WP Manifestindependent plugin directory
manifest / users / wordpress-hitobito-login

Hitobito Auth Codeberg

This plugin allows to authenticate users against Hitobito.

by Pfadi Laupen · codeberg.org/pfadilaupen/wordpress-hitobito-login · website

★ 0stars
0forks

Install

No release zip yet. The repository archive installs, but the folder name will carry the branch suffix and updates will not flow:

wp plugin install https://codeberg.org/pfadilaupen/wordpress-hitobito-login/archive/main.zip

This plugin allows to authenticate users against Hitobito. This plugin is based on OpenID Connect Generic Plugin for Wordpress.

Login & Role Mapping Flow

flowchart TD
    A["Login button"] --> B["Login via OpenID<br>(generic OpenID Connect flow —<br>authenticate, look up or create WP user)"]

    B -->|New user| C{"Role mapping<br>resolved?"}
    B -->|Existing user| D{"Role mapping<br>bypass set for<br>this user?"}

    D -->|Yes| E["Keep current<br>WP role(s)"]
    D -->|No| F{"Role mapping<br>resolved?"}

    C -->|No mapping found| G["Deny — creation blocked<br>(no matching mapping)"]
    C -->|Mapped to 'None'| H["Deny — access denied<br>(mapped to None)"]
    C -->|Valid role| I["Create WP user<br>with mapped role"]

    F -->|No mapping found| J{"'Update roles'<br>setting enabled?"}
    F -->|Mapped to 'None'| K["Deny — access denied<br>(mapped to None,<br>roles unchanged)"]
    F -->|Valid role| L{"'Update roles'<br>setting enabled?"}

    J -->|Yes| M["Strip all WP roles"] --> N["Deny — no matching mapping<br>(roles cleared)"]
    J -->|No| E

    L -->|Yes| O["Apply mapped role(s)"] --> P["Logged in"]
    L -->|No| E

    I --> P
    E --> P

    G --> Q["Login error"] --> A
    H --> Q
    K --> Q
    N --> Q

Devcontainer

For the first use you have to setup the container. This may take a while.

docker compose up -d
docker compose exec app /bin/sh
# Enter this in the docker shell:
bash .devcontainer/setup.sh

If the container is running you can access the Wordpress instance here: http://localhost:8080/
Use the following credentials to login:
User: admin
Password: password