Skip to content

About

WordPress upload security and content firewall plugin (engineering preview). Privately inspect uploaded files with policy rules, ClamD malware scanning, DLP/QR checks, image and SVG reconstruction, human review, audit logs, privacy controls and optional third-party scanners. Not production-ready.

Topics

Resources

Stars

1 star

Watchers

0 watching

Forks

Repository files navigation

Content Firewall

An unreleased WordPress upload-governance implementation. Full production acceptance remains open; see release status and the complete requirements ledger.

The WordPress entry is content-firewall.php; helpers live in includes/, namespaced modules in src/, and administration assets in assets/css/ and assets/js/. See the file-structure review for the layout, corresponding build source and migration from the earlier entry filename.

Implemented: private upload interception, file/resource checks, policy rules and private real-file/synthetic/history simulations, authenticated headless uploads, classic/scheduled publication checks, seven remote adapters including audio transcription, ClamD, image/SVG reconstruction, bounded text and located image redaction, DLP/QR payload inspection, leased jobs, local crash recovery, human review and uploader appeals, assignment/team/deadlines, saved queue views, resumable Setup, per-class retention and privacy export/erasure, optional PDF/video/audio processing and offline Content Credentials, REST, admin UI, CLI, audit and diagnostics.

Build and test:

composer install
npm ci
composer test
composer lint
composer analyse
npm run typecheck
npm test
npm run build

The real WordPress test environment uses test-only credentials and localhost port 8887:

docker compose -p cf-test -f compose.test.yml up -d db wordpress
docker compose -p cf-test -f compose.test.yml exec wordpress sh -c 'chown www-data:www-data /var/cf-private && chmod 700 /var/cf-private'
docker compose -p cf-test -f compose.test.yml run --rm cli wp core install --url=http://localhost:8887 --title='Firewall Test' --admin_user=admin --admin_password=cf-local-test-password --admin_email=admin@example.test --skip-email
docker compose -p cf-test -f compose.test.yml run --rm cli wp plugin activate content-firewall
docker compose -p cf-test -f compose.test.yml exec -u www-data wordpress php /var/www/html/wp-content/plugins/content-firewall/tests/Integration/run.php
docker compose -p cf-test -f compose.test.yml exec -u www-data wordpress php /var/www/html/wp-content/plugins/content-firewall/tests/Integration/review.php
docker compose -p cf-test -f compose.test.yml exec -u www-data wordpress php /var/www/html/wp-content/plugins/content-firewall/tests/Integration/hardening.php
docker compose -p cf-test -f compose.test.yml exec -u www-data wordpress php /var/www/html/wp-content/plugins/content-firewall/tests/Integration/privacy.php
docker compose -p cf-test -f compose.test.yml exec -u www-data wordpress php /var/www/html/wp-content/plugins/content-firewall/tests/Integration/workflows.php
docker compose -p cf-test -f compose.test.yml exec -u www-data wordpress php /var/www/html/wp-content/plugins/content-firewall/tests/Integration/publication-crash.php
npx playwright install chromium
npm run test:e2e

Use CF_BROWSER_CHANNEL=chrome npm run test:e2e when Chrome is already installed. The commands above show the basic sequence; the complete testing guide includes every integration suite, native tools, concurrency, browser and multisite order. They assume a fresh fixture. compose.test.yml stores the database in tmpfs: stopping/recreating the DB destroys its contents while WordPress config/files and private volumes may remain. Reinitialize a consistent disposable fixture before another installation, especially after multisite conversion; never reset a real site. Keep the fixture running through sequential database-mutating suites. Stop containers with docker compose -p cf-test -f compose.test.yml down only after finishing acceptance.

Build and verify a deterministic ZIP using python3 tools/verify-release.py. The artifact includes corresponding TypeScript source, its build script and locked build configuration, and excludes installed development dependencies and tests; no third-party PHP runtime packages are required. Composer PSR-4 loading is available in development; the distribution's equivalent autoloader supports installation without Composer. Verify generated API documentation with python3 tools/openapi.py --check and guide links/schema/evidence paths with python3 tools/verify-docs.py.

Read the current 22-role production review and earlier code review.

Start with the installation guide, operator runbook, provider contracts, media processing, privacy/retention, threat model and developer API.

About

WordPress upload security and content firewall plugin (engineering preview). Privately inspect uploaded files with policy rules, ClamD malware scanning, DLP/QR checks, image and SVG reconstruction, human review, audit logs, privacy controls and optional third-party scanners. Not production-ready.

Topics

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages