; WP client fast-fails on unreachable sites. Docs - README + CLAUDE.md drop the fixed "633 tools" claim. The total grows with each release; per-plugin approximations + dashboard-surfaced counts replace it. - Tools/Tests badges removed in favour of "Plugins: 10". Deployment - PyPI mirror chain, optional BUILD_HTTP_PROXY, Alpine→Yandex apk mirror, Debian-slim Plan-B Dockerfile, mirror.gcr.io variant. CI - Black + Ruff clean on Python 3.12; pytest tests/ green. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -178,6 +178,35 @@ class CredentialEncryption:
|
||||
json_str = self.decrypt(cipherdata, site_id)
|
||||
return json.loads(json_str)
|
||||
|
||||
def encrypt_for_scope(self, plaintext: str, scope: str) -> bytes:
|
||||
"""Encrypt a plaintext string using an arbitrary HKDF scope string.
|
||||
|
||||
Used when the encrypted value is not a per-site credentials blob but
|
||||
still needs per-key isolation (e.g. per-site AI provider API keys
|
||||
where scope is ``site_provider:{site_id}:{provider}``).
|
||||
|
||||
Args:
|
||||
plaintext: The string to encrypt.
|
||||
scope: Scope string used as HKDF info for key derivation. Any
|
||||
caller reading back the ciphertext must pass the same scope.
|
||||
|
||||
Returns:
|
||||
Encrypted bytes (same wire format as :meth:`encrypt`).
|
||||
"""
|
||||
return self.encrypt(plaintext, scope)
|
||||
|
||||
def decrypt_for_scope(self, cipherdata: bytes, scope: str) -> str:
|
||||
"""Decrypt cipherdata produced by :meth:`encrypt_for_scope`.
|
||||
|
||||
Args:
|
||||
cipherdata: Encrypted bytes.
|
||||
scope: Scope string — must exactly match what was used to encrypt.
|
||||
|
||||
Returns:
|
||||
Original plaintext string.
|
||||
"""
|
||||
return self.decrypt(cipherdata, scope)
|
||||
|
||||
|
||||
# Global credential encryption instance
|
||||
_credential_encryption: CredentialEncryption | None = None
|
||||
|
||||
Reference in New Issue
Block a user