
內容簡介
AuthLatch 幫助網站擁有者用安全的無密碼登入取代傳統的密碼登入方式,提供便捷且安全的使用者驗證體驗。
【主要功能】
• 一次性魔法連結,限時且單次使用
• WebAuthn/FIDO2 的密碼金鑰登入
• 自助式 AuthLatch 側邊欄頁面
• 使用者可新增、撤銷及命名自己的密碼金鑰
• 角色基礎的密碼金鑰存取限制
• 管理員生成的登入連結,選擇性 IP 綁定
外掛標籤
開發者團隊
原文外掛簡介
AuthLatch helps site owners replace routine password logins with secure passwordless access.
Key features:
One-time magic links requested by username or email, with expiry and one-use tokens.
Passkey login using WebAuthn/FIDO2.
Self-service AuthLatch sidebar page for selected user roles.
Users can add, revoke, and name their own passkeys.
Users can send a magic login link to their own account email.
Per-role passkey access and per-user passkey limits.
Branded responsive login screen with method tabs for magic links, passkeys, and password fallback.
Single active session control.
Admin-generated login links with optional IP binding and auto logout.
Admin-scoped login links that can block selected admin menus for that session.
Built-in SMTP settings for hosts where PHP mail delivery is disabled.
Audit log for important authentication events.
RTL-friendly login UI.
AuthLatch stores magic-link validators as hashes, verifies passkeys server-side, and uses WordPress capabilities, nonces, sanitization, and escaping throughout the admin interface.
Setup
Magic links
Enable Magic links in AuthLatch > Settings.
Set the default link expiry.
Configure the email subject and body.
Configure SMTP if the host disables PHP mail.
Users can request a login link from the login page with either username or email.
Enabled self-service roles can also send a login link from AuthLatch in the admin sidebar.
Passkeys
Enable Passkeys in AuthLatch > Settings.
Select the roles allowed to use passkeys.
Set the maximum passkeys per user.
Use HTTPS on the live site.
Users with allowed roles can open AuthLatch in the admin sidebar and click Add passkey.
Users can revoke old passkeys from the same page.
Self-service sidebar page
Open AuthLatch > Settings.
Select roles under Self-Service Page > Sidebar access roles.
Only selected roles will see the AuthLatch sidebar page.
The self-service page lets users manage their own passkeys and send a magic link to their own email.
Password fallback
Keep Username/password login enabled if normal WordPress login should remain available.
Keep admin password fallback enabled if administrators should still be able to log in with a password when password login is otherwise disabled.
SMTP
Enable Use SMTP for WordPress emails.
Enter host, port, encryption, username, password, from email, and from name.
Save settings.
Send a test email from AuthLatch > Settings.
Privacy
AuthLatch stores authentication-related records in the WordPress database, including hashed magic-link tokens, passkey public-key data, hashed IP values for audit and optional IP binding, and configuration settings. AuthLatch does not store plaintext magic-link validators. SMTP passwords are encrypted with WordPress salts before storage.
Third-Party Libraries
AuthLatch includes the MIT-licensed lbuchs/WebAuthn library for WebAuthn/FIDO2 server-side verification.
