• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

bleedingdeacons / promises / 31978348760
88%

Build:
DEFAULT BRANCH: main
Ran 16 Aug 2026 11:10PM UTC
Jobs 1
Files 28
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

16 Aug 2026 11:09PM UTC coverage: 88.097% (+0.06%) from 88.041%
31978348760

push

github

web-flow
fix(http): correct the Allow header on /mcp to POST only (#3)

The live endpoint answered `Allow: POST, GET` on its 405, telling a
client doing method discovery that GET was available and then refusing
it. WordPress builds that header itself, in rest_send_allow_header(),
from every method registered against the matched route — and it does so
on rest_post_dispatch, after the callback has returned, so the
`Allow: POST` set while building the response never survived.

Corrected on the same filter at priority 20, after WordPress's own. GET
stays registered: MCP says a server without the notification stream
should answer 405, and dropping the route would make WordPress answer
404, which reads as "wrong URL" and sends someone off checking their
configuration.

Only /mcp is touched; /health is a genuine GET and keeps `Allow: GET`.

The old test could not have caught this. It called streamNotSupported()
directly and asserted on the header it had just set, never reaching the
point where WordPress rebuilds it. The new tests drive the filter itself,
including the pass-through for a non-response value.

One trap worth recording, because the first attempt at this fix looked
broken for a reason that had nothing to do with the fix: the guard
originally named WP_HTTP_Response, which is correct in production —
WP_REST_Response extends it — but bleedingdeacons/wp-mocks declares
WP_REST_Response standalone. So the guard passed live and silently
returned early under test. It now names WP_REST_Response, which every
route here returns anyway, including rejected ones.

Verified on the Local site: GET /mcp -> 405 Allow: POST, GET /health ->
200 Allow: GET, POST /mcp -> 200.

Gates: PHPUnit 109 tests / 403 assertions, PHPStan level 8, PHPCS green.

1125 of 1277 relevant lines covered (88.1%)

5.35 hits per line

Jobs
ID Job ID Ran Files Coverage
1 31978348760.1 16 Aug 2026 11:10PM UTC 28
88.1
GitHub Action Run
Source Files on build 31978348760
  • Tree
  • List 28
  • Changed 1
  • Source Changed 0
  • Coverage Changed 1
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #31978348760
  • b7d9da26 on github
  • Prev Build on main (#31973842694)
  • Next Build on main (#32053444589)
  • Delete
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc