Skip to content

release: v3.1.0 — add 'authenticated' sentinel + rename Everyone → Public - #22

Merged
raftaar1191 merged 1 commit into
mainfrom
release/v3.1.0
Aug 8, 2026
Merged

raftaar1191 merged 1 commit into
mainfrom
release/v3.1.0

Conversation

@raftaar1191

Copy link
Copy Markdown
Contributor

Summary

  • Adds AccessControlManager::TYPE_AUTHENTICATED ('authenticated') sentinel — allows any logged-in user without a role/capability check.
  • Renames dropdown label Everyone (no restriction) → Public (no login required) for clarity, and adds a new Any logged-in user option below it.
  • Not breaking: 'everyone' behavior and stored rows are unchanged; new key is additive.

Changes

  • src/AccessControlManager.php — new TYPE_AUTHENTICATED constant; user_has_access() returns true iff \$user_id > 0 for this key, fires wpb_access_control_denied on the deny path.
  • src/Database/Rule/RuleQuery.php — set_rule() / normalize_input() handle 'authenticated' as a sentinel row alongside 'everyone'.
  • src/RestApi/RulesController.php — updated ac_key description.
  • js/components/ProviderDropdown.js — renamed label + new option; bundle rebuilt.
  • CHANGELOG.md — 3.1.0 entry.
  • README.md — updated dropdown table, access hierarchy, DB storage convention.

Test plan

  • All 147 PHPUnit tests still pass (verified locally).
  • Existing rules with access_control_key='everyone' continue to allow anonymous.
  • New rules with access_control_key='authenticated' allow logged-in, deny logged-out.
  • Admin dropdown shows the two renamed/new options above the providers.

🤖 Generated with Claude Code

… (v3.1.0)

Adds a second sentinel rule type so admins can require a login without
picking specific roles or users, and renames the public option so it is
unambiguous about anonymous access.

- AccessControlManager: new TYPE_AUTHENTICATED constant; user_has_access()
  returns true iff $user_id > 0 for this key, fires wpb_access_control_denied
  on the deny path.
- RuleQuery: set_rule() / normalize_input() handle 'authenticated' as a
  sentinel row alongside 'everyone'.
- RulesController: ac_key description mentions the new key.
- React dropdown: "Everyone (no restriction)" → "Public (no login required)";
  new "Any logged-in user" option added.
- CHANGELOG + README: document the new sentinel, updated dropdown table,
  and access hierarchy.
- Built assets rebuilt.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@raftaar1191
raftaar1191 merged commit 2e8f956 into main Aug 8, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant