WP Manifestindependent plugin directory
manifest / users / secure-client-portal

Secure Client Portal

A secure client portal for uploading and managing files with access control and server-side validation

by Your Name · github.com/wsiddhi/secure-client-portal

★ 0stars
0forks

Install

No release zip yet. The repository archive installs, but the folder name will carry the branch suffix and updates will not flow:

wp plugin install https://github.com/wsiddhi/secure-client-portal/archive/refs/heads/main.zip

A robust, secure document exchange system built for WordPress, configured with Role-Based Access Control (RBAC), auditing, and REST API integration. Designed to facilitate secure file sharing between administrators and specific clients.

🚀 Key Features

  • Role-Based Access Control (RBAC): Custom client_user role ensures strict separation of privileges.
  • Secure Document Vault:
    • Files are protected via WordPress nonces.
    • Strict MIME type validation.
    • Isolated storage logic (Media Library integration with strict ownership metadata).
  • Granular Permissions: Clients can strictly access and manage only their own documents.
  • Audit Logging: Custom MySQL table (wp_scp_activity_logs) tracks system operations (Upload, Delete) for compliance.
  • Developer API: Fully functional REST API endpoints for external integrations.
  • Modern UI: Shortcode-based frontend dashboard with a responsive/modern UI.

🛠️ Technical Architecture

  • Language: PHP 8
  • Platform: WordPress Core API
  • Database: Custom SQL Schema (dbDelta implementation)
  • Design Patterns: Singleton Pattern (SCP_Plugin::instance()) for resource management.
  • Security:
    • wp_verify_nonce for CSRF protection.
    • current_user_can vs user_can for capability checks.
    • Prepared queries used where applicable (e.g., REST logs); inserts use $wpdb->insert().

📂 Project Structure

secure-client-portal/
├── includes/
│   ├── class-scp-plugin.php      # Main singleton, lifecycle hooks, and initialization
│   ├── class-scp-logger.php      # Database logging service
│   └── class-scp-rest.php        # REST API controller (Endpoints & Validation)
├── public/
│   ├── assets/
│   │   └── scp.css               # Frontend styling
│   ├── class-scp-shortcodes.php  # UI rendering logic
│   └── class-scp-actions.php     # Form handlers (Upload/Delete)
├── secure-client-portal.php      # Bootstrapper
└── README.md

🔧 Installation & Setup

  1. Deploy: Upload the secure-client-portal folder to wp-content/plugins/.
  2. Activate: Enable the plugin via the WordPress Admin dashboard. This will:
    • Create the client_user role.
    • Provision the wp_scp_activity_logs database table.
  3. Configure Pages: Create two new pages and embed the following shortcodes:
    • Dashboard: [client_dashboard]
    • Documents: [client_documents]
  4. User Setup: create a new user and assign them the Client User role.

🔌 API Endpoints

The plugin exposes a secure REST API for headless integrations:

Method Endpoint Description Permission
GET /wp-json/scp/v1/documents Retrieve current user's documents client_user OR administrator
GET /wp-json/scp/v1/logs Fetch system audit logs (supports ?limit=50) manage_options (Admin)