Skip to content

WB Listora 1.4.0 - App password sign-in, with an owner switch and brute-force defences

Choose a tag to compare

@vapvarun vapvarun released this 02 Aug 01:48
· 301 commits to main since this release

Adds password sign-in for the mobile app, with an owner switch and the brute-force protections that route needs.

  • New - Members can sign in to the mobile app by typing the WordPress password they already have, instead of walking the browser approval screen.
  • New - Settings > Advanced carries an App sign-in switch so the site owner decides whether password sign-in is offered. Turning it off leaves the browser flow and does not sign out members who already use the app.
  • New - Signing in again from the same install replaces that install's credential instead of adding another, so a member's app-password list stops growing on every reconnect.
  • Improve - The app is told which sign-in doors this site offers before it draws the screen, so it never presents a path the site will refuse.
  • Improve - Sign-in failures answer identically whether the username or the password was wrong, so the endpoint cannot be used to discover which accounts exist.
  • Improve - Repeated failed sign-ins are throttled per address and per account, and only wrong passwords count toward the limit.
  • Improve - Sites running two-factor authentication are never bypassed; the app is handed back to the browser flow so the second factor can complete.
  • Fix - Members can delete their own listings again. The permission check refused the owner and allowed only administrators.
  • Fix - Custom badges now appear on directory cards and in Quick View, and a featured listing no longer shows the Featured label twice.
  • Fix - The single-form submission layout no longer hides its own steps.
  • Fix - Status colours now meet contrast requirements in dark mode.
  • Fix - The owner contact form and the Pro lead form share one submit path, so a listing shows one working form rather than two competing ones.
  • Dev - The server advertises its own contact and lead-form routes; clients no longer hardcode them.
  • Dev - Card view data now carries through anything added by the wb_listora_card_view_data filter, so an extension's additions reach the card templates.
  • Dev - New filters: wb_listora_app_scheme, wb_listora_app_connect_schemes, wb_listora_app_connect_bridge and wb_listora_app_password_login_enabled, plus the wb_listora_app_credential_issued action.
  • Compat - Ships in lockstep with WB Listora Pro 1.4.0. Install both updates together.

Full changelog: https://wbcomdesigns.com/release-notes/listora/
Ships in lockstep with WB Listora Pro 1.4.0: https://github.com/wbcomdesigns/wb-listora-pro/releases/tag/v1.4.0