Social Terminal 1.21.0 / Security
Terminal access and security
Configure guest, member, role, capability, and abuse-protection boundaries.
Review every enabled command before exposing the Terminal. Commands may be public, signed-in, role-restricted, capability-restricted, or administrator-only. Test a guest, normal member, denied role, and administrator.
Configure Cloudflare Turnstile in Security when required. For production, prefer COINTACTED_TURNSTILE_SITE_KEY, COINTACTED_TURNSTILE_SECRET_KEY, and COINTACTED_TURNSTILE_ENFORCE in wp-config.php. Enforcement accepts disabled, guests, or all.
The secret key must never enter public markup, terminal output, screenshots, logs, or support bundles. A visible terminal or stale browser control cannot bypass server permission checks.
Remote MCP execution requires a separate reviewed remote policy in addition to ordinary terminal access.
