Add open student registration with email confirmation and approval
CI / Tests (PHP 8.1) (pull_request) Successful in 1m18s
CI / Tests (PHP 8.2) (pull_request) Successful in 1m18s
CI / No Debug Code (pull_request) Successful in 2s
CI / PHPStan (pull_request) Successful in 3m20s
CI / Coding Standards (pull_request) Successful in 3m25s
CI / Tests (PHP 8.3) (pull_request) Successful in 2m33s
CI / Build Plugin Zip (pull_request) Skipped
CI / Tests (PHP 8.1) (pull_request) Successful in 1m18s
CI / Tests (PHP 8.2) (pull_request) Successful in 1m18s
CI / No Debug Code (pull_request) Successful in 2s
CI / PHPStan (pull_request) Successful in 3m20s
CI / Coding Standards (pull_request) Successful in 3m25s
CI / Tests (PHP 8.3) (pull_request) Successful in 2m33s
CI / Build Plugin Zip (pull_request) Skipped
Students could previously join by invite only. Add an optional self-approval mode, toggled from Studio Settings → Registration: anyone may sign up on the existing [us_student_register] page, confirm their email via a tokenised link, and then be approved by a studio admin before the account is usable. - Enabling the toggle mirrors WordPress's own membership settings (users_can_register + default_role = us_student) and snapshots their previous values so disabling restores them. - WordPress's native registration form is blocked while open registration is on (login_init redirect + registration_errors fail-safe + register_url) so it cannot bypass signup policy acceptance. - Pending accounts: unconfirmed email cannot log in; confirmed but unapproved can log in but the booking capability is withheld and the booking page shows an "awaiting approval" screen. - Approve/reject from Students → Pending Students; reject hard-deletes the account so the email is freed to re-apply. - Invite registration is unchanged; both modes coexist. Account lifecycle lives in user meta (RegistrationStatus); no new tables. Closes #63 Co-Authored-By: Claude Opus 4.8 <[email protected]>
This commit is contained in:
@@ -0,0 +1,128 @@
|
||||
<?php
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace Unsupervised\Schedular\Auth;
|
||||
|
||||
use Unsupervised\Schedular\Payment\StudioSettings;
|
||||
use Unsupervised\Schedular\Val;
|
||||
|
||||
/**
|
||||
* Handles the self-signup email-confirmation link, and keeps WordPress's own
|
||||
* registration form from being used to bypass the studio's policy-accepting
|
||||
* registration page while open registration is enabled.
|
||||
*/
|
||||
class EmailConfirmationHandler {
|
||||
|
||||
public function __construct(
|
||||
private StudioSettings $settings,
|
||||
private RegistrationMailer $mailer,
|
||||
) {}
|
||||
|
||||
public function register(): void {
|
||||
add_action( 'template_redirect', [ $this, 'maybeConfirm' ] );
|
||||
add_filter( 'register_url', [ $this, 'registerUrl' ] );
|
||||
// login_init fires at the top of wp-login.php for every request (GET form
|
||||
// display AND a direct POST) before any registration processing, so it is
|
||||
// the reliable choke point; registration_errors is a fail-safe in case a
|
||||
// POST ever reaches register_new_user().
|
||||
add_action( 'login_init', [ $this, 'blockNativeRegistration' ] );
|
||||
add_filter( 'registration_errors', [ $this, 'blockRegistrationErrors' ], 10, 1 );
|
||||
}
|
||||
|
||||
/**
|
||||
* Confirm a self-signup's email when the emailed `?us_confirm=<token>` link
|
||||
* is opened, then redirect back to the registration page with a result flag.
|
||||
*/
|
||||
public function maybeConfirm(): void {
|
||||
if ( is_admin() ) {
|
||||
return;
|
||||
}
|
||||
|
||||
// phpcs:ignore WordPress.Security.NonceVerification.Recommended -- the token is itself the capability-bearing secret (like a password-reset key); nonces do not apply to an emailed link.
