Roles and Capabilities in WordPress: Difference between revisions

From SWCP Support Wiki
Jump to navigationJump to search
Line 144: Line 144:
# get_role - Get the current user's Role
# get_role - Get the current user's Role
# remove_role - Remove a role from the master list of Roles
# remove_role - Remove a role from the master list of Roles
# add_cap - Add a capability
# add_cap - Add a capability to a Role or a User.
# remove_cap - Remove a capability
# remove_cap - Remove a capability from a Role or a User.
# current_user_can - Checks if the currently logged in user has a particular capability.
# current_user_can - Checks if the currently logged in user has a particular capability.


Useful classes: WP_Role, WP_Roles, WP_User
Useful classes: WP_Role, WP_Roles, WP_User

Revision as of 18:45, 19 June 2013

Standard Roles

One of the wonderful things about WordPress is the ability to have different levels of people all working on the web site. This is done by setting users with different levels of authorization. WordPress does this with a system that is actually quite generic. From a standard installation you get these roles:

  Admin
  Editor
  Author
  Contributor
  Subscriber
  and of course non-logged in consumers of your website.

This system can be extended to many other authorization schemes, such as a Members Only Section, Paid Subscription Content, special subwebsites for individuals to create pages, different groups of people collaborating on content independent of one another.

These roles are actually made up of capabilities. So a subscriber role has capabilities of Can Read Posts and Can edit Profile. The following is chart of capabilities assigned to the standard roles.

Standard Roles
Capability Admin Editor Author Contributor Subscriber
Add/Edit/Delete Plugins X
Add/Edit/Delete Users X
Add/Edit/Delete Themes X
Import/Export X
Install Updates X
Manage Comments X X
Manage Categories/Tags X X
Manage Links X X
Edit Any Post/Page X X
Publish/Delete Any Post/Page X X
Read/Edit Private Post/Page X X
Edit Own Published Posts X X X
Upload files X X X
Publish Posts X X X
Delete Own Posts X X X
Edit Draft Posts X X X X
Delete Draft Posts X X X X
Read Posts/Pages X X X X X
Edit Your Profile X X X X X

You can find more information on the meanings of each capability in the Codex at Codex Roles & Capabilites

Restricting Access to Pages and Posts

  1. You can password protect a Post or Page
  2. You can create a Page Template that checks to see if the user is logged in
  3. You can use a Plugin

Password protecting a page

Open a post/page for editing, you'll find Visibility under the Publish box. This contains an option to specify Password Protect.

Create a Page Template

Copy the index.php file to index-protected.php Then add a template header, like below:

 <?php
   /*
      Template Name: Protected Content
   */
  ?>

Then, after the wp_header, and before the wp_footer where everything is being displayed, i.e. before the loop, add the following:

   <?php 
        if (! is_user_logged_in()) {
             print "Sorry this is protected content\n";
        } else {
           /* the loop */
        }

Now you can select Protected Content as the template for a page and it will be protected. Note this is for pages only, not posts.

Plugins

  1. Members - A simple way to look at and create Roles and Capabilities and protect a page/post based on roles.
  2. Capabilities Manager Enhanced - Allows creation of Roles/Capabilities and has a nice layout for viewing this information. Does NOT provide page/post protection. This is Part of a larger system of plugins called Press Permit.
  3. User Access Manager - adds protection for pages/posts/categories/menu listings, etc. If you need special Roles/Capabilities you'll need something to create them, i.e. Members or Capabilities Manager Enhanced.
  4. S2 Members - Good plugin for pay subscription content protection. The Pro version has many payment gateway interfaces including Paypal Pro and Authorize.net, and the company is very active in support forums and has good customer service.
  5. Role Scoper - Lots of capabilities, but a bit difficult to set up. Written by the person that wrote Press Permit. It's very powerful, but can be confusing. Be sure to reserve plenty of time to play with the various options it provides before deploying it.
  6. Advanced Access Manager - Lots of options. All your setup is done within an AAM dashboard, so it's a little counter intuitive. Make backups before playing with it, powerful but a bit confusing.
  7. Press Permit - by Agapetry This is a set of plugins that will probably do everything you could want in the way of permissions. It is by the maker of Role Scoper and isn't a free solution. It is complex and there isn't much documentation at this point in time. There is a support forum and the author answers lots of questions. As with AAM, if you want something this complex please set aside some time to play with it and understand it.

Getting Started with Roles and Capabilities

I'd recommend installing Members. It's a straight forward way to be able to look at roles and what capabilities make them up. Use the Codex to get a more complete definition of what a capability means. Install other plugins, such as ecommerce plugins and take a look at what roles they add and how those roles are constructed.

Why do we care?

Understanding that Roles are made up of a set of Capabilities will help you out if you wind up having odd permission problems with a plugin or a theme.

Understanding roles can help you understand how WordPress functions. For example: when you login into the Dashboard WordPress builds the page you see one piece at at time, asking what capability does this piece of the dashboard require, and does the current user have that capability. This is why the dashboard looks so different for a subscriber than for an admin.

For Developers

Roles and Capabilities are useful tools for theme and plugin developers. Here are a couple of good pointers to get started.

  1. Roles_and_Capabilities The Codex on Roles and Capabilites
  2. The Ultimate Guide to Roles and Capabilites

Functions that are helpful:

  1. add_role - Add a role to the master list of Roles
  2. get_role - Get the current user's Role
  3. remove_role - Remove a role from the master list of Roles
  4. add_cap - Add a capability to a Role or a User.
  5. remove_cap - Remove a capability from a Role or a User.
  6. current_user_can - Checks if the currently logged in user has a particular capability.

Useful classes: WP_Role, WP_Roles, WP_User