5. Gotchas we hit

Written by

in

  • Wallet addresses are blank for most people. WoofID only shares wallet addresses when that session was signed in with the wallet itself. That’s a deliberate WoofID security rule.
  • The login plugin retries login_required. Without woof-key intercepting the callback first, a failed silent check would bounce the visitor onto the full WoofID login page.
  • No return trip after sign-out. Self-service WoofID apps can’t register a page to come back to after sign-out, so sign-out ends on WoofID’s own page.
  • No PKCE needed. The plugin doesn’t support PKCE, and WoofID doesn’t require it from apps that have a client secret.
  • Wallet-only accounts have no email. WordPress needs one, so woof-key fills in a placeholder at users.woofid.invalid.
  • Break-glass admin. The password form is hidden. Maintainers reach it at /wp-login.php?woof-local=1.