Beam my site up, Scotty. Copy complete Local sites between machines with Site Beam [A LocalWP Addon].

You might have noticed a pattern in my recent posts. First you hear nothing from me for years, and now all of a sudden, 7 posts in short succession…

And if you checked the imagery, you already seen what’s coming next.

Yes, here it is. Addon number 7, the biggest, the boldest.

This is my farewell gift, and I’m not even going anywhere.

Two laptops, one desk, one site that needs to move from A to B. The official route; export the site on machine A, watch a progress bar, find the zip, AirDrop-or-USB-stick it over, drag it into Local on machine B, watch another progress bar and move on.

For a transfer between two machines that are LITERALLY ON THE SAME NETWORK, half a meter apart. Continue reading “Beam my site up, Scotty. Copy complete Local sites between machines with Site Beam [A LocalWP Addon].”

There is a port conflict with this site’s domain. Sorry, what? No there isn’t [A LocalWP Addon].

Every Local user has seen it. The dreaded banner; “There is a port conflict with this site’s domain”. And every Local user has done the dance;

  • Restart Local
  • Restart Local again…
  • Reboot computer.

Or if you are up for it;

  • Quit Local
  • Check for lingering LocalWP processes
  • Forget nginx, restart Local
  • And problem still there.

The Problem

Local routes all your .local domains through its own bundled nginx on ports 80/443. When that router can’t bind its ports, you get the banner — with a shrug of a message and a “Use localhost” surrender-option. The banner blames a “conflict”, but conveniently never tells you with what. Helpful! Continue reading “There is a port conflict with this site’s domain. Sorry, what? No there isn’t [A LocalWP Addon].”

LocalWP and composer-based WordPress is not a good match, but we can fix that [A LocalWP Addon].

If you run modern composer-based WordPress projects, like Bedrock, or a company template with public_html/wp, WordPress as a package, config from a .env , etc. etc.; then you know that Local and composer projects go together like… well, like they don’t. Not without forcing them.

Import such a site into Local and behold the carnage; WordPress version: unknown. The Database tab: “Unable to find DB_HOST”. The multisite domain Sync button: does nothing. “Open Site Shell”: lands you nowhere useful. One-click admin: nope. Everything that makes Local pleasant is broken, and Local doesn’t even have the decency to tell you why. Continue reading “LocalWP and composer-based WordPress is not a good match, but we can fix that [A LocalWP Addon].”

Set-up additional Apache modules in LocalWP – because sometimes, defaults aren’t good enough [A LocalWP Addon].

You know the drill; you add a couple of Header directives to your .htaccess (a cache-control here, an X-Frame-Options there) you reload the page, you check the response headers and… nothing. No error, no warning, no headers. Just… nothing.

Welcome to debugging something that isn’t broken. My favorite pastime! (It is not.) Continue reading “Set-up additional Apache modules in LocalWP – because sometimes, defaults aren’t good enough [A LocalWP Addon].”

Local’s SSL “Trust” button is BROKEN on macOS. Here’s why, and here’s the fix. [A LocalWP Addon].

Click Trust next to your site’s SSL certificate in Local. Enter your admin password like a good citizen. Watch it report success. Open https://mysite.local and… “Your connection is not private”. Click Trust again. Password again. Success again. Warning again.

Insanity, as the saying goes, is clicking the same button twice and expecting different results. Or something like that.

The Problem

On modern macOS, Local’s Trust button doesn’t work. Well it does, but not for you. It shows the password prompt, appears to succeed, and changes absolutely nothing; browsers keep screaming about your .local certificate forever. And because it looks like it worked, you naturally assume the problem is elsewhere; your browser cache, your cert, your karma. It isn’t. It’s the button. Continue reading “Local’s SSL “Trust” button is BROKEN on macOS. Here’s why, and here’s the fix. [A LocalWP Addon].”

Sequel Pro can’t connect to Local’s MySQL 8? MySQL Fixes AddOn to the rescue [A LocalWP Addon].

The Problem

Connect a classic client (for example Sequel Pro, older Sequel Ace, older JDBC tools) to a Local site running MySQL 8 and you’re greeted with authentication errors about caching_sha2_password.

(I talked about this already, here)

The classic clients speak mysql_native_password; MySQL 8 defaults to the new plugin, and on 8.4+ the old plugin isn’t just non-default, but (and in my opinion, this is a bug of omission) it ships disabled.

Meanwhile Local’s own connections work fine, so from Local’s point of view there is no bug. From MY point of view, sitting in front of a client that can’t connect to my own database; there very much is. Continue reading “Sequel Pro can’t connect to Local’s MySQL 8? MySQL Fixes AddOn to the rescue [A LocalWP Addon].”

This just in: Contact-Form-7 (WordPress) Vulnerability – 5 million websites at risk – CVE-2020-35489

A vulnerability has been discovered in Contact Form 7 that allows an attacker to upload malicious scripts. The publishers of Contact Form 7 have released an update to fix the vulnerability.

Unrestricted File Upload Vulnerability…

Noooo, I’m not going to steal/copy/plagiarize this article, just read the article on CVE 2020 35489 on searchenginejournal.com.

But I do have something to add. Continue reading “This just in: Contact-Form-7 (WordPress) Vulnerability – 5 million websites at risk – CVE-2020-35489”

Handy script: lbf

[Edit: This script is defunct since Local rebuilt the application and ditched the virtual machine. This script works only with the old “Local by Flywheel”  and not with the “Local Lightning” app. For the latter, see my lbl script]

Local (by Flywheel) is great, but for a terminal type of person as I am, I find it way more convenient to SSH into a VM and use the WP-CLI to perform WordPress tasks. With a platform like Vagrant, one has the

vagrant ssh
command to shell into the virtual environment.

With Local, you can do this with the push of a button in Local, but as said, I like the terminal better.

lbf ssh
is waaaaay faster than going to the Local app, find the site, click the SSH button.

But wait, there is much more ;) Continue reading “Handy script: lbf”

WordPress REST-API nonce-sense.

Working with the WordPress REST-API is HELL. There. I said it. It is powerful, it is secure, it is everything a developer needs, but for the love of [fill in your favorite deity here], WordPress, be consistent!

Using the REST-API requires authentication. Well, that’s not a problem. Just create a route to log-in and one to log-out. WordPress has functions to do that.

wp_signon()
and
wp_logout()

The first hurdle is getting the WordPress REST API to function. Oh, wait, you need a nonce ?! Well, thank you WordPress for this ‘security’-measure. For everything else in WordPress the authentication cookies you get when logging in to /wp-admin are enough, but for REST-API you need a nonce … the F why !?

Sorry, but this is just NONCE-SENSE! Pun intented. If only it were funny. Continue reading “WordPress REST-API nonce-sense.”

Google Tag Manager restart after AJaX page-reload

Quick Tip

So you have this very fast AJaX page loader (InstantClick) on your website, but you want to use Google Tag Manager and track your pageview with Analytics etc; here’s how you reset Tag Manager and re-load it after your AJaX page is loaded; Continue reading “Google Tag Manager restart after AJaX page-reload”

Confidental Infomation
stop spam mail