Skip to content

Commit 323b657

Browse files
Tsvetan StoychevTsvetan Stoychev
authored andcommitted
Set first release version to 0.0.8
1 parent 230c1d3 commit 323b657

24 files changed

Lines changed: 59 additions & 540 deletions

‎.agents/skills/change-basicrum-settings/SKILL.md‎

Lines changed: 9 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
---
22
name: change-basicrum-settings
3-
description: Change Basicrum WordPress settings across defaults, admin UI, validation, migrations, and runtime gates. Use for Beacon URL, Brum Site ID, monitoring enablement, HTTP Strictness, Script Position, or any basicrum_settings option.
3+
description: Change Basicrum WordPress settings across defaults, admin UI, validation, future migrations, and runtime gates. Use for Beacon URL, Brum Site ID, monitoring enablement, HTTP Strictness, Script Position, or any basicrum_settings option.
44
---
55

66
# Change Basicrum Settings
@@ -13,15 +13,18 @@ runtime use, upgrades, tests, documentation, and translations.
1313
1. Inspect `plugins/basicrum/src/Helpers.php` for keys and defaults.
1414
2. Inspect `Admin/Settings/Page.php` and `Validate.php` for rendering,
1515
sanitization, validation, and error messages.
16-
3. Inspect `Admin/Upgrades.php` before changing an existing stored value.
16+
3. After the first public release, inspect the migration service before changing
17+
an existing stored value. Do not add migration machinery for unreleased
18+
development schemas.
1719
4. Find every runtime consumer and existing test with `rg`.
1820
5. Define behavior for new installs, existing installs, enabled monitoring, and
1921
disabled monitoring before editing.
2022

2123
## Implement the complete behavior
2224

2325
- Keep the `basicrum_settings` schema synchronized across defaults, UI,
24-
validation, migrations, runtime code, tests, docs, and translations.
26+
validation, runtime code, tests, docs, translations, and any post-release
27+
migrations.
2528
- Make server-side validation authoritative. Client-side disabled states and
2629
invalid-field styling are usability aids, not security controls.
2730
- Require a valid Beacon URL and Brum Site ID when monitoring is enabled. Keep
@@ -35,8 +38,9 @@ runtime use, upgrades, tests, documentation, and translations.
3538
invalid icon with the field it describes and render it only while invalid.
3639
- Sanitize by data type, escape for the final output context, and preserve
3740
capability and nonce protections already supplied by the settings flow.
38-
- Add a version-gated migration when stored data must change. Make migrations
39-
idempotent.
41+
- Once a public version exists, add a version-gated migration when stored data
42+
must change. Make migrations idempotent. Before the first public release,
43+
keep one clean schema without compatibility aliases.
4044

4145
If user-facing text changes, also apply `$update-basicrum-copy`.
4246

‎AGENTS.md‎

Lines changed: 8 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -19,16 +19,17 @@ namespace, PSR-4 Composer autoloading, PHP 7.4+, and WordPress 6.0+.
1919
- Settings use the `basicrum_settings` option. Keep defaults, UI, and
2020
sanitization in sync in `Helpers`, `Admin\Settings\Page`, and
2121
`Admin\Settings\Validate`.
22-
- Add version-gated migrations to `Admin\Upgrades`; use the option/version
23-
constants from `Helpers`.
22+
- Version `0.0.8` is the first public release and has no upgrade migrations.
23+
After it is published, use version-gated, idempotent migrations only when a
24+
stored schema change requires one.
2425

2526
## Project Skills
2627

2728
Repository-owned workflows live in `.agents/skills/`. Claude discovers the
2829
same canonical files through links in `.claude/skills/`.
2930

