| 开发者 | codeforbroke |
|---|---|
| 更新时间 | 2026年10月3日 03:09 |
| PHP版本: | 7.4 及以上 |
| WordPress版本: | 7.1 |
| 版权: | GPLv2 or later |
| 版权网址: | 版权信息 |
/wp-json/ are refused, so your content can't be read through the API. Login, contact form and oEmbed endpoints keep working.cfb_must_login_redirect_url
Send logged-out visitors somewhere other than the default login page.
add_filter( 'cfb_must_login_redirect_url', function ( $redirect_url, $redirect_to ) { return 'https://example.com/custom-login'; }, 10, 2 );
Filter: cfb_must_login_allowed_rest_routes
Keep additional REST API endpoints open while protection is on.
add_filter( 'cfb_must_login_allowed_rest_routes', function ( $routes ) { $routes[] = '/my-plugin/v1/public'; return $routes; } );
Action: cfb_must_login_clear_cache
Runs whenever the plugin clears caches. Hook in to clear a cache it doesn't know about.
add_action( 'cfb_must_login_clear_cache', function () { // Your custom cache clearing. } );
Capability: cfb_must_login_manage
Controls who can change the plugin's settings. It maps to manage_options by default; change it with the map_meta_cap filter.
They're sent to the login page. Once they log in, they're returned to the page they were trying to reach.
The login, registration and password reset pages, so people can actually sign in. A few other things stay reachable too:
Yes. While login is required, search engines can't crawl your site. That's what you want for a private site, but switch it off before you launch publicly.
WordPress exposes posts, pages and other data at /wp-json/. With protection on, logged-out requests to those endpoints are refused. It's on by default and can be turned off separately under Settings → CFB Must Login.
Even with protection on, these keep working:
cfb_must_login_allowed_rest_routes filter.
Yes. When you toggle the login requirement, CFB Must Login clears the cache for WP Super Cache, W3 Total Cache, WP Rocket, LiteSpeed Cache, WP Fastest Cache, Autoptimize, Cache Enabler, Comet Cache, SG Optimizer and WP-Optimize. If you use server-level or CDN caching, purge that too.
Not yet. Version 1.0 requires login for the entire site.
Yes. It simply makes sure people are logged in. Your membership plugin keeps handling who can see what.
Yes, with the cfb_must_login_redirect_url filter. See the developer documentation above.