Skip to content

Reserved WebDecoy-Test User-Agent always records a test detection - #80

Merged
cport1 merged 1 commit into
mainfrom
feat/test-trigger
Aug 18, 2026
Merged

Reserved WebDecoy-Test User-Agent always records a test detection#80
cport1 merged 1 commit into
mainfrom
feat/test-trigger

Conversation

@cport1

@cport1 cport1 commented Aug 18, 2026

Copy link
Copy Markdown
Contributor

Companion to WebDecoy/app#698 (part of WebDecoy/app#677).

curl -A "WebDecoy-Test/1.0" https://your-site.example/ now always records a detection:

  • Logged locally on every install (visible on the plugin's Detections page), submitted to the cloud on connected installs
  • Answered with a 403 JSON receipt so the curl output itself shows the plugin acted
  • Checked before the allowlist (a developer testing from an allowlisted IP still gets their receipt), before the block check, and before rules: a test must always fire and must never trip enforcement
  • Skips the critical-moment alert queue (a test must not page anyone)
  • The cloud labels these rows as tests and keeps them out of stats and billing

All 94 tests pass; phpcs 0 errors. Ships with the next release via bin/release-all.sh (not releasing here).

curl -A "WebDecoy-Test/1.0" https://your-site.example/ now always
produces a detection (WebDecoy/app#677): logged locally on every
install, submitted to the cloud on connected ones, and answered with a
403 JSON receipt so the curl output itself shows the plugin acted.

Checked before the allowlist (a developer testing from an allowlisted
IP still gets their receipt), before the block check, and before rules:
a test must always fire and must never trip enforcement or the
critical-moment alert. The cloud labels these rows as tests and keeps
them out of stats and billing.
@cport1
cport1 merged commit 75bbc03 into main Aug 18, 2026
3 checks passed
@cport1
cport1 deleted the feat/test-trigger branch August 18, 2026 17:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant