Skip to content

Sites: Require network permission for membership changes. - #149

Merged
JJJ merged 10 commits into
masterfrom
security/sites-role-capability
Oct 2, 2026
Merged

JJJ merged 10 commits into
masterfrom
security/sites-role-capability

Conversation

@JJJ

@JJJ JJJ commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Require the existing network site-management capability before the Sites profile section changes Multisite membership or roles. Enforce user-editing permission for account-status changes, which previously relied on a hidden control. Require role-promotion permission in the Permissions section for each target site and reject crafted self-role changes.

Align the remaining Sites save boundaries with WordPress Core: accept an existing primary site without requiring membership; check network access before bulk changes; require remove_users for removal and promote_users, promote_user, and an editable role before changing an existing member's role. New membership still requires manage_sites.

An independent review found two further issues, now addressed: Permissions role saves validate the target network before switching sites, and Sites bulk actions preserve registered custom role slugs without accepting unknown roles.

Prepare version 2.7.4 and credit Nguyen Viet Tin for the private Sites report.

Validation

  • PHPUnit covers denied and authorized membership, role, status, and primary-site saves, including cross-network IDs and custom role slugs.
  • PHPStan, the centrally managed PHPCS gate, release metadata, and translation catalog pass locally on the current head.
  • Exact-head WordPress integration and compatibility checks run in CI.
  • All commits are signed and GitHub marks them Verified.

JJJ added 10 commits October 2, 2026 08:53
Only network site managers may add, remove, or change a user’s role on a Multisite site from the Sites profile section. Cover self-service escalation and authorized network administration, and prepare version 2.7.4.

Props Nguyen Viet Tin.
Use the real Multisite smoke environment to verify that self-service role assignment is blocked and network administration still works. Restore the centrally enrolled PHPUnit bootstrap and avoid new PHPCS baseline allowances.
Move Sites membership regression coverage into a new PHPUnit test file. The central CI policy pins the existing Multisite smoke payload by hash, so leave that payload intact.
Keep WordPress site-membership test doubles in a separate fixture and align assignments so the required PHPCS baseline does not grow.
The status control is hidden on self-profile screens, but posted values still reached the global save callback. Require permission to edit another user and respect the status-control visibility filter before changing account status.

Cover self-edit, unauthorized editing, and permitted user management.
Check promote_user at the Permissions section save boundary for every site, including the current site and single-site installs. This prevents direct section saves from changing roles with self-profile access alone.

Add regression coverage for denied and authorized role changes.
The Sites section now accepts a primary site only when it belongs to the edited user, matching the choices shown in the form. Add regression coverage for crafted and valid values.
Require an existing site for primary-site selection without requiring membership. Apply network access and action-specific removal or promotion permissions to Sites bulk changes, while retaining site-management access for new membership.

Reject crafted self-role changes in Permissions and cover allowed and denied paths.
Check site existence and editable network access in the Permissions save path before switching sites. Preserve custom role slugs in Sites bulk actions and verify that each role exists on the target site.

Add regression coverage for cross-network and nonexistent sites, custom role slugs, and unregistered roles.
@JJJ
JJJ marked this pull request as ready for review October 2, 2026 16:52
Copilot AI balanced review requested due to automatic review settings October 2, 2026 16:52
@JJJ
JJJ merged commit 1692e69 into master Oct 2, 2026
15 checks passed
@JJJ
JJJ deleted the security/sites-role-capability branch October 2, 2026 16:55

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Security-sensitive Multisite authorization and user-data changes require final human validation despite targeted regression coverage.

Review effort: Balanced
Findings: None

What changed in this PR

Hardens user-status and Multisite membership/role authorization while preparing release 2.7.4.

Changes:

  • Adds capability, network-access, role, and site validation.
  • Adds targeted security regression tests.
  • Synchronizes release metadata and translations.
File Description
wp-user-profiles/​includes/​status.php Secures status updates.
wp-user-profiles/​includes/​sections/​sites.php Secures site membership operations.
wp-user-profiles/​includes/​sections/​permissions.php Secures cross-site role changes.
wp-user-profiles/​assets/​languages/​wp-user-profiles.pot Updates translation catalog.
wp-user-profiles.php Bumps plugin version.
tests/​StatusPermissionsTest.php Tests status authorization.
tests/​SitesPermissionsTest.php Tests membership boundaries.
tests/​PermissionsSecurityTest.php Tests role-change authorization.
tests/​fixtures/​site-membership-stubs.php Adds membership test doubles.
tests/​fixtures/​class-wpup-test-status-db.php Adds status database double.
tests/​fixtures/​class-wpup-test-site-roles.php Adds role-registry double.
readme.txt Updates release metadata and notes.
package.json Bumps package version.
package-lock.json Synchronizes locked version.
CHANGELOG.md Documents release 2.7.4.

💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants