=== Membership.fi ===
Contributors: anssikuuttimembership
Tags: members, membership, login, openid connect, restrict content
Requires at least: 6.5
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 0.2.0
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Members sign in with their Membership account. Pages and files for members only, or for chosen groups, following the member register.

== Description ==

Membership.fi connects an association's WordPress site to its member register in [Membership](https://membership.fi). Members sign in with the account they already use for their membership card and invoices, and the site knows who is a member and which groups they belong to.

* **Sign in with Membership.** A button on the login page, as a block, as a shortcode or as a menu link. Passwords never pass through your site.
* **Pages for members or for groups.** Every page and post has a Visibility setting: everyone, members, or chosen groups (for example one section of a sports club). Groups come from Membership as they are there.
* **Protected files.** A file uploaded to a restricted page is kept in a folder the web server does not serve, and handed out only to those who may see the page.
* **Access follows the register.** Membership is asked again every day. When a membership ends, or the member withdraws the site's permission, their access ends here too. Nobody has to remember to remove an account.
* **Roles by group.** A group in Membership can bring a WordPress role, such as Editor for the communications team, and takes it away again when someone leaves the group. Administrator can never be given this way.

Restricted content is kept out of every place WordPress would otherwise show it: search, archives, feeds, the REST API, menus and the Page List block, sitemaps, comments, previous and next links, oEmbed and featured images. Restricted pages are marked noindex and never cached for the next visitor.

The plugin needs an association that uses Membership, and an administrator there to register the site.

== Installation ==

1. Download the plugin from https://membership.fi/wordpress/membership-fi.zip. In WordPress, open Plugins, Add New, Upload Plugin, choose the file and activate the plugin.
2. Open Settings, Membership and copy the redirect address shown there.
3. In Membership, open Settings, Connections, and under "Sign in with Membership" add a website with that redirect address. Membership shows a client ID and a secret once.
4. Paste them into the plugin's settings and save. The settings page checks the connection straight away.
5. Choose who may see each page in the Visibility panel of the page editor.

Updates come from membership.fi and appear among WordPress's other updates, so a site that updates plugins automatically gets them automatically too.

The settings page also checks that the web server refuses to serve protected files directly. Apache is covered by the plugin itself. On nginx, add the rule the settings page shows.

== Frequently Asked Questions ==

= Do members need a WordPress account? =

No. The first time a member signs in with Membership, an account is made for them. If an account with the same verified email address already exists, it is used instead. Administrator accounts are never linked by email: an administrator links their own account from their profile page.

= What does the site learn about a member? =

Their name, email address, and membership in the association that registered the site: status, role, membership type, member number and the groups they belong to. Memberships in other associations are never shared. The member agrees to this once per site, and can withdraw it in Membership at any time. The plugin stores the name, email address, membership status and groups; the rest is not copied.

= What happens if I deactivate the plugin? =

Restricted pages are made private, so they do not become public while nothing restricts them. Activating the plugin again publishes them as they were. Protected files stay protected.

= Does it work with page caching? =

Yes, as long as the cache skips signed-in visitors, which is the default for common caching plugins and hosts. Restricted pages are sent with headers that forbid caching.

= Can I use another OpenID Connect plugin instead? =

Yes, signing in with Membership follows the OpenID Connect standard. Group-based visibility, protected files and the daily membership check are what this plugin adds.

== Screenshots ==

1. Choosing who sees a page: everyone, members, or chosen groups.
2. What a visitor sees on a page for one group, with the way to sign in.
3. Signing in with Membership on the WordPress login page.
4. The first time, Membership shows the member what the site will be told and asks once.
5. The settings page checks the connection and that protected files are refused by the web server.
6. A member of the group sees the page and its files.

== External services ==

This plugin connects to Membership, a member register service by Membership (https://membership.fi), to sign members in and to check their membership. Nothing is sent before an administrator has entered the site's client ID and secret.

* When a visitor chooses to sign in, their browser is sent to Membership's sign-in page (by default https://api.membership.fi/oidc). Membership then sends back a one-time code, which the site exchanges for the member's name, email address, membership status and groups, sending its client ID and secret.
* About once a day, for each member who has signed in, the site asks Membership whether the membership is still valid, sending its client ID, secret and that member's refresh token.
* When the settings are saved or checked, the site fetches Membership's public sign-in settings and tests its client ID and secret.
* A few times a day, when WordPress checks for updates, the site fetches https://membership.fi/wordpress/membership-fi.json to see whether a new version exists, and downloads the new version from membership.fi when it is installed. The request carries WordPress's usual user agent, which names the site's address; nothing about its members is sent.

Membership's terms of service: https://membership.fi/terms
Membership's privacy policy: https://membership.fi/privacy

== Changelog ==

= 0.2.0 =
* Updates from membership.fi, through WordPress's own update screens.
* Files of a deleted restricted page stay restricted, and a protected file whose page is gone counts as members only.
* Each protected file has a folder of its own, so a file of the same name can never keep another one out of the protected folder.
* Every file is checked hourly and on activation to be in the folder its visibility calls for.
* Links to resized protected images no longer contain an ampersand, which could make the block editor reject an image block.
* New members' accounts start without the admin toolbar.

= 0.1.0 =
* First release: sign in with Membership, visibility for members and groups, protected files, roles by group and the daily membership check.
