WP Manifestindependent plugin directory
manifest / users / one-time-links-v2-wp-plugin

ICET One-Time Registration Links v3

Protects /registration/ with one-time token+NIC. Allows refresh in same tab, blocks new tabs/devices. Redirects invalid access to /link-expired/.

by sharada · github.com/sharada-marasinghe/one-time-links-v2-wp-plugin

★ 0stars
0forks

Install

No release zip yet. The repository archive installs, but the folder name will carry the branch suffix and updates will not flow:

wp plugin install https://github.com/sharada-marasinghe/one-time-links-v2-wp-plugin/archive/refs/heads/main.zip

ICET One-Time Registration Links (v2)

Generate NIC+token one-time links for /registration/. First valid visit consumes the token and redirects to a session URL to allow refreshing in the same browser. Public access to /registration/ is blocked. Admin can delete used records.

Description

  • Initial URL structure: /registration/?token=XXXX&nic=YYYY
  • First valid visit:
    • Validates NIC + token
    • Marks token as used
    • Creates a random session URL: /registration/session/{session_key}/
    • Redirects the user there
  • Refreshes of that session URL in the same browser are allowed.
  • Visiting /registration/ without a valid NIC+token is blocked/redirected.
  • Admin page shows generated links, session URLs, and a Delete action for cleanup.

Installation

  1. Upload icet-one-time-links-v2.zip via Plugins → Add New → Upload Plugin.
  2. Activate the plugin.
  3. Go to One-Time Links v2 menu.
  4. (Optional) Set Expired/Invalid Redirect URL (e.g., /link-expired/).

Settings

  • Protected Page Path (default /registration/).
  • Expired/Invalid Redirect URL to handle blocked/expired access.

Notes

  • Preventing use in a second tab of the same browser is technically constrained on the server. This plugin mitigates by exchanging the token for a secret session URL and tying it to the current PHP session. The original token URL cannot be reused.
  • If you use caching/CDN, bypass cache for /registration/ with ?token= and for /registration/session/*.