跳至内容
WordPress.org

China 简体中文

  • 主题
  • 插件
  • 新闻
    • 文档
    • 论坛
  • 关于
  • 获取 WordPress
获取 WordPress
WordPress.org

Plugin Directory

Dorvis Auth

  • 提交插件
  • 我的收藏
  • 登录
  • 提交插件
  • 我的收藏
  • 登录

Dorvis Auth

作者:dorvis
下载
  • 详情
  • 评价
  • 安装
  • 开发进展
支持

描述

Dorvis Auth allows your WordPress users to log in using the Dorvis OIDC provider. It supports the Authorization Code Flow with PKCE for secure authentication.

Features:
* “Authenticate with Dorvis” button on the login form.
* Automatic account creation on first sign-in, or link-only mode where users attach a Dorvis identity to an account they already have.
* Maps First Name and Last Name from OIDC claims.
* Optionally rejects username and password sign-in once everyone has linked.
* Configurable Client ID, Secret, Issuer URI and Redirect URI via Settings.

Privacy

Dorvis Privacy and Cookie Policy

安装

  1. Upload the dorvis_auth folder to the /wp-content/plugins/ directory.
  2. Activate the plugin through the ‘Plugins’ menu in WordPress.
  3. Go to Settings > Dorvis Auth.
  4. Enter your Client ID and Client Secret.
  5. Set the Issuer URI and the Redirect URI (must match your Dorvis OIDC configuration).
  6. Save changes.

The Redirect URI path must be routed to WordPress, so the site needs a permalink structure other than Plain.

常见问题

Where do I get my Client ID?

You must contact Dorvis support or use the demo credentials provided in the documentation.

How do I move an existing site to Dorvis sign-in?

Turn off Create accounts automatically. Existing users sign in with their password, open their profile and click Link Dorvis identity. The Users list shows who has linked. Once everyone has, turn on Disable password sign-in.

Can I link accounts in bulk instead of asking everyone to click?

Turn on Match accounts by personal code, then set the dorvis_personal_code user meta field on each account to that person’s code, digits only with no dashes or spaces. Those users can sign in with Dorvis straight away. The Users list shows them as Pending until they first sign in, so a mistyped code is visible before anyone is locked out.

Accounts that were already linked before the setting was turned on keep working, and their personal code is filled in the next time they sign in.

dorvis_personal_code is the only user meta field meant to be written by hand. Setting `dorvis_sub` directly also links an account, but the plugin then treats it as one it created and overwrites its name and public URL slug from Dorvis on the next sign-in.

What if Dorvis is unreachable and password sign-in is disabled?

Define DORVIS_AUTH_ALLOW_PASSWORD_LOGIN as true in wp-config.php.

Does this work alongside a two-factor authentication plugin?

No. Signing in with Dorvis establishes the WordPress session directly, so plugins that add a second factor to the username and password form are not part of that path. The second factor is whatever the Dorvis identity provider asks for.

What claims are mapped?

given_name and family_name become the user’s name fields and display name, and the name also becomes the public URL slug. person_code is stored as the dorvis_personal_code user meta field; it is never used as the username.

This mapping is applied on every sign-in to accounts the plugin created. An account that already existed on the site when it was linked keeps the name and public URL slug the site gave it.

评价

此插件暂无评价。

贡献者及开发者

「Dorvis Auth」是开源软件。 以下人员对此插件做出了贡献。

贡献者
  • dorvis

帮助将「Dorvis Auth」翻译成简体中文。

对开发感兴趣吗?

您可以浏览代码,查看SVN仓库,或通过RSS订阅开发日志。

更新日志

0.3.0

  • Added link-only mode and a link/unlink control on the user profile screen. Unlinking your own identity requires a password sign-in, so it cannot lock you out; an administrator can unlink another account either way.
  • Added an option to reject password and application password sign-in, with a wp-config.php escape hatch.
  • Added a “Dorvis” column to the Users list.
  • Added an option to identify accounts by personal code, which allows linking them in bulk. Off by default; while it is off the personal code is neither stored nor matched on.
  • The ID token is validated and discarded rather than kept in user meta. Signing out clears the WordPress session, which is all there is to clear.
  • The personal_code user meta field written by 0.2.0 is renamed to dorvis_personal_code on upgrade, so it is read again and removed on uninstall rather than left behind.
  • Deleting the plugin now removes its settings, the user meta it wrote and its cached discovery data.

0.2.0

  • Account usernames and profile URL slugs are now derived from the OIDC subject and the name claims.
  • Discovery documents are cached per issuer, signing keys are cached and refreshed when validation fails, and token endpoint errors are surfaced to the user.
  • The Issuer URI must now use https.

0.1.0

  • Added PKCE, state and nonce protection to the authorization request.
  • Added callback handling with state verification.
  • Added ID token validation, discovery caching and logout.

0.0.2

  • Added settings page.
  • Improved user mapping logic.

0.0.1

  • Initial release.

额外信息

  • 版本 0.1.2
  • 最后更新:4 天前
  • 活跃安装数量 不到10
  • WordPress 版本 5.5 或更高版本
  • 已测试的最高版本为 7.1.2
  • PHP 版本 8.0 或更高版本
  • 语言
    English (US)
  • 标签
    authenticationloginoidcopenid connectsso
  • 高级视图

评级

尚未提交反馈。

您的评价

查看全部评论

贡献者

  • dorvis

支持

有话要说吗?是否需要帮助?

查看支持论坛

  • 关于
  • 新闻
  • 主机
  • 隐私
  • 陈列窗
  • 主题
  • 插件
  • 区块样板
  • 学习
  • 支持
  • 开发者
  • WordPress.tv ↗︎
  • 参与
  • 活动
  • 捐赠 ↗
  • 周边商品 ↗
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org
WordPress.org

China 简体中文

  • 关注我们的 X(原 Twitter)账号
  • 访问我们的 Bluesky 账号
  • 关注我们的 Mastodon 账号
  • 访问我们的 Threads 账号
  • 访问我们的 Facebook 公共主页
  • 关注我们的 Instagram 账号
  • 关注我们的 LinkedIn 主页
  • 访问我们的 TikTok 账号
  • 访问我们的 YouTube 频道
  • 访问我们的 Tumblr 账号
代码如诗
The WordPress® trademark is the intellectual property of the WordPress Foundation.