Add M365 Login plugin: Microsoft Entra ID sign-in for existing users

Adds a WordPress plugin that places a customisable "Sign in with
Microsoft" button on wp-login.php and signs existing users in via the
OpenID Connect authorization code flow with PKCE. Users are matched by
e-mail address only; no accounts are created.

Security: single-use state/nonce bound to an HttpOnly cookie, ID token
signature verification against Microsoft's JWKS (RS256 only) with
issuer/audience/tenant/expiry/nonce checks, optional tenant pinning,
account binding to the Microsoft object ID, e-mail domain allow-list,
client secret encrypted at rest (AES-256-GCM).

Admin: settings screen with connection, button and security tabs, live
button preview, colour presets, media-library icon picker, redirect URI
copy button and tenant connectivity test.

Packaging for WordPress.org: readme.txt with External services section,
GPL-2.0 license, uninstall.php, POT + German translations, .distignore,
build script, PHPCS config and CI running Plugin Check.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JJxAHYdMfKPoN4koRc4Ci2
This commit is contained in:
friloo 2026-09-22 14:21:10 +00:00
commit 3e3e87b399
No known key found for this signature in database
35 changed files with 5413 additions and 0 deletions

189
assets/js/admin.js Normal file
View file

@ -0,0 +1,189 @@
/* global jQuery, wp, m365LoginAdmin */
( function ( $ ) {
'use strict';
var cfg = window.m365LoginAdmin || {};
var i18n = cfg.i18n || {};
$( function () {
var $preview = $( '#m365-preview' );
/* ---------------- Tabs ---------------- */
var $tabs = $( '.m365-admin__tab' );
var $panels = $( '.m365-admin__panel' );
function activate( name ) {
$tabs.removeClass( 'is-active' ).attr( 'aria-selected', 'false' ).filter( '[data-tab="' + name + '"]' ).addClass( 'is-active' ).attr( 'aria-selected', 'true' );
$panels.removeClass( 'is-active' ).filter( '[data-panel="' + name + '"]' ).addClass( 'is-active' );
try {
window.localStorage.setItem( 'm365LoginTab', name );
} catch ( e ) {}
}
$tabs.on( 'click', function () {
activate( $( this ).data( 'tab' ) );
} );
try {
var saved = window.localStorage.getItem( 'm365LoginTab' );
if ( saved && $tabs.filter( '[data-tab="' + saved + '"]' ).length ) {
activate( saved );
}
} catch ( e ) {}
// Jump to the tab that contains a validation error.
var $error = $( '.settings-error' ).first();
if ( $error.length && $error.text().toLowerCase().indexOf( 'tenant' ) !== -1 ) {
activate( 'connection' );
}
/* ---------------- Live preview ---------------- */
function setVar( name, value ) {
$preview[ 0 ].style.setProperty( '--m365-' + name, value );
}
function updateIcon() {
var show = $( '[data-preview="show-icon"]' ).is( ':checked' );
var url = $.trim( $( '#m365-icon-url' ).val() );
var $icon = $( '#m365-preview-icon' );
var $thumb = $( '#m365-icon-thumb' );
$icon.toggleClass( 'is-hidden', ! show );
if ( url ) {
var $img = $( '<img>', { src: url, alt: '' } );
$icon.empty().append( $img );
$thumb.empty().append( $img.clone() );
} else {
$icon.html( cfg.defaultLogo || '' );
$thumb.html( cfg.defaultLogo || '' );
}
}
$( '[data-preview="text"]' ).on( 'input', function () {
$( '#m365-preview-text' ).text( $( this ).val() );
} );
$( '[data-preview="divider"]' ).on( 'input', function () {
var val = $.trim( $( this ).val() );
$( '#m365-preview-divider' ).text( val ).closest( '.m365-login__divider' ).toggleClass( 'is-hidden', ! val );
} ).trigger( 'input' );
$( '[data-preview="show-icon"], #m365-icon-url' ).on( 'change input', updateIcon );
