# CYBERMAPS release notes

Review current 7.3.4 changes and the preserved plugin release history.

The website documents **7.3.4**. The WordPress.org release is pending.

## 7.3.4

*   Fixed cross-site origin caching for `/ai-discovery` without changing its public URL.

## 7.3.3

*   Added an ownership-safe `/ai-discovery` fallback for origins with unpurgeable path caches.

## 7.3.2

*   Isolated APCu and shared object-cache entries across independent WordPress installations.

## 7.3.1

*   Fixed the Advanced Cloudflare eligibility control fatal and confirmation-row visibility.

## 7.3.0

*   Added opt-in, expiring redacted diagnostics/support bundles; renamed System Status to Debugging.

## 7.2.2

*   Disabled Cloudflare mutations when proxy traffic is not detected, with an exact-host, page-scoped manual confirmation for advanced deployments.

## 7.2.1

*   Fixed recoverable OAuth completion, canonical rule paths, and automatic browser-visible verification with per-resource diagnostics.
*   Added Cloudflare execution proof and complete OAuth metadata cache bypass.

## 7.2.0

*   Added public Cloudflare OAuth with PKCE, account consent, automatic combined rule installation, immediate token revocation, and no stored credential.
*   Added a bounded open-source callback relay, ambiguity-safe zone selection, OAuth lifecycle status, and a one-time-token fallback.
*   Added self-managed Cloudflare OAuth for organizations that want the callback, PKCE transaction, code exchange, and token revocation to remain on WordPress.

## 7.1.0

*   Added System Status with stack detection and explicit optimization-utilization evidence.
*   Added one-time-token Cloudflare header and cache-safety automation plus default-on LiteSpeed and APCu controls.
*   Unified edge diagnostics with the static publication header contract and added scoped Cybermaps-only cache invalidation.

## 7.0.1

*   Added ownership-safe `.well-known` fallbacks with explicit conformance status.
*   Unified OAuth metadata, bounded LLMS scans, and fixed duplicate-header diagnostics.

## 7.0.0

*   Raised the minimum to WordPress 7.1 and added a native public Ability kernel shared by MCP, WebMCP, API Catalog, OpenAPI, and ARD discovery.
*   Replaced nested well-known configuration with exact WordPress global rewrite rules, removed physical well-known defaults, and retained ownership-safe cleanup and public verification.

## 6.6.1

*   Added automatic ownership-safe `/.well-known/` routing for header-sensitive discovery endpoints on compatible Apache and LiteSpeed servers.
*   Added public GET/HEAD verification and explicit blocked-before-WordPress diagnostics without substituting wrong-MIME static files.

## 6.6.0

*   Added enriched per-API RFC 9727/RFC 9264 Linksets and a public REST health endpoint.
*   Added OAuth metadata, optional RFC 8628 device approval, and opt-in Auth.md without unsupported OIDC or fabricated JWKS claims.
*   Added the experimental current MCP Server Card, draft ARD AI Catalog, and opt-in read-only WebMCP with explicit maturity guidance.
*   Added server/cache/CDN rules and Configured, Advertised, Publicly verified, and canonical-interception diagnostics.

Earlier release history is included in `changelog.txt`.
