Secure Client Portal
A secure client portal for uploading and managing files with access control and server-side validation
★ 0stars
0forks
Install
No release zip yet. The repository archive installs, but the folder name will carry the branch suffix and updates will not flow:
wp plugin install https://github.com/wsiddhi/secure-client-portal/archive/refs/heads/main.zipA robust, secure document exchange system built for WordPress, configured with Role-Based Access Control (RBAC), auditing, and REST API integration. Designed to facilitate secure file sharing between administrators and specific clients.
🚀 Key Features
- Role-Based Access Control (RBAC): Custom
client_userrole ensures strict separation of privileges. - Secure Document Vault:
- Files are protected via WordPress nonces.
- Strict MIME type validation.
- Isolated storage logic (Media Library integration with strict ownership metadata).
- Granular Permissions: Clients can strictly access and manage only their own documents.
- Audit Logging: Custom MySQL table (
wp_scp_activity_logs) tracks system operations (Upload, Delete) for compliance. - Developer API: Fully functional REST API endpoints for external integrations.
- Modern UI: Shortcode-based frontend dashboard with a responsive/modern UI.
🛠️ Technical Architecture
- Language: PHP 8
- Platform: WordPress Core API
- Database: Custom SQL Schema (
dbDeltaimplementation) - Design Patterns: Singleton Pattern (
SCP_Plugin::instance()) for resource management. - Security:
wp_verify_noncefor CSRF protection.current_user_canvsuser_canfor capability checks.- Prepared queries used where applicable (e.g., REST logs); inserts use
$wpdb->insert().
📂 Project Structure
secure-client-portal/
├── includes/
│ ├── class-scp-plugin.php # Main singleton, lifecycle hooks, and initialization
│ ├── class-scp-logger.php # Database logging service
│ └── class-scp-rest.php # REST API controller (Endpoints & Validation)
├── public/
│ ├── assets/
│ │ └── scp.css # Frontend styling
│ ├── class-scp-shortcodes.php # UI rendering logic
│ └── class-scp-actions.php # Form handlers (Upload/Delete)
├── secure-client-portal.php # Bootstrapper
└── README.md
🔧 Installation & Setup
- Deploy: Upload the
secure-client-portalfolder towp-content/plugins/. - Activate: Enable the plugin via the WordPress Admin dashboard. This will:
- Create the
client_userrole. - Provision the
wp_scp_activity_logsdatabase table.
- Create the
- Configure Pages: Create two new pages and embed the following shortcodes:
- Dashboard:
[client_dashboard] - Documents:
[client_documents]
- Dashboard:
- User Setup: create a new user and assign them the Client User role.
🔌 API Endpoints
The plugin exposes a secure REST API for headless integrations:
| Method | Endpoint | Description | Permission |
|---|---|---|---|
GET |
/wp-json/scp/v1/documents |
Retrieve current user's documents | client_user OR administrator |
GET |
/wp-json/scp/v1/logs |
Fetch system audit logs (supports ?limit=50) |
manage_options (Admin) |