تخطى إلى المحتوى
WordPress.org

العربية

  • القوالب
  • الإضافات
  • الأخبار
  • الدعم الفني
  • حول
    • كُتيب المساهمة
  • احصل على ووردبريس
احصل على ووردبريس
WordPress.org

Plugin Directory

Headless Login Guard

  • Submit a plugin
  • My favorites
  • Log in
  • Submit a plugin
  • My favorites
  • Log in

Headless Login Guard

بواسطة Andrew Wilkinson
تنزيل
  • تفاصيل
  • المراجعات
  • التنصيب
  • التطوير
الدعم

الوصف

A lightweight plugin that forces login for backend access in a headless WordPress setup. Keeps your WordPress dashboard private while allowing your front end (e.g. Astro, Next.js) to pull content via GraphQL/REST.

What it does

  • Requires authentication for /wp-admin/ and other backend pages
  • Always allows the login page to avoid redirect loops
  • Leaves key endpoints open for headless use:
    • /wp-json/ (REST API)
    • /graphql (WPGraphQL)
    • /wp-admin/admin-ajax.php (AJAX)
    • /wp-cron.php (cron)
    • /robots.txt
    • /sitemap*.xml (sitemaps and indexes)
    • /wp-content/uploads/* (media)
    • /favicon.ico
    • /newrelic (New Relic monitoring)
  • Logged-in users visiting the backend root get redirected to the dashboard
  • Works with Bedrock layouts (handles root path vs /wp/)

Use case

  • WordPress is the content backend
  • Public site is built with Astro/Next.js/etc
  • Editors log in to WordPress. Visitors never see the backend
  • Front end builds and live pages can still query GraphQL/REST without authentication

Customization

Developers can customize allowed endpoints using the force_login_allowed_patterns filter:

add_filter('force_login_allowed_patterns', function($patterns) {
    $patterns[] = '#^/healthz$#';           // custom health check
    $patterns[] = '#^/status$#';            // uptime checks
    $patterns[] = '#^/wp-json/acf/v3/.*#';  // specific REST namespace
    return $patterns;
});

التنصيب

  1. Upload the plugin files to the /wp-content/plugins/force-login directory, or install the plugin through the WordPress plugins screen directly.
  2. Activate the plugin through the ‘Plugins’ screen in WordPress.
  3. The plugin will automatically start protecting your backend – no configuration needed!

الأسئلة المتكررّة

I’m locked out! How do I access my site?

Visit /wp-login.php directly to sign in. The plugin always allows access to the login page.

My front-end requests are failing. What should I do?

Verify the endpoint is on the allow list. Check the plugin description for the default allowed patterns, or use the force_login_allowed_patterns filter to add custom endpoints.

Does this work with Bedrock?

Yes! The plugin correctly handles both standard WordPress installs and Bedrock layouts where the site URL and home URL may differ.

Can I add custom endpoints?

Yes, use the force_login_allowed_patterns filter to add your own regex patterns for additional endpoints that should remain public.

المراجعات

لا توجد مراجعات لهذه الإضافة.

المساهمون والمطوّرون

“Headless Login Guard” هو برنامج مفتوح المصدر. وقد ساهم هؤلاء الأشخاص بالأسفل في هذه الإضافة.

المساهمون
  • Andrew Wilkinson

ترجمة ”Headless Login Guard“ إلى لغتك.

مُهتم بالتطوير؟

تصفّح الشفرة، تحقق من مستودع SVN، أو الاشتراك في سجل التطوير بواسطة RSS.

سجل التغييرات

1.0.1

  • Added: New Relic monitoring endpoint allowlist pattern (/newrelic) to support APM monitoring
  • Added: WordPress.org plugin directory compatibility
  • Added: Proper plugin structure with activation/deactivation hooks
  • Added: Filter hook for customizing allowed patterns
  • Improved: Code organization and documentation

1.0.0

  • Initial release
  • Restricts backend (/wp-admin/) to authenticated users
  • Allows GraphQL and REST API endpoints for headless front-ends
  • Basic whitelist of essential endpoints (cron, ajax, robots.txt, sitemaps, uploads)

ميتا Meta

  • Version 1.0.1
  • Last updated قبل شهرين
  • Active installations أقل من 10
  • WordPress version 6.0 أو أعلى
  • Tested up to 6.9.5
  • PHP version 8.1 أو أعلى
  • Language
    English (US)
  • Tags
    GraphQLheadlessloginrest-apisecurity
  • عرض متقدم

التقييم

لم يتم تقديم أي مراجعات بعد.

Your review

See all reviews

المساهمون

  • Andrew Wilkinson

الدعم

لديك شيء لتقوله؟ بحاجة الى مساعدة؟

عرض منتدى الدعم

  • نبذة عن
  • أخبار
  • الاستضافة
  • الخصوصية
  • Showcase
  • قوالب
  • إضافات
  • الأنماط
  • تعلم
  • الدعم الفني
  • المطوّرون
  • WordPress.tv ↗
  • شارك بالمساهمة معنا
  • الفعاليات
  • Donate ↗
  • Five for the Future
  • WordPress.com ↗
  • Matt ↗
  • bbPress
  • BuddyPress
WordPress.org
WordPress.org

العربية

  • Visit our X (formerly Twitter) account
  • قم بزيارة حسابنا على بلوسكاي
  • Visit our Mastodon account
  • قم بزيارة حسابنا على ثريدز
  • قم بزيارة صفحتنا على الفيسبوك
  • Visit our Instagram account
  • Visit our LinkedIn account
  • قم بزيارة حسابنا على تيك توك
  • Visit our YouTube channel
  • قم بزيارة حسابنا على Tumblr
الكود شِعرٌ.
The WordPress® trademark is the intellectual property of the WordPress Foundation.