| 开发者 | dreamfox |
|---|---|
| 更新时间 | 2026年9月29日 21:28 |
| PHP版本: | 8.1 及以上 |
| WordPress版本: | 7.1 |
| 版权: | GPLv2 or later |
| 版权网址: | 版权信息 |
wp_insert_post_data guard.map_meta_cap pins Client Editors to their assigned protected pages; everything else (including deleting and creating posts) is denied._elementor_data writes are validated the same way as everywhere else./wp-content/plugins/dreamfox-client-edit-mode, or install through the WordPress plugins screen.No. The editor UI is locked for the role, but every save is additionally validated on the server against the stored page. Even a hand-crafted REST API request with a Client Editor's credentials cannot add, remove, move or restyle elements — the whole save is rejected with a 403 and a list of violations.
Only what you allow per page, in three categories: text (headings, paragraphs, button labels …), images (replace an image, its alt text or caption) and links (URLs and link targets). Layout, styling, element structure and everything else is always locked. You can override the three categories per user.
The save is rejected as a whole — no partial merge — and the editor shows a clear message explaining what was not allowed. The attempt is recorded in the activity log.
Yes. Client Editors can open the Elementor editor on their assigned pages, and every save (plus direct _elementor_data writes) is validated against the same text/image/link rules as the block editor.
As many as you like — there is no limit.
Yes, twice over: every allowed save creates a regular WordPress revision (so you can compare and restore), and the activity log records who changed what, when, linked to that revision — plus every blocked attempt.
Blocks get a persistent internal ID when a page is protected. Blocks added afterwards do not have one yet and are read-only for Client Editors until you press Re-sync IDs on the Protected Pages screen.
dreamfox_client_edit_permissions — filter the permission set used for a protected page.dreamfox_client_edit_can_modify — filter a single per-element/attribute permission decision (structural changes never reach this filter; they are always denied).dreamfox_client_edit_allowed_attributes — classify attributes of custom blocks/widgets into the text / image / link / layout / style / advanced categories.dfce_protected_post_types — post types guarded by the block editor save guard (default: page, post).dfce_save_blocked (action) — fires whenever an enforcement path blocks a save.Not by default. Enable "Delete all plugin data when the plugin is uninstalled" under Client Edit → Settings → Advanced first if you want a clean removal. The Client Editor role itself is always removed on uninstall.