Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,10 @@
# Changelog

## 1.4.0

- feat(providers): add `BuddyBossProfileTypeProvider` — gate a resource by one or more BuddyBoss profile types (member types). Options are listed via `bp_get_member_types()` and curated via the `wpb_access_control_bb_profile_type_options` filter
- feat(AccessControl): the React UI's "Who can access" dropdown lists **BuddyBoss Profile Type** when the BuddyBoss Platform plugin is active; the entry is hidden automatically when BuddyBoss is inactive (existing `available` flag wired through `RulesController` and `ProviderDropdown`)

## 1.3.0

- feat(providers): add `WpCapabilityProvider` — gate a resource by one or more WordPress capability slugs; options are discovered dynamically across every role returned by `wp_roles()` and curated via the `wpb_access_control_wp_capability_options` filter
Expand Down
20 changes: 20 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -254,6 +254,7 @@ The component has four states driven by a single **"Who can access"** dropdown:
| **Everyone (no restriction)** | Nothing — all users can access |
| **WordPress Role** | Checkboxes for each WordPress role |
| **WordPress Capability** | Checkboxes for each WordPress capability (discovered across all roles) |
| **BuddyBoss Profile Type** | Checkboxes for each BuddyBoss profile type — hidden automatically when BuddyBoss Platform is inactive |
| **Users** | Search-as-you-type field + selected-user tags |

Custom providers registered via the filter also appear in the dropdown. If
Expand Down Expand Up @@ -719,6 +720,7 @@ correct controls dynamically without hard-coding provider IDs.
| `wp_role` | `WpRoleProvider` | Restricts by WordPress user role. Administrator is always bypassed. |
| `wp_user` | `WpUserProvider` | Restricts to specific WordPress users by ID. |
| `wp_capability` | `WpCapabilityProvider` | Restricts by one or more WordPress capability slugs. Users holding **any** of the selected capabilities pass. |
| `bb_profile_type` | `BuddyBossProfileTypeProvider` | Restricts by one or more BuddyBoss profile types (member types). Reports `available: false` when BuddyBoss Platform is not active — the React dropdown hides the option automatically. |

### `WpRoleProvider` filters

Expand Down Expand Up @@ -760,6 +762,24 @@ returns true for **any** selected capability.
| `wpb_access_control_wp_capability_options` | `(array $options): array` | Add or remove selectable capability options (e.g. to surface a custom cap that no role holds yet) |
| `wpb_access_control_wp_capability_has_access` | `(bool $result, int $user_id, array $selected): bool` | Override the final capability-based decision |

### `BuddyBossProfileTypeProvider`

Requires the [BuddyBoss Platform](https://www.buddyboss.com/platform/) plugin
to be active. When inactive the provider reports `is_available() === false`
and the React dropdown hides the option automatically; saved rules of type
`bb_profile_type` deny by default while BuddyBoss is missing.

Options are profile-type slugs (the same identifiers BuddyBoss exposes via
`bp_get_member_types()`). Both admin-created types (Profile Types CPT) and
code-registered types via `bp_register_member_type()` appear in the list.
Access is granted when the requesting user is assigned to **any** of the
selected profile types (via `bp_get_member_type()`).

| Filter | Signature | Description |
|--------|-----------|-------------|
| `wpb_access_control_bb_profile_type_options` | `(array $options): array` | Add or remove selectable profile-type options |
| `wpb_access_control_bb_profile_type_has_access` | `(bool $result, int $user_id, array $selected): bool` | Override the final profile-type-based decision |

---

## Important Notes
Expand Down
2 changes: 1 addition & 1 deletion assets/build/index.asset.php
Original file line number Diff line number Diff line change
@@ -1 +1 @@
<?php return array('dependencies' => array('react-jsx-runtime', 'wp-api-fetch', 'wp-element'), 'version' => 'a5bfff25a721fa37903f');
<?php return array('dependencies' => array('react-jsx-runtime', 'wp-api-fetch', 'wp-element'), 'version' => 'db414737ada472bc3fef');
2 changes: 1 addition & 1 deletion assets/build/index.js

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 2 additions & 0 deletions js/components/RoleOptionsPanel.js
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,8 @@ const PROVIDER_DESCRIPTIONS = {
'Select which WordPress Role values may access this resource. Leave all unchecked to deny everyone (except administrators).',
wp_capability:
'Select which WordPress capabilities grant access. Users holding any of the checked capabilities are allowed. Administrators always have access.',
bb_profile_type:
'Select which BuddyBoss profile types grant access. Users assigned to any of the checked profile types are allowed. Administrators always have access.',
};

/**
Expand Down
1 change: 1 addition & 0 deletions src/AccessControlManager.php
Original file line number Diff line number Diff line change
Expand Up @@ -107,6 +107,7 @@ public function load_providers(): void {
new WpRoleProvider(),
new WpUserProvider(),
new WpCapabilityProvider(),
new BuddyBossProfileTypeProvider(),
);

/**
Expand Down
Loading
Loading