Roles and Capabilities in WordPress
One of the wonderful things about WordPress is the ability to have different levels of people all working on the web site. This is done by setting users with different levels of authorization. WordPress does this with a system that is actually quite generic. From a standard installation you get these roles:
Admin Editor Author Contributor Subscriber and of course non-logged in consumers of your website.
This system can be extended to many other authorization schemes, such as a Members Only Section, Paid Subscription Content, special subwebsites for individuals to create pages, different groups of people collaborating on content independent of one another.
These roles are actually made up of capabilities. So a subscriber role has capabilities of Can Read Posts and Can edit Profile. The following is chart of capabilities assigned to the standard roles.
| Capability | Admin | Editor | Author | Contributor | Subscriber |
|---|---|---|---|---|---|
| Add/Edit/Delete Plugins | X | ||||
| Add/Edit/Delete Users | X | ||||
| Add/Edit/Delete Themes | X | ||||
| Import/Export | X | ||||
| Install Updates | X | ||||
| Manage Comments | X | X | |||
| Manage Categories/Tags | X | X | |||
| Manage Links | X | X | |||
| Edit Any Post/Page | X | X | |||
| Publish/Delete Any Post/Page | X | X | |||
| Read/Edit Private Post/Page | X | X | |||
| Edit Own Published Posts | X | X | X | ||
| Upload files | X | X | X | ||
| Publish Posts | X | X | X | ||
| Delete Own Posts | X | X | X | ||
| Edit Draft Posts | X | X | X | X | |
| Delete Draft Posts | X | X | X | X | |
| Read Posts/Pages | X | X | X | X | X |
| Edit Your Profile | X | X | X | X | X |
You can find more information on the meanings of each capability in the Codex at Codex Roles & Capabilites
Restricting Access to Pages and Posts
- You can password protect a Post or Page
- You can create a Page Template that checks to see if the user is logged in
- You can use a Plugin
Password protecting a page
Open a post/page for editing, you'll find Visibility under the Publish box. This contains an option to specify Password Protect.
Create a Page Template
Copy the index.php file to index-protected.php Then add a template header, like below:
<?php
/*
Template Name: Protected Content
*/
?>
Then, after the wp_header, and before the wp_footer where everything is being displayed, i.e. before the loop, add the following:
<?php
if (! is_user_logged_in()) {
print "Sorry this is protected content\n";
} else {
/* the loop */
}
Now you can select Protected Content as the template for a page and it will be protected. Note this is for pages only, not posts.