Adds a WordPress plugin that places a customisable "Sign in with Microsoft" button on wp-login.php and signs existing users in via the OpenID Connect authorization code flow with PKCE. Users are matched by e-mail address only; no accounts are created. Security: single-use state/nonce bound to an HttpOnly cookie, ID token signature verification against Microsoft's JWKS (RS256 only) with issuer/audience/tenant/expiry/nonce checks, optional tenant pinning, account binding to the Microsoft object ID, e-mail domain allow-list, client secret encrypted at rest (AES-256-GCM). Admin: settings screen with connection, button and security tabs, live button preview, colour presets, media-library icon picker, redirect URI copy button and tenant connectivity test. Packaging for WordPress.org: readme.txt with External services section, GPL-2.0 license, uninstall.php, POT + German translations, .distignore, build script, PHPCS config and CI running Plugin Check. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01JJxAHYdMfKPoN4koRc4Ci2
27 lines
658 B
Bash
Executable file
27 lines
658 B
Bash
Executable file
#!/usr/bin/env bash
|
||
# Builds build/m365-login.zip – the folder inside the archive is named after the
|
||
# WordPress.org slug (m365-login), regardless of the repository name.
|
||
set -euo pipefail
|
||
|
||
ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
|
||
SLUG="m365-login"
|
||
BUILD="$ROOT/build"
|
||
STAGE="$BUILD/$SLUG"
|
||
|
||
rm -rf "$BUILD"
|
||
mkdir -p "$STAGE"
|
||
|
||
# rsync honours .distignore-style excludes.
|
||
rsync -a --delete \
|
||
--exclude-from="$ROOT/.distignore" \
|
||
--exclude 'build' \
|
||
"$ROOT/" "$STAGE/"
|
||
|
||
(
|
||
cd "$BUILD"
|
||
rm -f "$SLUG.zip"
|
||
zip -rq "$SLUG.zip" "$SLUG"
|
||
)
|
||
|
||
echo "Created $BUILD/$SLUG.zip"
|
||
unzip -l "$BUILD/$SLUG.zip" | tail -n +4 | head -n -2 | awk '{print $4}'
|