wp-m365-login/m365-login.php
friloo 8766927123
Add certificate authentication, in-app setup guides and security audit
Certificate (RFC 7523 client assertion) as an alternative to the client
secret: one-click generation of a 3072-bit RSA key pair with a
self-signed certificate, .cer download (public part only), own PEM
upload with validation, expiry display, encrypted key storage. Both the
authorization code exchange and the Graph client-credentials request
use the selected method. Step-by-step guides for secret, certificate
and the app registration are shown in the settings.

Security audit (docs/security-audit.md) and fixes:
- Multi-tenant mode ignored the unverified email claim: matching now
  uses the UPN only, or the email claim when xms_edov is true.
- Login starts are rate limited per client (30 per 10 minutes).
- Optional trusted proxy header for client IPs
  (M365_LOGIN_CLIENT_IP_HEADER / filter).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JJxAHYdMfKPoN4koRc4Ci2
2026-09-22 15:04:32 +00:00

38 lines
1.7 KiB
PHP

<?php
/**
* Plugin Name: M365 Login
* Plugin URI: https://github.com/friloo/wp-m365-login
* Description: Adds a customisable "Sign in with Microsoft" button to the WordPress login page. Existing users are matched by e-mail address via Microsoft Entra ID (OpenID Connect, PKCE).
* Version: 1.0.0
* Requires at least: 6.0
* Requires PHP: 7.4
* Author: friloo
* Author URI: https://github.com/friloo
* License: GPL-2.0-or-later
* License URI: https://www.gnu.org/licenses/gpl-2.0.html
* Text Domain: m365-login
* Domain Path: /languages
*/
defined( 'ABSPATH' ) || exit;
define( 'M365_LOGIN_VERSION', '1.0.0' );
define( 'M365_LOGIN_FILE', __FILE__ );
define( 'M365_LOGIN_DIR', plugin_dir_path( __FILE__ ) );
define( 'M365_LOGIN_URL', plugin_dir_url( __FILE__ ) );
define( 'M365_LOGIN_OPTION', 'm365_login_settings' );
require_once M365_LOGIN_DIR . 'includes/class-m365-login-settings.php';
require_once M365_LOGIN_DIR . 'includes/class-m365-login-crypto.php';
require_once M365_LOGIN_DIR . 'includes/class-m365-login-jwt.php';
require_once M365_LOGIN_DIR . 'includes/class-m365-login-certificate.php';
require_once M365_LOGIN_DIR . 'includes/class-m365-login-graph.php';
require_once M365_LOGIN_DIR . 'includes/class-m365-login-auth.php';
require_once M365_LOGIN_DIR . 'includes/class-m365-login-button.php';
require_once M365_LOGIN_DIR . 'includes/class-m365-login-admin.php';
require_once M365_LOGIN_DIR . 'includes/class-m365-login.php';
require_once M365_LOGIN_DIR . 'includes/functions.php';
register_activation_hook( __FILE__, array( 'M365_Login', 'activate' ) );
add_action( 'plugins_loaded', array( 'M365_Login', 'instance' ) );