User Roles and Security

Updated

What it helps you do

Give clients and staff the access they need without letting them take over the site or add code to it.

The Manager role

Manager is the Dirigible theme's role for site owners. A Manager can edit all content, change site settings and the Customizer, and add, edit and remove users.

A Manager can't install, activate or edit plugins and themes. To keep it that way:

  • Assigning roles: a Manager can give users any role except Administrator.

  • Administrator accounts: a Manager can't edit, promote or delete Administrators.

  • New User Default Role: in Settings → General, a Manager can only pick a role they could give a user themselves. If the default role is ever set above them, new users they add get Subscriber instead. People who sign up on the site themselves also get Subscriber when the default role could change settings, manage users or add code (Administrator, Manager, Editor).

  • All Settings: the hidden All Settings screen (/wp-admin/options.php) is for Administrators only. Managers use the normal Settings screens.

  • Custom code: Managers can't use tools that run custom code, such as WP All Import. Ask an Administrator to run imports.

  • Plugins, themes and roles behind the scenes: a Manager's changes can't switch on a plugin, switch the theme, or give any role something the Manager can't do, even through another plugin's settings page.

Managers can still manage every other role, including other Managers, Editors, Authors and Shop Managers.

Search engine visibility: if the site is set to discourage search engines, the Dashboard's Welcome screen shows a warning. Managers and Administrators can click Let search engines index this site there to fix it.

Tools & Maintenance: Managers can use the audits and everyday tools there, such as Update blocks and Send test email. The tools that make sitewide or permanent changes only appear for Administrators: Find & replace, Forms → Entry cleanup, and applying fixes in Fix broken image references and Restore block settings from revisions.

Browser security headers

Every page tells browsers not to second-guess file types (X-Content-Type-Options: nosniff), and on live sites served over HTTPS, to keep using HTTPS (Strict-Transport-Security). Nothing changes for visitors; the headers close two well-known gaps that hosting doesn't cover. A developer can adjust them with the ds_security_headers filter.

Strong passwords for staff accounts

Anyone who can edit content or run the shop (Administrators, Managers, Editors, Authors, Contributors and Shop Managers) must choose a strong password when they set a new one:

  • Rules: at least 12 characters, not a common password (like Password123!), not mostly one character, and not based on their username, email, name or the site name. A passphrase of a few unrelated words works well.
  • Where it applies: the Profile and Edit User screens, Add New User, the "Lost your password?" reset form, and WooCommerce's Account details and password reset pages.
  • Weak password checkbox: the "Confirm use of weak password" box is hidden for these accounts.

Existing passwords keep working; nobody is forced to reset. Customers and Subscribers aren't affected, and saving a profile without touching the password fields works as before.

Usernames stay private

Password-guessing starts with a list of real usernames, so the site no longer hands them out to logged-out visitors:

  • Login messages: a wrong username and a wrong password get the same message, "The username, email address or password is incorrect." The "Lost your password?" form always says the email is on its way, whether or not the account exists. This applies on the WordPress login screen and on WooCommerce's My Account page.
  • Behind the scenes: the public user list in the site's API, the authors list in the sitemap, and author links in shared-post previews are hidden from logged-out visitors. Author pages still work.
  • Author page addresses: an author page used to be at /author/<username>/. It now uses the author's display name (like /author/jane-smith/), or author-<number> when the display name is the username or an email address. Old addresses redirect to the new ones. New accounts get the new style from the start. Usernames, emails and display names don't change.
  • Display name reminder: anyone whose public display name is still their username sees a reminder after logging in, linking to Profile → Display name publicly as.

Logged-in users, the block editor's author picker and WooCommerce checkout aren't affected.

Authors and Contributors

Authors and Contributors write content but can't add code to it:

  • Code in content: when they save, raw <iframe>, <style> and stylesheet <link> tags are removed. Embed videos and other media with the Embed blocks instead (paste the page's URL); those keep working.
  • Custom fields: they can't change theme and plugin fields through the Custom Fields panel. They can still edit those fields through the normal field boxes in the editor.

Editors, Managers and Administrators aren't affected. Content already on the site isn't changed; the limits apply when a page is saved.

Tips

  • If a client needs to add embed codes or custom scripts, make them an Editor, not an Author.