Chuyển đến phần nội dung
WordPress.org

tiếng Việt

  • Giao diện
  • Plugin
  • Tin tức
    • Tài liệu hướng dẫn
    • Diễn đàn
  • Giới thiệu
  • Facebook #WPVN
  • Tải WordPress
Tải WordPress
WordPress.org

Plugin Directory

WP One Tap Google Sign In

  • Gửi một plugin
  • Yêu thích của tôi
  • Đăng nhập
  • Gửi một plugin
  • Yêu thích của tôi
  • Đăng nhập

WP One Tap Google Sign In

Bởi Sunil Kumar Sharma
Tải về
  • Chi tiết
  • Đánh giá
  • Cài đặt
  • Nhà phát triển
Hỗ trợ

Mô tả

WP One Tap Google Sign In adds Google One Tap authentication to WordPress. It helps site owners offer a faster, passwordless login experience while keeping authentication tied to existing WordPress user accounts.

When a visitor signs in with Google, the plugin verifies the Google ID token server-side, checks the configured OAuth client ID, confirms the Google email is verified, and then signs in the matching WordPress user. The plugin also supports site-wide display for logged-out visitors, a customizable companion message block, and direct Google account linking from WordPress user profiles.

Key Features

  • Google One Tap prompt on the WordPress login screen.
  • Optional site-wide One Tap prompt for logged-out visitors.
  • Server-side Google ID token verification with WordPress HTTP APIs.
  • Existing-user login only by default.
  • Google account linking and disconnect controls on WordPress user profiles.
  • Automatic account-link migration after a successful verified email login.
  • Admin activity log for successful logins, failed attempts, account linking, and unlinking events.
  • Salted hashes for IP addresses and Google account identifiers in the activity log.
  • Optional custom message block with image, title, and formatted content.
  • WordPress 7.0-ready metadata with PHP 8.1, 8.2, and 8.3 compatibility.

Security Approach

The plugin uses WordPress nonces for AJAX requests, sanitizes all incoming data, escapes admin output, and validates the Google token audience against the configured OAuth client ID. It does not create new users automatically. A Google login succeeds only when the verified Google account maps to an existing WordPress user.

Privacy

The activity log stores the Google email address used during an event, the WordPress user ID when available, event status, event reason, user agent, and salted hashes of the request IP address and Google account identifier. Activity records older than 90 days are pruned automatically when new events are logged.

Configuration

Create a Google OAuth Client ID

  1. Open the Google Cloud Console credentials page:
    https://console.developers.google.com/apis/credentials
  2. Create an OAuth 2.0 Client ID.
  3. Choose Web application as the application type.
  4. Add your WordPress site’s authorized JavaScript origin.
  5. Copy the client ID into Settings > One Tap GSI.

Link a WordPress User to Google

  1. Open Users > Profile for your own account, or edit another user if your role allows it.
  2. Find the Google One Tap Sign-In section.
  3. Use the Google button to link a verified Google account.
  4. To disconnect, check Disconnect this Google account and save the profile.

Customize the Message Block

  1. Go to Settings > One Tap GSI.
  2. Enable the custom message block.
  3. Choose an image from the Media Library or enter an image URL.
  4. Add a short title and supporting formatted content.
  5. Save the settings.

Ảnh màn hình

One Tap Google Sign In settings.
One Tap Google Sign In settings.
Google One Tap sign-in prompt on the WordPress login screen.
Google One Tap sign-in prompt on the WordPress login screen.

Cài đặt

  1. Upload the wp-one-tap-google-sign-in folder to the /wp-content/plugins/ directory.
  2. Activate the plugin through the Plugins screen in WordPress.
  3. Go to Settings > One Tap GSI.
  4. Enter your Google OAuth 2.0 Web application client ID.
  5. Confirm that your site’s login URL is allowed in your Google OAuth application configuration.
  6. Choose whether One Tap should appear only on the login page or site-wide for logged-out visitors.
  7. Add optional custom message content if you want supporting copy beside the One Tap prompt.

Hỏi đáp

Does this plugin create new WordPress users?

No. WP One Tap Google Sign In signs in existing WordPress users only. It does not automatically register new users.

Can users disconnect their Google account?

Yes. Users can disconnect the linked Google account from their WordPress profile. Administrators with permission to edit users can also manage the link for other accounts.

What happens if a user changes their Google email address?

After account linking, the plugin uses Google’s stable account identifier for future logins. This is more reliable than email-only matching.

Where can I view login attempts?

