Releases: BrianHenryIE/bh-wp-autologin-urls
Releases · BrianHenryIE/bh-wp-autologin-urls
Release list
v2.6.0
What's Changed
- Modernize dev environment; fix rate limiting by @BrianHenryIE in #30
- Catch exceptions at the plugin's boundaries so it can never fatal a site by @BrianHenryIE in #31
- Prefix psr/log by @BrianHenryIE in #32
Security: rate limiting never actually blocked anything – failed autologin attempts are now counted and enforced
Security: malformed autologin codes are recorded against the IP and user again, restoring brute-force protection lost when the failure transients were replaced by a rate limiter
Fix: repeated use of a valid autologin link no longer exhausts the rate limit – only failures are counted
Fix: don't show autologin URLs in the admin UI for administrator accounts
Fix: MailPoet 5.34 compatibility – the removed MailPoet\Models\Subscriber legacy model replaced with its Doctrine equivalents
Fix: usernames which are entirely numeric failed to resolve in API::get_wp_user()
Fix: fatal error when an integration's constructor has an untyped or union-typed parameter
Fix: fatal error prefilling the WooCommerce checkout when the session handler has no set_customer_session_cookie()
Fix: get_ip_address() when HTTP_X_FORWARDED_FOR cannot be parsed
Fix: REST API expires_in schema – int is not a valid type (WordPress _doing_it_wrong since 5.5), and it was wrongly marked format: url
Fix: PHP 8.1 deprecations – FILTER_SANITIZE_STRING / FILTER_SANITIZE_STRIPPED
Fix: PHP 8.4 deprecation – implicit nullable parameter
Fix: a failure storing an autologin code no longer breaks the operation it was hooked into – notably wp_mail(), where an uncaught exception could break other plugins' emails
Fix: catch throwables at every hook the plugin registers, so it can never fatal a site; failures are logged and shown as an admin notice
Fix: $wpdb error messages were lost before the exception was created, so the error admin notice had no detail
Fix: don't email a magic "Sign-in Link" when no autologin code could be created
Add: get_wp_user() to API_Interface
Tested up to WordPress 7.0
Dev: dev environment modernized – wp-browser 4 / Codeception 5, PHPStan level 8 over src and tests, PHPCS clean, Rector, Playwright against WordPress 7.0, rebuilt GitHub Actions
Full Changelog: 2.5.0...2.6.0
v2.5.0
2.4.2
- Fix: fatal error with User Switching plugin – firing
wp_logintoo early. Fix #24, thanks @sisaacrussell, @johnbillion, @mgratch
v2.4.1
- Fix: fatal error with WooCommerce HPOS meta boxes hook – strict typing issue. Fix #25 Thanks @sisaacrussell. See BrianHenryIE/bh-wp-private-uploads@d9f362b
v2.4.0
- Add: REST API
- Add/fix: prefill WooCommerce checkout with user details from The Newsletter Plugin, Klaviyo, Mailpoet
- Fix: fatal error on first request after WooCommerce is deleted from filesystem
- Fix: broken WooCommerce orders page
- Fix: strpos() null error when HTTP_USER_AGENT missing. Thanks @sisaacrussell
- Fix: bug with bh-wp-logger – thanks @sisaacrussell
- Improve: logging
- Improve: don't add autologin codes to The Newsletter Plugin emails' URLs
v2.3.0
- Add: "Send magic login email" button on users list table
- Fix: bug with bh-wp-logger – thanks @Amit-Biswas
- Add: screenshots to .org plugin page
- Add: CLI documentation
- Fix: minor wording
- Dev: add Playwright tests

v2.2.0
v2.1.1
- Fix: Default expiry time when omitted in CLI was parsing as 0
- Add: Warning that logs may contain autologin codes
v2.1.0
- Add: CLI commands
wp autologin-urls get-urlandwp autologin-urls send-magic-link - Fix: Links to
/wp-adminwere redirecting to wp-login screen because$_COOKIEwas not yet set - Performance: Return early when no querystring set
- Fix:
wp_safe_redirect()exit()is now conditional
v2.0.0
- Breaking: UI for regex subject filters removed (functionality still exists through filters)
- Fix: Use correct
determine_current_userfilter for login - Update library: RateLimit library has bugfix to handle
falsereturned from transients for expectedarray - Update library: bh-wp-logger library has performance and feature improvements
