| 开发者 | diesismedia |
|---|---|
| 更新时间 | 2026年9月24日 18:58 |
| PHP版本: | 8.1 及以上 |
| WordPress版本: | 7.1 |
| 版权: | GPLv2 or later |
| 版权网址: | 版权信息 |
/wp-admin and /wp-login.php. It only helps if every request really passes through Cloudflare. Without Cloudflare Tunnel, anyone who knows the origin's address can reach WordPress directly and skip Access entirely.
DIESIS JWT Auth for Cloudflare Access closes that gap. For the paths you choose, WordPress itself checks the Cf-Access-Jwt-Assertion header that Cloudflare Access adds to authenticated requests. A request without a valid token is answered with HTTP 403 before WordPress does anything else.
What it does
cloudflareaccess.com URL. Incomplete or invalid settings disable enforcement instead of locking you out. If Cloudflare's key endpoint is temporarily unreachable, a previously cached key set keeps working.
Third-party service
To verify tokens the plugin downloads the public signing keys of your Cloudflare Access team from the issuer you configure, for example https://your-team.cloudflareaccess.com/cdn-cgi/access/certs. No site data is sent; the request is a plain download of public keys, repeated at most every 12 hours or after a key rotation. Cloudflare's terms and privacy policy apply to that endpoint: Terms, Privacy policy.
Source code, issues and support: github.com/DiesisMedia/diesis-jwt-auth
https://your-team.cloudflareaccess.com, and the application audience. Save with enforcement still disabled.https://your-team.cloudflareaccess.com, with no extra path./wordpress/, use:
/wordpress/wp-login.php
/wordpress/wp-admin
/wordpress/wp-admin/
Use the path prefix from your actual login and admin URLs, without the domain. Leaving Protected paths empty restores the default three paths; it does not disable protection.
Issuer and Application audience are specific to your Cloudflare setup and have no shared default. Leave Allowed emails and Excluded paths empty for the default setup. If you add an email allowlist, use your actual permitted addresses, one per line, matching your Access policy.Exclusions in this plugin only stop the origin check. Cloudflare Access decides on its own which paths it intercepts. Leave the path public in the Access application as well.
Any failed check ends in 403: no Cf-Access-Jwt-Assertion header, a token not signed with RS256, an invalid or expired signature, a wrong issuer or audience, a missing email claim, or an email that is not on the allowed list. With WP_DEBUG enabled the reason is written to the PHP error log.
Make sure you are opening the site through Cloudflare, not through the origin's own address, and that the Access application covers the same paths as the plugin. If you need to disable the plugin without admin access, rename or delete its folder under wp-content/plugins/ via SFTP or your host's file manager.
A cached key set stays valid for 12 hours and keeps working. Only if there are no cached keys at all and Cloudflare cannot be reached are protected requests denied.
No. Service tokens carry a common_name instead of an email and are always denied. Keep paths used by machines out of the protected paths.
Follow the review link: that ends it for your account for good. "Remind me later" brings the notice back after three months, after a year and after two years; the last reminder offers "Don't show this again" instead and ends it as well. The notice only ever appears on the Dashboard, the Plugins screen and the plugin's own settings page, and only once enforcement has been running for two weeks.
Yes. Settings are per site, and uninstalling cleans up every site of the network.
diesis-jwt-auth; the option and cached key names follow it.keys_unavailable./a/../wp-login.php can no longer dodge a protected path.true for the enforcement flag on programmatic option updates.