Go to Settings > One Tap GSI Activity to review recent sign-in, linking, and unlinking events.

Does the plugin store raw IP addresses?

No. The plugin stores a salted hash of the request IP address for correlation in security reviews.

Is this compatible with WordPress 7.0 and modern PHP?

The plugin metadata targets WordPress 7.0 and PHP 8.1 or higher. The code avoids dynamic properties, deprecated Google client dependencies, and older PHP patterns that commonly cause warnings on PHP 8.2 and PHP 8.3.

Đánh giá

Không có đánh giá nào cho plugin này.

Người đóng góp & Lập trình viên

“WP One Tap Google Sign In” là mã nguồn mở. Những người sau đã đóng góp vào plugin này.

Những người đóng góp
  • Sunil Kumar Sharma

Dịch “WP One Tap Google Sign In” sang ngôn ngữ của bạn.

Muốn tham gia phát triển?

Duyệt code, check out SVN repository, hoặc theo dõi nhật ký phát triển qua RSS.

Nhật ký thay đổi

1.2.1

  • [Changed] Raised the minimum PHP requirement to 8.1 for production readiness on PHP 8.1, 8.2, and 8.3.
  • [Changed] Updated Composer and WordPress.org metadata to match the PHP 8.1+ support policy.
  • [Fixed] Updated package metadata for PHP 8.1+ and Google API client compatibility.

1.2.0

  • [Added] Google account linking and disconnect controls on WordPress user profiles.
  • [Added] Admin activity log for login, failed login, link, and unlink events.
  • [Added] Automatic account-link migration after successful verified email login.
  • [Changed] Reworked runtime token verification to use WordPress HTTP APIs.
  • [Changed] Updated plugin ownership metadata to Sunil Kumar Sharma, sunilkumarthz, and wpsimplified.in.
  • [Changed] Expanded WordPress.org readme documentation with setup, security, privacy, and FAQ details.
  • [Security] Uses Google’s stable account identifier after linking and stores IP/Google identifiers as salted hashes in the audit log.

1.1.0

  • [Added] Declared WordPress 7.0, PHP 7.4, and modern Composer package requirements.
  • [Changed] Reworked script loading to use wp_enqueue_script() for the Google Identity Services client and stable plugin asset versions.
  • [Changed] Updated admin settings text, escaping, sanitization, and localization for WordPress Coding Standards.
  • [Fixed] Corrected login AJAX responses to use structured JSON instead of raw strings.
  • [Security] Added AJAX nonce verification, stricter Google ID token validation, audience checks, and verified-email enforcement before setting WordPress auth cookies.

1.0.1

  • Initial public release.

Meta

  • Phiên bản 1.2.1
  • Cập nhật lần cuối 3 tháng trước
  • Số lượt cài đặt 10+
  • Phiên bản WordPress 7.0 hoặc cao hơn
  • Đã kiểm tra lên đến 7.0.4
  • Phiên bản PHP 8.1 hoặc cao hơn
  • Ngôn ngữ
    English (US)
  • Thẻ
    authenticationGoogle Logingoogle one tappasswordless loginwordpress login
  • Nâng cao

Đánh giá

Chưa có đánh giá nào được gửi.

Your review

Xem tất cả đánh giá

Những người đóng góp

  • Sunil Kumar Sharma

Hỗ trợ

Có điều gì muốn nói? cần giúp đỡ?

Xem diễn đàn hỗ trợ

Ủng hộ

Bạn có muốn hỗ trợ vào sự phát triển của plugin này?

Ủng hộ plugin này

  • Giới thiệu
  • Tin tức
  • Lưu trữ
  • Quyền riêng tư
  • Trưng bày
  • Giao diện
  • Plugin
  • Mẫu khối
  • Học hỏi
  • Hỗ trợ
  • Nhà phát triển
  • WordPress.tv ↗
  • Tham gia
  • Sự kiện
  • Quyên góp ↗
  • Swag ↗
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org
WordPress.org

tiếng Việt

  • Truy cập tài khoản X (trước đây là Twitter) của chúng tôi
  • Visit our Bluesky account
  • Visit our Mastodon account
  • Visit our Threads account
  • Xem trang Facebook của chúng tôi
  • Truy cập tài khoản Instagram của chúng tôi
  • Truy cập tài khoản LinkedIn của chúng tôi
  • Visit our TikTok account
  • Truy cập kênh YouTube của chúng tôi
  • Visit our Tumblr account
Viết code như làm thơ.
The WordPress® trademark is the intellectual property of the WordPress Foundation.