| 开发者 |
Secufor
secufor |
|---|---|
| 更新时间 | 2026年8月20日 01:21 |
| PHP版本: | 7.4 及以上 |
| WordPress版本: | 7.0 |
| 版权: | GPLv2 or later |
| 版权网址: | 版权信息 |
state parameter (CSRF protection)id_token rather than from a userinfo endpoint./wp-content/plugins/, or install it from the Plugins screen.Any URL on your site works, for example your home page. Enter exactly the same value in the plugin and in the provider's application settings — most providers reject the exchange if the two differ by even a trailing slash.
By default the plugin refuses to link an existing account that holds administrative privileges to an external provider based on its e-mail address alone, because a misconfigured or hostile provider could otherwise claim your administrator's address. Developers can allow it with the secuforoauth_allow_privileged_email_linking filter.
Yes. Each provider has a "Configure Mappages" section: the key is the claim returned by the provider, the value is the target WordPress field. Editing the mapping is available in the premium version.
Yes. The sign-in button links to a static URL; the security token is generated when the visitor clicks it, not when the page is rendered.
secuforoauth_unregister_action AJAX endpoint was reachable by unauthenticated visitors and could disconnect the site from its Secufor account. It now requires the manage_options capability and a valid nonce, and is no longer registered for logged-out users (CVE-2026-7617).state parameter is now generated per click, stored single-use, and bound to the visitor's browser with a cookie, preventing login CSRF.