30-
- `change-basicrum-settings` - options, validation, dependencies, migrations,
31-
and runtime gates.
31+
- `change-basicrum-settings` - options, validation, dependencies, future
32+
migrations, and runtime gates.
3233
- `update-basicrum-copy` - naming, administrator copy, branding, and gettext
3334
catalogs.
3435
- `integrate-basicrum-consent` - external consent adapters, callback contracts,
@@ -63,9 +64,9 @@ in the matching skill.
6364
displays those exact files as escaped copyable text, and automatic handling
6465
may enqueue exactly one after the consent loader. Prefer WP Consent API; when
6566
it is unavailable, select a direct adapter only if exactly one supported
66-
provider is detected. Ambiguous combinations fail closed. Existing sites
67-
without the integration setting remain manual; new installations default to
68-
automatic. Browser tests must execute the same packaged files.
67+
provider is detected. Ambiguous combinations fail closed. Automatic handling
68+
is the first-release default; manual callbacks remain an explicit choice.
69+
Browser tests must execute the same packaged files.
6970
- Keep automatic and manual administrator guidance visually separate. Automatic
7071
handling shows a compact verdict, provider evidence, one next action, and
7172
copyable non-secret diagnostics. Reveal the callback contract, provider tabs,

‎README.md‎

Lines changed: 3 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -84,11 +84,8 @@ evidence for all three supported providers, one next action, and copyable
8484
non-secret diagnostics. A blocked result can reveal the matching manual setup
8585
without silently saving the mode change.
8686

87-
Sites upgraded from a version without the connection setting remain on **Manual
88-
callbacks** to avoid running a second adapter beside an existing webmaster
89-
snippet. Manual handling loads no adapter automatically. The webmaster must
90-
load one adapter after the Basicrum consent loader and call one callback on
91-
every page.
87+
Manual handling loads no adapter automatically. The webmaster must load one
88+
adapter after the Basicrum consent loader and call one callback on every page.
9289

9390
Basicrum does not persist a separate consent choice across page loads; the
9491
external tool is authoritative on every page. If consent is withdrawn after
@@ -246,7 +243,7 @@ security advisories. CI runs all three checks on every push and pull request.
246243
It also verifies that the plugin header version, `BASICRUM_VERSION`, WordPress
247244
`Stable tag`, and top changelog version match. Release workflows additionally
248245
compare the GitHub release tag to that version. Release tags must use the
249-
`v<version>` form, such as `v1.0.2`. To check a planned release locally, run
246+
`v<version>` form, such as `v0.0.8`. To check a planned release locally, run
250247
`BASICRUM_RELEASE_TAG=v<version> make conventions`.
251248

252249
Dependabot checks npm, Composer dependencies, and GitHub Actions weekly. CI

‎checklist.md‎

Lines changed: 4 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -24,16 +24,15 @@ Acceptance criteria:
2424
- [x] Decide whether each mode has distinct runtime behavior.
2525
- [x] Implement the defined behavior, or remove modes that do not represent real
2626
behavior and keep a single consent-enabled switch.
27-
- [x] Keep defaults, settings UI, validation, migrations, documentation, and
28-
translations synchronized.
27+
- [x] Keep defaults, settings UI, validation, runtime behavior, documentation,
28+
and translations synchronized.
2929
- [x] Add PHP tests for every supported setting and loader selection path.
3030

3131
Decision:
3232

3333
- Immediate loading and consent-controlled loading are the only observable
34-
policies. The retired `explicit`, `implicit`, and `cookie_popup` values all
35-
selected the same loader and have been removed without changing existing
36-
sites' consent gate.
34+
policies. The unused `explicit`, `implicit`, and `cookie_popup` development
35+
values were removed before the first public release.
3736
- Basicrum supplies an integration gate, not a consent popup, legal-basis
3837
decision, or compliance guarantee.
3938
- In consent-controlled loading, the site's external consent tool is the source

