-
Notifications
You must be signed in to change notification settings - Fork 1
Expand file tree
/
Copy pathreadme.txt
More file actions
75 lines (55 loc) · 3.29 KB
/
Copy pathreadme.txt
File metadata and controls
75 lines (55 loc) · 3.29 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
=== Pressable Basic Authentication ===
Contributors: pressable
Tags: pressable, basic auth, authentication, security
Requires at least: 6.7
Tested up to: 7.1
Requires PHP: 8.1
Stable tag: 1.0.5
License: GPLv2 or later
License URI: http://www.gnu.org/licenses/gpl-2.0.html
== Description ==
The Pressable Basic Authentication plugin enforces HTTP Basic Authentication across your WordPress site, requiring users to authenticate before accessing any page. This is particularly useful for development environments, ensuring that only authorized users can view or interact with the site during development or testing phases.
== FEATURES ==
* Enforces HTTP Basic Authentication on all front-end and back-end pages.
* Installed on sites to restrict public access.
* Allows super administrators to bypass authentication for seamless management.
* Integrates with WordPress's authentication system for user verification.
* Provides a mechanism to log out of Basic Authentication sessions.
== Frequently Asked Questions ==
= How do I use this plugin? =
No manual configuration is required. When accessing a protected site, you'll be prompted to enter your WordPress credentials.
= Can I disable Basic Authentication on my site? =
Basic Authentication is enforced on sites to protect your site during development. To remove this protection, you can promote your site to a live environment through the MyPressable Control Panel.
= What credentials should I use to authenticate? =
Use your WordPress username and password associated with the site. Ensure that your user account has the necessary permissions to access the site.
== Installation ==
No manual installation is necessary.
== Screenshots ==
* Initial release
== Changelog ==
= 1.0.5 =
* Fixed: Basic Authentication could be bypassed entirely on any URL, with no
credentials, by making a request to a gated page resemble one of the endpoints
excluded from authentication -- by naming one in the query string
(`/?x=wp-json/wp/v2`), by reaching the page through one
(`/xmlrpc.php/../wp-login.php`), or by trailing one after it
(`/wp-login.php/wp-json/wp/v2/`). All three served the login form and allowed a
full WordPress sign-in, as did a request target beginning `//`
(`//wp-login.php/wp-json/wp/v2/`). xmlrpc.php is now matched on the script the
server actually resolved, and a REST endpoint only when nothing preceding it in
the request path names a script the server would execute instead.
* Fixed: sending the `X-Requested-With: XMLHttpRequest` request header waived
Basic Authentication on any URL, a full sign-in included. That header is
caller-supplied, so it no longer counts as AJAX -- only WordPress's own
`DOING_AJAX` constant (set by admin-ajax.php) does.
* Fixed: logging out on a site also running User Switching caused a fatal error.
* Fixed: a logout request no longer reaches wp_logout() without valid credentials.
* Fixed: a logout URL without action=logout is no longer redirected away from the
logout while still signed in.
= 1.0.4 =
* Reverted the 1.0.3 changes pending verification. Functionally identical to 1.0.2.
= 1.0.3 =
* Deferred logout handling to init to avoid the User Switching conflict. Withdrawn
in 1.0.4; re-issued, with the exclusion fix above, in 1.0.5.
= 1.0.2 =
* PHP 8.4 compatibility.