Download the PHP package kodansha/wack-preview without Composer
On this page you can find all versions of the php package kodansha/wack-preview. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Download kodansha/wack-preview
More information about kodansha/wack-preview
Files in kodansha/wack-preview
Package wack-preview
Short Description Helpers to make it possible to preview posts on frontend.
License GPL-3.0-or-later
Homepage https://github.com/kodansha/wack-preview
Informations about the package wack-preview
WACK Preview
WACK Preview is a WordPress plugin that helps you to implement a preview system for unpublished drafts on your frontend application.
How it works
Originally designed for use with the WACK Stack, this plugin can also be used with other decoupled, headless WordPress setups that use separate frontend applications, such as those utilizing the REST API or WPGraphQL.
This plugin replaces the default permalinks and preview links for posts (and other custom post types) generated by WordPress.
Preview links are generated with a JWT token as a parameter. By verifying this JWT using the same secret key on your frontend application, you can ensure the token was legitimately generated by WordPress. This lets you securely fetch data before it is published.
Installation
- Requires PHP 8.2 or later
- Requires WordPress 6.9 or later
- Requires Composer
Using Composer
[!NOTE] This plugin is not available on the WordPress.org plugin repository. The only installation method currently available is through Composer.
Configuration
To use WACK Preview, you need to configure URL mappings for displaying pages on the frontend. Additionally, you must set up a secret token for preview URLs.
You can configure these settings using one of the following methods:
- Define settings with the
WACK_PREVIEW_SETTINGSconstant - Configure settings through the WordPress admin menu
Setting via WACK_PREVIEW_SETTINGS constant
Define WACK_PREVIEW_SETTINGS in functions.php or similar:
[!NOTE] For each post type,
publishandpreviewcan be configured independently. Ifpreviewis not set for a post type butpublishis, preview links will be rewritten using thepublishpath (with the preview token appended as a query parameter), instead of being left as WordPress's default preview link. If neitherpublishnorpreviewis set, the original link is left unchanged.[!NOTE] The secret_key is used to sign tokens with HMAC-SHA256 (HS256). A minimum length of 32 bytes is required. Using a shorter key will result in a fatal error at runtime. Generate a sufficiently long random value with a command such as
openssl rand -hex 32.[!NOTE] On multisite WordPress installations, the WACK_PREVIEW_SETTINGS constant does not function as expected. In such cases, configure settings individually for each site using the admin menu.
Setting via WordPress admin menu
Navigate to the WACK Preview settings screen in the WordPress admin menu and follow the on-screen instructions.
[!TIP] If settings are defined in both the
WACK_PREVIEW_SETTINGSconstant and the admin menu, the constant's settings will take precedence. This allows flexible configuration - for example, you could define only thesecret_keyas a constant (keeping it out of the database) while managing other settings through the admin screen.
Preview token payload
The preview token is a JWT token that contains the following payload:
This means that the frontend application can verify the token is valid for the
specified post by checking the sub field.
API
wack_preview_verify_token
This is a utility function provided as a convenient API. It can be used in WordPress themes to verify preview tokens and control access to unpublished posts.
It returns true if the token is valid, false otherwise.