|
||||
$rawToken = sanitize_text_field( Val::string( wp_unslash( $_GET['us_confirm'] ?? '' ) ) );
|
||||
if ( '' === $rawToken ) {
|
||||
return;
|
||||
}
|
||||
|
||||
$base = $this->registrationPageUrl();
|
||||
$userId = RegistrationStatus::userIdForToken( $rawToken );
|
||||
|
||||
if ( null === $userId || RegistrationStatus::isTokenExpired( $userId, gmdate( 'Y-m-d H:i:s' ) ) ) {
|
||||
wp_safe_redirect( add_query_arg( 'us_confirmed', 'expired', $base ) );
|
||||
exit;
|
||||
}
|
||||
|
||||
RegistrationStatus::confirmEmail( $userId );
|
||||
|
||||
$user = get_user_by( 'id', $userId );
|
||||
if ( $user instanceof \WP_User ) {
|
||||
$this->mailer->notifyAdminsPending( $user );
|
||||
}
|
||||
|
||||
wp_safe_redirect( add_query_arg( 'us_confirmed', '1', $base ) );
|
||||
exit;
|
||||
}
|
||||
|
||||
/**
|
||||
* Point WordPress's own "Register" links at the studio registration page
|
||||
* while open registration is on and a page is configured.
|
||||
*/
|
||||
public function registerUrl( string $url ): string {
|
||||
if ( ! $this->settings->openRegistrationEnabled() ) {
|
||||
return $url;
|
||||
}
|
||||
|
||||
$pageId = Val::int( get_option( RegistrationController::OPTION_PAGE, 0 ) );
|
||||
|
||||
return $pageId > 0 ? (string) get_permalink( $pageId ) : $url;
|
||||
}
|
||||
|
||||
/**
|
||||
* Redirect any `wp-login.php?action=register` request (GET or POST) to the
|
||||
* studio registration page, so the bare native form — which cannot collect
|
||||
* required policy acceptances — is never used.
|
||||
*/
|
||||
public function blockNativeRegistration(): void {
|
||||
if ( ! $this->settings->openRegistrationEnabled() ) {
|
||||
return;
|
||||
}
|
||||
|
||||
// phpcs:ignore WordPress.Security.NonceVerification.Recommended -- read-only routing decision; no state is changed here.
|
||||
$action = sanitize_key( Val::string( wp_unslash( $_REQUEST['action'] ?? '' ) ) );
|
||||
if ( 'register' !== $action ) {
|
||||
return;
|
||||
}
|
||||
|
||||
$pageId = Val::int( get_option( RegistrationController::OPTION_PAGE, 0 ) );
|
||||
if ( $pageId <= 0 ) {
|
||||
return;
|
||||
}
|
||||
|
||||
wp_safe_redirect( (string) get_permalink( $pageId ) );
|
||||
exit;
|
||||
}
|
||||
|
||||
/**
|
||||
* Fail-safe: reject any native registration attempt while open registration
|
||||
* is on, so `register_new_user()` can never create a policy-less account.
|
||||
*
|
||||
* @param \WP_Error $errors Accumulated registration errors.
|
||||
* @return \WP_Error
|
||||
*/
|
||||
public function blockRegistrationErrors( \WP_Error $errors ): \WP_Error {
|
||||
if ( $this->settings->openRegistrationEnabled() ) {
|
||||
$errors->add(
|
||||
'us_registration_redirect',
|
||||
esc_html__( 'Please register on the studio registration page.', 'unsupervised-schedular' )
|
||||
);
|
||||
}
|
||||
|
||||
return $errors;
|
||||
}
|
||||
|
||||
private function registrationPageUrl(): string {
|
||||
$pageId = Val::int( get_option( RegistrationController::OPTION_PAGE, 0 ) );
|
||||
|
||||
return $pageId > 0 ? (string) get_permalink( $pageId ) : home_url( '/' );
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user