Skip to the guide
All guides

Turn a finding into a fix

Understand the problem, agree on the fix and check that it works.

app WordPress DevKit 2.0.0checked reading 2 minutes

On this page

1. Confirm the original failing invariant

Read the cited source, the project instructions and the relevant engineering contract. Identify the actor, input, actual control flow and expected behavior. If the path or the contract is missing, keep the finding unverified instead of fixing a guess.

2. Authorize a bounded fix

A review never edits. Ask for the change explicitly and name its edges:

Text
Implement only the confirmed missing capability check in fixture_update (plugin.php:4-8).
Read this project's governing instructions first.
State the affected files, intended behavior and validation plan before editing.
Write the failing regression first: subscriber with a valid nonce must get 403 and the option must not change.
Preserve successful administrator writes and unrelated code.
Do not deploy or broaden the task.

3. Work at the source of the failure

  1. Inspect neighboring handlers and the project's established validation and error patterns.
  2. Restore the intended invariant at the failing boundary, not with a downstream filter, an invented fallback or a new architecture.
  3. Add a regression that reproduces the original failure and preserves legitimate operations.
  4. Run the project's own lint, static analysis, integration or browser checks. Record absent tools and failures.

4. What a good change looks like

Text
function fixture_update() {
    check_ajax_referer( 'fixture-settings', 'nonce' );
    if ( ! current_user_can( 'manage_options' ) ) {
        wp_send_json_error( array( 'message' => 'Forbidden' ), 403 );
    }
    $banner = isset( $_POST['banner'] ) && is_string( $_POST['banner'] )
        ? sanitize_text_field( wp_unslash( $_POST['banner'] ) )
        : '';
    update_option( 'fixture_banner', $banner );
    wp_send_json_success();
}

The nonce proves intent; the capability check supplies authority. The fix touches one handler and leaves the administrator path unchanged.

5. Make the result reviewable

Ask for the changed files, behavior before and after, the exact commands with exit codes, screenshots when the change is visual, and residual risks. A source diff supports a fix; verified runtime behavior needs the relevant execution.

Example acceptance

  • A user lacking the capability receives the established denied response and no write occurs.
  • An authorized administrator can still save a valid value.
  • Invalid input follows the existing validation contract.
  • No baseline, ignore rule or authorization control is weakened to pass checks.

Note

This guide describes fixing a target WordPress project. Deployment and publication are separate task boundaries and need their own authorization.