‎docs/audits/checklist.md‎

Lines changed: 4 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -61,10 +61,9 @@ operator-journey defect, P3 = minor/polish.
6161
browser coverage, and release ZIP required-file checks.
6262
- [x] P2 Replace the proposed "persistent consent warning" with contextual
6363
detection and privacy-safe automatic handling in `render_consent_info()` -
64-
never a site-wide notice. New installations default to automatic handling;
65-
existing installations without the setting remain manual. WP Consent API
66-
takes priority, exactly one direct Borlabs Cookie or CookieYes provider may
67-
be selected, and ambiguous or missing providers fail closed. The settings
64+
never a site-wide notice. Automatic handling is the first-release default.
65+
WP Consent API takes priority, exactly one direct Borlabs Cookie or CookieYes
66+
provider may be selected, and ambiguous or missing providers fail closed. The settings
6867
page shows an Active, Action needed, Off, or Blocked verdict with provider
6968
evidence, one next action, and copyable non-secret diagnostics. Only manual
7069
handling reveals the callback contract and matching packaged adapter tabs;
@@ -123,7 +122,7 @@ operator-journey defect, P3 = minor/polish.
123122
category, stale caches). (UX 3 / BR-DOC-08, BR-DOC-09, walkthrough-06)
124123
- [ ] P2 Lifecycle docs: purge caches after disabling/deactivating (cached
125124
pages keep the loader; browser-cached HTML cannot be purged at all);
126-
what deactivation keeps vs uninstall removes; migration notes; multisite
125+
what deactivation keeps vs uninstall removes; multisite
127126
guidance. (UX 8 / BR-DOC-13, BR-DOC-17, BR-DOC-18, BR-DOC-20)
128127
- [ ] P2 wp.org listing: add the four screenshots or drop the section;
129128
fix Installation step order; add a Support section; align page-type

‎docs/audits/operator-experience-audit.md‎

Lines changed: 1 addition & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
# Basicrum WordPress Operator Experience Audit (2026-07-18)
22

3-
Webmaster operating-comfort audit of `plugins/basicrum/` at version 1.0.2:
3+
Webmaster operating-comfort audit of `plugins/basicrum/` at version 0.0.8:
44
how comfortable, clear, and safe the plugin is for a WordPress-competent
55
non-developer to install, configure, verify, operate, and maintain. Method:
66
four tracers (settings UX and copy, live wp-admin walkthrough on the real
@@ -144,8 +144,6 @@ settings screen. (issue-backoffice-unlinked, walkthrough-05, BR-DOC-16)
144144
(documentation side of privacy audit item 3). (BR-DOC-13)
145145
- [ ] State what deactivation keeps (settings) and uninstall removes.
146146
(BR-DOC-17)
147-
- [ ] Surface a notice after silent upgrade migrations (e.g. legacy installs
148-
kept on immediate loading). (BR-DOC-18)
149147
- [ ] Add multisite guidance; network activation leaves every subsite
150148
unconfigured. (BR-DOC-20)
151149

@@ -204,7 +202,6 @@ settings screen. (issue-backoffice-unlinked, walkthrough-05, BR-DOC-16)
204202
admin sidebar" matches reality). (BR-DOC-01)
205203
- [x] A corrupt install aborts with an actionable notice instead of a white
206204
screen. (BR-DOC-03)
207-
- [x] Upgrade Notice sections truthfully describe migration behavior.
208205
(BR-DOC-04)
209206
- [x] The Privacy Policy Guide contribution reflects the live configuration.
210207
(BR-DOC-05)

‎docs/audits/privacy-audit.md‎

Lines changed: 7 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
# Basicrum WordPress Privacy Audit (2026-07-18)
22

33
Evidence-based privacy engineering and compliance-readiness audit of
4-
`plugins/basicrum/` at version 1.0.2, including the uncommitted privacy-first
4+
`plugins/basicrum/` at version 0.0.8, including the uncommitted privacy-first
55
header and readme edits. Method: four parallel code tracers over data flow,
66
cookies/consent, WordPress integration, and disclosures; every claimed defect
77
adversarially verified by three independent refuters (majority rule); full test
@@ -114,9 +114,8 @@ documentation, though excluded from the release ZIP.
114114
## 8. Clean up multisite uninstall residue (BR-WP-14)
115115

116116
`uninstall.php` deletes options only on the site where uninstall runs. On
117-
multisite networks, `basicrum_settings` and `basicrum_version` rows persist on
118-
other subsites. Low severity: the residue is operator configuration, not
119-
visitor personal data.
117+
multisite networks, `basicrum_settings` rows persist on other subsites. Low
118+
severity: the residue is operator configuration, not visitor personal data.
120119

121120
- [ ] Iterate `get_sites()` with `switch_to_blog()`/`restore_current_blog()`
122121
on multisite, or document the limitation in `readme.txt`.
@@ -156,9 +155,9 @@ visitor personal data.
156155
- [x] Opt-in is idempotent; opt-out disables collection and removes RT/BA at
157156
the host and all parent domains, runtime-verified (COOKIE-04, COOKIE-06,
158157
DF-04).
159-
- [x] Validation fails closed: invalid consent input selects consent mode;
160-
retired `consent_mode` cannot be re-saved; migrations never flip consent
161-
posture or silently enable monitoring (BR-WP-09, BR-WP-10).
158+
- [x] Validation fails closed: invalid consent input selects manual callbacks;
159+
no pre-release compatibility path can flip consent posture or silently enable
160+
monitoring (BR-WP-09, BR-WP-10).
162161
- [x] HTTPS enforced: `http://` beacon URLs upgrade unless development mode is
163162
explicitly on and warned; the bundle also defaults `beacon_url_force_https`.
164163
Tracer claim BR-WP-06 (protocol-relative bypass) was overturned in
@@ -228,7 +227,7 @@ visitor personal data.
228227
`examples/integrations/README.md` rides on generic WP Consent API evidence;
229228
verify or soften it.
230229
- [ ] Run the release packaging verification so the new privacy copy provably
231-
lands in the 1.0.2 ZIP before shipping.
230+
lands in the 0.0.8 ZIP before shipping.
232231

233232
## 14. Primary sources (accessed 2026-07-18)
234233

‎plugins/basicrum/README.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
Plugin Name: Basicrum WordPress Plugin
33
Plugin URI: https://www.basicrum.com/
44
Description: Open source Real User Monitoring for WordPress.
5-
Version: 1.0.2
5+
Version: 0.0.8
66
Author: Tsvetan Stoychev
77
Author URI: https://www.basicrum.com/contact/
88
License: MIT

‎plugins/basicrum/basicrum.php‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@
33
* Plugin Name: Basicrum - Real User Monitoring
44
* Plugin URI: https://www.basicrum.com/
55
* Description: Privacy-first Real User Monitoring with consent-controlled loading, page types, and Web Vitals.
6-
* Version: 1.0.2
6+
* Version: 0.0.8
77
* Author: Tsvetan Stoychev
88
* Author URI: https://www.basicrum.com/contact/
99
* License: MIT
@@ -19,7 +19,7 @@
1919
}
2020

2121
// Plugin constants.
22-
define( 'BASICRUM_VERSION', '1.0.2' );
22+
define( 'BASICRUM_VERSION', '0.0.8' );
2323
define( 'BASICRUM_PLUGIN_FILE', __FILE__ );
2424
define( 'BASICRUM_PLUGIN_DIR', plugin_dir_path( __FILE__ ) );
2525

‎plugins/basicrum/languages/basicrum.pot‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
# This file is distributed under the MIT.
33
msgid ""
44
msgstr ""
5-
"Project-Id-Version: Basicrum - Real User Monitoring 1.0.2\n"
5+
"Project-Id-Version: Basicrum - Real User Monitoring 0.0.8\n"
66
"Report-Msgid-Bugs-To: https://wordpress.org/support/plugin/basicrum\n"
77
"Last-Translator: FULL NAME <EMAIL@ADDRESS>\n"
88
"Language-Team: LANGUAGE <LL@li.org>\n"

0 commit comments

Comments
 (0)