Add open student registration with email confirmation and approval
CI / Tests (PHP 8.1) (pull_request) Successful in 1m18s
CI / Tests (PHP 8.2) (pull_request) Successful in 1m18s
CI / No Debug Code (pull_request) Successful in 2s
CI / PHPStan (pull_request) Successful in 3m20s
CI / Coding Standards (pull_request) Successful in 3m25s
CI / Tests (PHP 8.3) (pull_request) Successful in 2m33s
CI / Build Plugin Zip (pull_request) Skipped

Students could previously join by invite only. Add an optional
self-approval mode, toggled from Studio Settings → Registration: anyone
may sign up on the existing [us_student_register] page, confirm their
email via a tokenised link, and then be approved by a studio admin
before the account is usable.

- Enabling the toggle mirrors WordPress's own membership settings
  (users_can_register + default_role = us_student) and snapshots their
  previous values so disabling restores them.
- WordPress's native registration form is blocked while open
  registration is on (login_init redirect + registration_errors
  fail-safe + register_url) so it cannot bypass signup policy acceptance.
- Pending accounts: unconfirmed email cannot log in; confirmed but
  unapproved can log in but the booking capability is withheld and the
  booking page shows an "awaiting approval" screen.
- Approve/reject from Students → Pending Students; reject hard-deletes
  the account so the email is freed to re-apply.
- Invite registration is unchanged; both modes coexist.

Account lifecycle lives in user meta (RegistrationStatus); no new tables.

Closes #63

Co-Authored-By: Claude Opus 4.8 <[email protected]>
This commit is contained in:
2026-07-18 10:50:21 -03:00
co-authored by Claude Opus 4.8
parent e7d8257973
commit 7370755951
23 changed files with 1713 additions and 88 deletions
+113
View File
@@ -0,0 +1,113 @@
<?php
declare(strict_types=1);
namespace Unsupervised\Schedular\Auth;
use Unsupervised\Schedular\Val;
/**
* Transactional emails for the self-approval registration flow: the email
* confirmation link, the studio-admin heads-up that someone is ready to
* approve, and the approval / rejection notices to the student.
*/
class RegistrationMailer {
/**
* Email the new student a link to confirm their address. Returns false when
* there is no recipient.
*/
public function sendConfirmation( \WP_User $user, string $confirmUrl ): bool {
if ( '' === (string) $user->user_email ) {
return false;
}
$subject = sprintf(
/* translators: %s: site name */
__( 'Confirm your email for %s', 'unsupervised-schedular' ),
$this->siteName()
);
$body = sprintf(
/* translators: 1: site name, 2: confirmation URL */
__( "Thanks for signing up at %1\$s.\n\nPlease confirm your email address by opening this link:\n%2\$s\n\nOnce confirmed, a studio admin will review and approve your account. You'll get another email when it's ready.", 'unsupervised-schedular' ),
$this->siteName(),
$confirmUrl
);
return (bool) wp_mail( $user->user_email, $subject, $body );
}
/**
* Tell the studio admins a self-signup has confirmed their email and is
* waiting for approval. Sent to the site admin email.
*/
public function notifyAdminsPending( \WP_User $user ): bool {
$adminEmail = Val::string( get_option( 'admin_email', '' ) );
if ( '' === $adminEmail ) {
return false;
}
$subject = __( 'A new student is awaiting approval', 'unsupervised-schedular' );
$body = sprintf(
/* translators: 1: student name, 2: student email */
__( "%1\$s (%2\$s) has confirmed their email and is awaiting approval.\n\nReview them under Students → Pending Students in wp-admin.", 'unsupervised-schedular' ),
(string) $user->display_name,
(string) $user->user_email
);
return (bool) wp_mail( $adminEmail, $subject, $body );
}
/**
* Tell the student their account has been approved. Returns false when there
* is no recipient.
*/
public function sendApproved( \WP_User $user ): bool {
if ( '' === (string) $user->user_email ) {
return false;
}
$subject = sprintf(
/* translators: %s: site name */
__( 'Your %s account is approved', 'unsupervised-schedular' ),
$this->siteName()
);
$body = sprintf(
/* translators: 1: site name, 2: login URL */
__( "Good news — your account at %1\$s has been approved. You can now log in and book:\n%2\$s", 'unsupervised-schedular' ),
$this->siteName(),
wp_login_url()
);
return (bool) wp_mail( $user->user_email, $subject, $body );
}
/**
* Tell an applicant their registration was declined. Takes the email address
* directly, since the account is deleted as part of rejection.
*/
public function sendRejected( string $email ): bool {
if ( '' === $email ) {
return false;
}
$subject = sprintf(
/* translators: %s: site name */
__( 'Your %s registration', 'unsupervised-schedular' ),
$this->siteName()
);
$body = sprintf(
/* translators: %s: site name */
__( 'Thank you for your interest in %s. We are unable to approve your registration at this time. Please contact the studio if you have any questions.', 'unsupervised-schedular' ),
$this->siteName()
);
return (bool) wp_mail( $email, $subject, $body );
}
private function siteName(): string {
$name = (string) get_bloginfo( 'name' );
return '' !== $name ? $name : __( 'the studio', 'unsupervised-schedular' );
}
}