Linux 软件免费装

Secufor OAuth

开发者 Secufor
secufor
更新时间 2026年8月20日 01:21
PHP版本: 7.4 及以上
WordPress版本: 7.0
版权: GPLv2 or later
版权网址: 版权信息

标签

authentication sso oauth single-sign-on openid-connect

下载

1.0.5 1.0.1 1.0.2 1.0.3 1.0.6 1.0.7 1.0.8 1.1.0 1.0.4

详情介绍:

Secufor OAuth adds Single Sign-On (SSO) to WordPress. Visitors sign in with an account they already have — Google, Microsoft, GitHub, Slack and others — instead of creating yet another password on your site. The plugin implements the OAuth 2.0 Authorization Code flow: the visitor is sent to the provider, the provider sends them back with a one-time code, and the plugin exchanges that code for the user's profile server-side. A matching WordPress account is created on first sign-in, or reused on subsequent ones. Features Included provider presets Google, Microsoft, Microsoft Entra ID, Facebook, Keycloak, Discord, GitHub, GitLab, LinkedIn, WordPress.com, Slack, Amazon, Twitch, Salesforce, AWS Cognito, Dropbox, Zoom, Spotify and Bitbucket. A generic OpenID Connect preset is also included, so any standards-compliant provider can be configured by entering its authorization, token and userinfo endpoints manually. Presets only pre-fill the endpoints and scopes. You still need to register an application with the provider and paste in your own Client ID and Client Secret. Providers that are not supported For transparency, these cannot work with the plugin's server-side Authorization Code flow and are deliberately not offered:

安装:

  1. Upload the plugin folder to /wp-content/plugins/, or install it from the Plugins screen.
  2. Activate the plugin.
  3. Go to Secufor Oauth → Create OAuth and pick a provider.
  4. Register an application with that provider and set its redirect URI to a URL on your site.
  5. Paste your Client ID and Client Secret into the plugin, and save.
  6. Copy the shortcode shown on the provider's configuration screen and place it on any page or post.

升级注意事项:

1.1.0 Security release. Fixes an unauthenticated endpoint that could disconnect your Secufor account (CVE-2026-7617), hardens the OAuth flow against login CSRF and account takeover, and repairs the sign-in flow, which did not complete in earlier versions. Upgrading is strongly recommended.

常见问题:

What should I use as the redirect URI?

Any URL on your site works, for example your home page. Enter exactly the same value in the plugin and in the provider's application settings — most providers reject the exchange if the two differ by even a trailing slash.

Why can't my administrator account sign in through a provider?

By default the plugin refuses to link an existing account that holds administrative privileges to an external provider based on its e-mail address alone, because a misconfigured or hostile provider could otherwise claim your administrator's address. Developers can allow it with the secuforoauth_allow_privileged_email_linking filter.

Can I change which provider field maps to which WordPress field?

Yes. Each provider has a "Configure Mappages" section: the key is the claim returned by the provider, the value is the target WordPress field. Editing the mapping is available in the premium version.

Does the plugin work with a page cache?

Yes. The sign-in button links to a static URL; the security token is generated when the visitor clicks it, not when the page is rendered.

更新日志:

1.1.0