Repository navigation
Sites: Require network permission for membership changes. - #149
Merged
Merged
Conversation
Only network site managers may add, remove, or change a user’s role on a Multisite site from the Sites profile section. Cover self-service escalation and authorized network administration, and prepare version 2.7.4. Props Nguyen Viet Tin.
Use the real Multisite smoke environment to verify that self-service role assignment is blocked and network administration still works. Restore the centrally enrolled PHPUnit bootstrap and avoid new PHPCS baseline allowances.
Move Sites membership regression coverage into a new PHPUnit test file. The central CI policy pins the existing Multisite smoke payload by hash, so leave that payload intact.
Keep WordPress site-membership test doubles in a separate fixture and align assignments so the required PHPCS baseline does not grow.
The status control is hidden on self-profile screens, but posted values still reached the global save callback. Require permission to edit another user and respect the status-control visibility filter before changing account status. Cover self-edit, unauthorized editing, and permitted user management.
Check promote_user at the Permissions section save boundary for every site, including the current site and single-site installs. This prevents direct section saves from changing roles with self-profile access alone. Add regression coverage for denied and authorized role changes.
The Sites section now accepts a primary site only when it belongs to the edited user, matching the choices shown in the form. Add regression coverage for crafted and valid values.
This reverts commit f181f8f.
Require an existing site for primary-site selection without requiring membership. Apply network access and action-specific removal or promotion permissions to Sites bulk changes, while retaining site-management access for new membership. Reject crafted self-role changes in Permissions and cover allowed and denied paths.
Check site existence and editable network access in the Permissions save path before switching sites. Preserve custom role slugs in Sites bulk actions and verify that each role exists on the target site. Add regression coverage for cross-network and nonexistent sites, custom role slugs, and unregistered roles.
Contributor
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
Security-sensitive Multisite authorization and user-data changes require final human validation despite targeted regression coverage.
Review effort: Balanced
Findings: None
What changed in this PR
Hardens user-status and Multisite membership/role authorization while preparing release 2.7.4.
Changes:
- Adds capability, network-access, role, and site validation.
- Adds targeted security regression tests.
- Synchronizes release metadata and translations.
| File | Description |
|---|---|
wp-user-profiles/includes/status.php |
Secures status updates. |
wp-user-profiles/includes/sections/sites.php |
Secures site membership operations. |
wp-user-profiles/includes/sections/permissions.php |
Secures cross-site role changes. |
wp-user-profiles/assets/languages/wp-user-profiles.pot |
Updates translation catalog. |
wp-user-profiles.php |
Bumps plugin version. |
tests/StatusPermissionsTest.php |
Tests status authorization. |
tests/SitesPermissionsTest.php |
Tests membership boundaries. |
tests/PermissionsSecurityTest.php |
Tests role-change authorization. |
tests/fixtures/site-membership-stubs.php |
Adds membership test doubles. |
tests/fixtures/class-wpup-test-status-db.php |
Adds status database double. |
tests/fixtures/class-wpup-test-site-roles.php |
Adds role-registry double. |
readme.txt |
Updates release metadata and notes. |
package.json |
Bumps package version. |
package-lock.json |
Synchronizes locked version. |
CHANGELOG.md |
Documents release 2.7.4. |
💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Require the existing network site-management capability before the Sites profile section changes Multisite membership or roles. Enforce user-editing permission for account-status changes, which previously relied on a hidden control. Require role-promotion permission in the Permissions section for each target site and reject crafted self-role changes.
Align the remaining Sites save boundaries with WordPress Core: accept an existing primary site without requiring membership; check network access before bulk changes; require
remove_usersfor removal andpromote_users,promote_user, and an editable role before changing an existing member's role. New membership still requiresmanage_sites.An independent review found two further issues, now addressed: Permissions role saves validate the target network before switching sites, and Sites bulk actions preserve registered custom role slugs without accepting unknown roles.
Prepare version 2.7.4 and credit Nguyen Viet Tin for the private Sites report.
Validation