$( '[data-preview="radius"]' ).on( 'input change', function () {
setVar( 'radius', $( this ).val() + 'px' );
$( '#m365-radius-value' ).text( $( this ).val() + ' px' );
} );
$( '.m365-color' ).wpColorPicker( {
change: function ( event, ui ) {
var key = $( event.target ).data( 'preview' );
var color = ui.color.toString();
setVar( key.replace( '_', '-' ), color );
},
clear: function ( event ) {
var $input = $( event.target ).closest( '.wp-picker-container' ).find( '.m365-color' );
setVar( $input.data( 'preview' ).replace( '_', '-' ), $input.data( 'default-color' ) );
}
} );
$( '.m365-preset' ).on( 'click', function () {
var preset = $( this ).data( 'preset' );
if ( ! preset ) {
return;
}
$.each( preset, function ( key, value ) {
$( '#m365-button_' + key ).wpColorPicker( 'color', value );
} );
} );
/* ---------------- Media library ---------------- */
var frame;
$( '#m365-icon-choose' ).on( 'click', function ( e ) {
e.preventDefault();
if ( ! window.wp || ! wp.media ) {
return;
}
if ( ! frame ) {
frame = wp.media( {
title: i18n.chooseIcon || '',
button: { text: i18n.useIcon || '' },
library: { type: 'image' },
multiple: false
} );
frame.on( 'select', function () {
var attachment = frame.state().get( 'selection' ).first().toJSON();
var url = attachment.url;
if ( attachment.sizes && attachment.sizes.thumbnail && attachment.mime !== 'image/svg+xml' ) {
url = attachment.sizes.thumbnail.url;
}
$( '#m365-icon-url' ).val( url ).trigger( 'input' );
} );
}
frame.open();
} );
$( '#m365-icon-reset' ).on( 'click', function ( e ) {
e.preventDefault();
$( '#m365-icon-url' ).val( '' ).trigger( 'input' );
} );
/* ---------------- Secret visibility ---------------- */
$( '.m365-toggle-secret' ).on( 'click', function () {
var $input = $( '#m365-client-secret' );
var show = 'password' === $input.attr( 'type' );
$input.attr( 'type', show ? 'text' : 'password' );
$( this ).find( '.dashicons' ).toggleClass( 'dashicons-visibility', ! show ).toggleClass( 'dashicons-hidden', show );
} );
/* ---------------- Copy redirect URI ---------------- */
$( '.m365-copy__button' ).on( 'click', function () {
var $btn = $( this );
var text = $( '#' + $btn.data( 'copy' ) ).text();
var done = function () {
$btn.text( i18n.copied || 'Copied!' );
window.setTimeout( function () {
$btn.text( i18n.copy || 'Copy' );
}, 1500 );
};
if ( navigator.clipboard && navigator.clipboard.writeText ) {
navigator.clipboard.writeText( text ).then( done );
} else {
var $tmp = $( '<textarea>' ).val( text ).appendTo( 'body' ).select();
try {
document.execCommand( 'copy' );
} catch ( e ) {}
$tmp.remove();
done();
}
} );
/* ---------------- Test tenant ---------------- */
$( '#m365-test' ).on( 'click', function () {
var $btn = $( this );
var $out = $( '#m365-test-result' );
var label = $btn.text();
$btn.prop( 'disabled', true ).text( i18n.testing || '…' );
$out.removeClass( 'is-success is-error' ).prop( 'hidden', true ).empty();
$.post( cfg.ajaxUrl, {
action: cfg.action,
nonce: cfg.nonce,
tenant: $( '#m365-tenant' ).val()
} ).done( function ( res ) {
if ( res && res.success ) {
$out.addClass( 'is-success' ).text( res.data.message ).append( $( '<code>' ).text( res.data.issuer ) );
} else {
$out.addClass( 'is-error' ).text( ( res && res.data && res.data.message ) || i18n.testFailed || '' );
}
} ).fail( function () {
$out.addClass( 'is-error' ).text( i18n.testFailed || '' );
} ).always( function () {
$btn.prop( 'disabled', false ).text( label );
$out.prop( 'hidden', false );
} );
} );
} );
}( jQuery ) );