-
Notifications
You must be signed in to change notification settings - Fork 843
feat: Expand application password abilities #45220
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: trunk
Are you sure you want to change the base?
Conversation
|
Are you an Automattician? Please test your changes on all WordPress.com environments to help mitigate accidental explosions.
Interested in more tips and information?
|
|
Thank you for your PR! When contributing to Jetpack, we have a few suggestions that can help us test and review your patch:
This comment will be updated as you work on your PR and make changes. If you think that some of those checks are not needed for your PR, please explain why you think so. Thanks for cooperation 🤖 Follow this PR Review Process:
If you have questions about anything, reach out in #jetpack-developers for guidance! Jetpack plugin: The Jetpack plugin has different release cadences depending on the platform:
If you have any questions about the release process, please ask in the #jetpack-releases channel on Slack. |
Code Coverage SummaryCannot generate coverage summary while tests are failing. 🤐 Please fix the tests, or re-run the Code coverage job if it was something being flaky. |
1b9ad63 to
ac4c623
Compare
Allow authenticating for `admin-ajax` and post preview requests with application passwords. This enables cookie-less clients--e.g, the iOS and Android mobile apps--to successfully authenticate these requests.
Return early if the provided value is already truthy.
8e1970e to
cc53440
Compare
Allow authenticating for
admin-ajaxand post preview requests with application passwords. This enables cookie-less clients—e.g, the iOS and Android mobile apps—to successfully authenticate these requests.Ref CMM-713. Close CMM-766.
Proposed changes:
Leverage the
application_password_is_api_requestfilter to conditionally extend application password authentication for:admin-ajaxOther information:
Jetpack product discussion
pbArwn-7AD-p2
Does this pull request change what data or activity we track or use?
No
Testing instructions:
Tip
Apply these Jetpack changes to your site (see comment) before testing.
1. Authenticate
admin-ajaxrequests with application passwordsadmin-ajaxaction:curl -I 'https://<site_domain>/wp-admin/admin-ajax.php?action=logged-in'admin-ajaxaction:2. Authenticate post preview request with application passwords
curl -I 'https://<site_domain>/?p=<post_id>&preview=true'3. Retrieve application password abilities
{"admin-ajax":true,"post-previews":true}