wp-m365-login/uninstall.php
Friederich Loheide 4edf20bc45
Some checks are pending
CI / PHP lint (7.4) (pull_request) Waiting to run
CI / PHP lint (8.0) (pull_request) Waiting to run
CI / PHP lint (8.1) (pull_request) Waiting to run
CI / PHP lint (8.2) (pull_request) Waiting to run
CI / PHP lint (8.3) (pull_request) Waiting to run
CI / PHP lint (8.4) (pull_request) Waiting to run
CI / WordPress Coding Standards (pull_request) Waiting to run
CI / WordPress.org Plugin Check (pull_request) Waiting to run
Add Microsoft 365 user sync with roles, profile fields and deprovisioning
New "User sync" tab that imports Microsoft 365 / Entra ID users as
WordPress accounts and keeps them up to date:

- Scope: whole tenant or the (nested) members of selected groups,
  guests optional, e-mail domain allow-list respected. Existing accounts
  are linked by e-mail address.
- Roles: selectable default role plus a group -> role mapping (in
  addition to or instead of the default role, first match wins).
  Roles of pre-existing accounts are only managed on request.
- Profile: selectable Graph attributes (names, job title, department,
  phones, address, language, ...) and the profile photo as avatar.
- Deprovisioning: accounts disabled or deleted in Microsoft 365 (or
  removed from the sync groups) are deactivated or deleted; accounts
  deactivated by the sync are reactivated automatically. Deactivated
  accounts lose every sign-in path and all sessions.
- Safeguards: dry run, safety stop above 20 % (min. 5) deprovisioning,
  abort on any Graph error, "deleted" only on a 404 for the object ID,
  protected pre-existing administrators and own account, content
  reassignment required for deletion, run lock.
- Runs manually, via WP-Cron or `wp m365-login sync [--dry-run]`.
- Users screen column with deactivate/reactivate row actions and a
  read-only Microsoft 365 section on the profile screen.

The Graph client gains paging, retry on throttling and user, group
member and photo endpoints. The group picker is now reusable.
Version 1.1.0, German translations (du/Sie), docs and audit addendum.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-09-23 16:34:30 +00:00

58 lines
1.8 KiB
PHP

<?php
/**
* Removes all plugin data on uninstall.
*
* @package M365_Login
*/
if ( ! defined( 'WP_UNINSTALL_PLUGIN' ) ) {
exit;
}
global $wpdb;
/**
* Deletes options, transients and user meta for one site.
*/
function m365_login_uninstall_site() {
global $wpdb;
delete_option( 'm365_login_settings' );
delete_option( 'm365_login_sync_report' );
wp_clear_scheduled_hook( 'm365_login_sync' );
// Synced profile photos (uploads/m365-login-avatars/).
$uploads = wp_get_upload_dir();
$dir = trailingslashit( $uploads['basedir'] ) . 'm365-login-avatars';
if ( is_dir( $dir ) ) {
foreach ( (array) glob( $dir . '/m365-*' ) as $file ) {
wp_delete_file( $file );
}
@rmdir( $dir ); // phpcs:ignore WordPress.PHP.NoSilencedErrors.Discouraged, WordPress.WP.AlternativeFunctions.file_system_operations_rmdir -- best effort, may contain foreign files.
}
// Transients: state records and JWKS cache.
$wpdb->query( // phpcs:ignore WordPress.DB.DirectDatabaseQuery
$wpdb->prepare(
"DELETE FROM {$wpdb->options} WHERE option_name LIKE %s OR option_name LIKE %s",
$wpdb->esc_like( '_transient_m365_login_' ) . '%',
$wpdb->esc_like( '_transient_timeout_m365_login_' ) . '%'
)
);
}
if ( is_multisite() ) {
$m365_login_site_ids = get_sites( array( 'fields' => 'ids', 'number' => 0 ) );
foreach ( $m365_login_site_ids as $m365_login_site_id ) {
switch_to_blog( $m365_login_site_id );
m365_login_uninstall_site();
restore_current_blog();
}
} else {
m365_login_uninstall_site();
}
// User meta is global. Imported accounts stay; copied profile fields (m365_*) are kept as ordinary user data.
foreach ( array( '_m365_login_oid', '_m365_login_last_login', '_m365_login_synced', '_m365_login_disabled', '_m365_login_last_sync', '_m365_login_photo' ) as $m365_login_meta_key ) {
delete_metadata( 'user', 0, $m365_login_meta_key, '', true );
}