Repository navigation
Conversation
…pack Protect plugin
|
Are you an Automattician? Please test your changes on all WordPress.com environments to help mitigate accidental explosions.
Interested in more tips and information?
|
|
Thank you for your PR! When contributing to Jetpack, we have a few suggestions that can help us test and review your patch:
This comment will be updated as you work on your PR and make changes. If you think that some of those checks are not needed for your PR, please explain why you think so. Thanks for cooperation 🤖 Follow this PR Review Process:
If you have questions about anything, reach out in #jetpack-developers for guidance! Jetpack plugin: No scheduled milestone found for this plugin. If you have any questions about the release process, please ask in the #jetpack-releases channel on Slack. |
Code Coverage SummaryCannot generate coverage summary while tests are failing. 🤐 Please fix the tests, or re-run the Code coverage job if it was something being flaky. |
6d2c079 to
ba796ae
Compare
ba796ae to
5c74b1e
Compare
With the protect-dashboard module active and no standalone plugin, the link went to protect-details or Jetpack Cloud instead of the Protect page.
… retry A failed save no longer resets the IP list field to the saved value, and a failed settings load now clears its error on retry and offers a Try again button. Section types take an optional state type, the tab search param is narrowed at runtime, and the settings hook returns a stable object.
ProtectCard and CardRow keep their props and now render through Card from the WordPress UI package, so border, radius, background and header spacing come from the design system.
… section registry Adds routes/ to the client Jest roots so route tests run.
…to add/protect-dashboard-foundation
The base branch added a Jetpack_Protect_Dashboard_Test class of its own, so the section registry tests now live in that class and the threats test moves into the same suite directory.
…to add/protect-dashboard-foundation # Conflicts: # projects/plugins/jetpack/composer.lock
…' into add/protect-dashboard-login-protection
My Jetpack no longer depends on the feature flags package, so the Jetpack plugin now reports the flag through jetpack_my_jetpack_protect_in_jetpack.
…to add/protect-dashboard-foundation
…' into add/protect-dashboard-login-protection
Pass LoginProtectionState to ProtectSection and DashboardContext now that they take a state type, and drop the casts.
b531356 to
6567e4b
Compare
…d-login-protection # Conflicts: # projects/packages/my-jetpack/src/class-main-features.php # projects/packages/my-jetpack/src/products/class-protect.php # projects/packages/my-jetpack/tests/php/Protect_Product_Test.php # projects/plugins/jetpack/_inc/lib/class-jetpack-protect-dashboard-feature-flags.php # projects/plugins/jetpack/composer.json # projects/plugins/jetpack/composer.lock # projects/plugins/jetpack/modules/protect-dashboard.php # projects/plugins/jetpack/tests/php/_inc/lib/Jetpack_Protect_Dashboard_Feature_Flags_Test.php
Fixes JETPACK-2958
Part of JETPACK-2883, JETPACK-2887
Proposed changes
sections/login-protection/andsections/class-jetpack-protect-dashboard-login-protection.php).protecttoggle (disabled when the module is unavailable), plus the "Always allow specific IP addresses" toggle and list, with a button that adds the visitor's own IP.account-protectiontoggle (disabled when the module is unavailable).ssotoggle, plus "Match accounts using email addresses" and "Require Two-Step Authentication". As in Jetpack Settings, thessotoggle is disabled without a connected owner or in offline mode, and turning it off asks for confirmation first. Both options are disabled while SSO is off. When a filter or constant forces an option, the toggle is locked, shows the value SSO actually applies, and help text says so.protect,account-protectionandsso, thejetpack_protect_blocked_attemptscount (always sent, formatted withnumber_format_i18n()), whether SSO can be turned on (connected owner, not offline), the SSO locks (eachHelperscall guarded withmethod_exists) and the effective SSO values (Helpers::match_by_email(),Helpers::is_two_step_required()), and the current IP. The section adds no REST routes of its own and usesjetpack/v4/settings.Related product discussion/links
Does this pull request change what data or activity we track or use?
No.
Testing instructions
Build and sync Jetpack to a connected test site, then run:
wp companion feature-flag enable jetpack-protect-dashboard(or force thejetpack-protect-dashboardflag on with thejetpack_feature_flag_enabled_jetpack-protect-dashboardfilter)wp eval 'Jetpack_Options::delete_option("available_modules");'wp jetpack module activate protect-dashboardwp jetpack module activate protect, then the same foraccount-protectionandssoGo to Jetpack › Protect (
admin.php?page=jetpack-protect). Check that the Login protection card shows "3 of 3 on", "All-time blocked login attempts", and the three methods marked On.Click "Configure login protection". The Settings tab should open, with three subsections under Login protection.
Turn "Match accounts using email addresses" off, then back on. Each change should save with a 200 POST to
jetpack/v4/settings.Turn on "Always allow specific IP addresses", click "Add my IP address", then click Save. Check that
jetpack_waf_ip_allow_listnow holds your IP.Turn off "Allow users to log in with their WordPress.com account". A confirmation dialog should appear; Cancel leaves SSO on, "Turn off" saves it. The two options under it should then become disabled. Go back to Overview: the badge should now read "2 of 3 on" and the WordPress.com login row should say Off.
Locked option: add an mu-plugin with
add_filter( 'jetpack_sso_require_two_step', '__return_true' );and reload. "Require accounts to use WordPress.com Two-Step Authentication" should be on and disabled, with help text saying it is enforced. Remove the mu-plugin afterwards.Review follow-ups
Fixed:
available, and the SSO toggle needs a connected owner and no offline mode, as in Jetpack Settings.AlertDialogfrom@wordpress/ui).Deferred:
h3s sit under the card title, whichProtectCard(foundation) renders as aspan; the fix belongs inProtectCard(render the title ash2).Screenshots
Overview → Login protection card:


Settings → Login protection card: