Contents
Hooks reference - Plugixa Advanced User Role Editor
The plugin fires 14 actions and 9 filters, all prefixed plugixa_aure_. Two of
the actions exist only in Pro and are marked PRO.
The plugin has no front end, so every hook here runs in the admin, in a REST request, in WP-CLI or in a scheduled task.
The ones you are most likely to want
| Hook | Type | What it is for |
|---|---|---|
plugixa_aure_written |
action | React to any change to a role or a person, with the state before and after |
plugixa_aure_capability_owner |
filter | Tell the editor that a permission belongs to your plugin, and give it a readable label |
plugixa_aure_capability_severity |
filter | Mark one of your permissions as dangerous |
plugixa_aure_role_templates |
filter | Add or remove starting points in the new-role wizard |
plugixa_aure_count_role_users |
filter | Switch off head counts on a site with a very large number of users |
Actions
Lifecycle
plugixa_aure_loaded
Fires once the plugin has finished starting, on plugins_loaded.
| Parameter | Type | Meaning |
|---|---|---|
$container |
PlugixaAure\Core\Container |
The plugin’s service container |
add_action( 'plugixa_aure_loaded', function ( $container ) {
// The role editor is present and booted.
} );
plugixa_aure_activated
Fires when the plugin is activated, after its tables and capabilities are in place. The plugin itself uses it to take the first restore point. No parameters.
add_action( 'plugixa_aure_activated', function () {
// Runs once per activation.
} );
plugixa_aure_deactivated
Fires when the plugin is deactivated, before its scheduled events are cleared. No parameters.
add_action( 'plugixa_aure_deactivated', function () {
wp_clear_scheduled_hook( 'my_addon_task' );
} );
plugixa_aure_fs_loaded
Fires when the Freemius SDK, which handles licensing and updates, has been loaded. It does not fire on a copy of the plugin that has no SDK. No parameters.
add_action( 'plugixa_aure_fs_loaded', function () {
// The licensing SDK is available.
} );
Admin and REST
plugixa_aure_admin_submenus
Fires straight after the plugin registers its admin menu page, so more submenu pages can be added under it.
| Parameter | Type | Meaning |
|---|---|---|
$parent_slug |
string | The parent menu slug, plugixa-aure |
$render |
callable | The callback that renders the app’s container |
add_action( 'plugixa_aure_admin_submenus', function ( $parent_slug, $render ) {
add_submenu_page( $parent_slug, 'My page', 'My page', 'manage_options', 'my-page', 'my_page_render' );
}, 10, 2 );
plugixa_aure_enqueue_assets
Fires on the plugin’s own admin screen, once the app’s scripts are enqueued. It does not fire on any other admin page.
| Parameter | Type | Meaning |
|---|---|---|
$hook_suffix |
string | The admin page being rendered |
add_action( 'plugixa_aure_enqueue_assets', function ( $hook_suffix ) {
wp_enqueue_script( 'my-addon', plugins_url( 'addon.js', __FILE__ ), array(), '1.0.0', true );
} );
plugixa_aure_register_rest_routes
Fires on rest_api_init, after the plugin has registered its own routes. Use it
to add routes alongside them. See the
REST API.
| Parameter | Type | Meaning |
|---|---|---|
$namespace |
string | plugixa-aure/v1 |
$container |
PlugixaAure\Core\Container |
The plugin’s service container |
add_action( 'plugixa_aure_register_rest_routes', function ( $namespace ) {
register_rest_route( $namespace, '/my-addon', array(
'methods' => 'GET',
'callback' => 'my_addon_route',
'permission_callback' => fn () => current_user_can( 'plugixa_aure_view' ),
) );
} );
Changes to roles and people
These two fire from every path that writes: the screens, a restore, an import, the rescue link, the background role move and WP-CLI.
plugixa_aure_before_write
Fires immediately before a role or a person is changed. The plugin listens to it at priority 5 to take the restore point, so a callback at the default priority runs after the restore point exists and before the change is written.
| Parameter | Type | Meaning |
|---|---|---|
$operation |
string | What is about to be written. See the table below |
$target |
string | The role slug, permission or account id it applies to |
add_action( 'plugixa_aure_before_write', function ( $operation, $target ) {
error_log( "About to write {$operation} on {$target}" );
}, 10, 2 );
Besides the operations in the table below, this action also fires once with
changes.apply when a set of reviewed changes is saved together. Its $target
is a comma-separated list such as role:editor,user:12.
plugixa_aure_written
Fires after a change has been saved.
| Parameter | Type | Meaning |
|---|---|---|
$operation |
string | What was written |
$target |
string | The role slug, permission or account id |
$before |
array | The state beforehand |
$after |
array | The state afterwards |
$context |
array | Anything else the writer recorded. Often empty |
$operation |
$target |
$before and $after |
$context |
|---|---|---|---|
role.create |
Role slug | Empty, then name and capabilities |
|
role.rename |
Role slug | name in each |
|
role.delete |
Role slug | name and capabilities, then empty |
reassigned_to, users_moved |
role.capabilities |
Role slug | The role’s permission map in each | granted, revoked, denied, cleared |
capability.purge |
Permission | roles it was removed from, then empty |
|
user.roles |
Account id | roles in each, in order |
|
user.capabilities |
Account id | The account’s own permission map in each | |
user.rescue |
Account id | roles in each |
via is rescue_link |
users.migrate |
from -> to |
role in each |
mode, changed |
In a permission map, true is granted and false is blocked.
add_action( 'plugixa_aure_written', function ( $operation, $target, $before, $after, $context ) {
if ( 'user.roles' === $operation ) {
my_addon_sync_roles( (int) $target, $after['roles'] );
}
}, 10, 5 );
Saved settings and rules
Each of these fires after a save, and only when something actually changed. All pass the same two parameters.
| Parameter | Type | Meaning |
|---|---|---|
$before |
array | The stored value before the save |
$after |
array | The stored value after it |
| Action | Fires after |
|---|---|
plugixa_aure_settings_saved |
The plugin’s settings change |
plugixa_aure_module_flags_saved |
A feature is switched on or off in Settings. The arrays map feature id to on or off |
plugixa_aure_redirects_saved |
The redirect rules change |
plugixa_aure_menu_rules_saved PRO |
The Admin menu rules are saved or undone |
plugixa_aure_admin_cleanup_saved PRO |
The Screen clean-up rules are saved or undone |
The two Pro actions fire on every save of their screen, whether or not the rules differ.
add_action( 'plugixa_aure_settings_saved', function ( $before, $after ) {
if ( $before['snapshot_retention'] !== $after['snapshot_retention'] ) {
// The number of restore points to keep was changed.
}
}, 10, 2 );
// Pro only.
add_action( 'plugixa_aure_menu_rules_saved', function ( $before, $after ) {
foreach ( $after['roles'] as $role => $rule ) {
// $rule['mode'] is 'hide' or 'allow'; $rule['items'] is a list of menu keys.
}
}, 10, 2 );
Filters
plugixa_aure_capability_owner
Claims permissions for the plugin that registered them. A claimed permission is listed with that owner, can carry its own label and description in place of ones made from its slug, and is not treated as a leftover that can be removed from every role.
| Parameter | Type | Meaning |
|---|---|---|
$owners |
array | Permission slug to owner. The value is the owner’s name, or an array with owner and optionally label and description |
add_filter( 'plugixa_aure_capability_owner', function ( $owners ) {
$owners['view_bookings'] = array(
'owner' => 'Bookings Pro',
'label' => __( 'See every booking', 'bookings-pro' ),
);
return $owners;
} );
plugixa_aure_capability_severity
Changes how dangerous a permission is considered to be. The tiers are
critical, high, medium and none. A permission the plugin itself rates
critical cannot be lowered, and a value that is not one of the four tiers is
ignored.
| Parameter | Type | Meaning |
|---|---|---|
$severity |
string | The tier worked out by the plugin |
$cap |
string | The permission slug |
add_filter( 'plugixa_aure_capability_severity', function ( $severity, $cap ) {
return 'manage_bookings_settings' === $cap ? 'high' : $severity;
}, 10, 2 );
plugixa_aure_count_role_users
Whether the plugin counts how many people hold each role. Return false on a
site where counting is too slow. Head counts then show as unknown instead of a
number, including in the review of unsaved changes.
| Parameter | Type | Meaning |
|---|---|---|
$enabled |
bool | Whether to count. Default true |
add_filter( 'plugixa_aure_count_role_users', '__return_false' );
plugixa_aure_role_templates
Adds, removes or changes the starting points offered when
creating a role.
Each template is an array with id, label, description, requires,
levels and grant.
| Parameter | Type | Meaning |
|---|---|---|
$templates |
array | The list of templates, before the plugin works out which are available on this site |
// Take the SEO manager template out of the wizard.
add_filter( 'plugixa_aure_role_templates', function ( $templates ) {
return array_values( array_filter(
$templates,
fn ( $template ) => 'seo-manager' !== $template['id']
) );
} );
plugixa_aure_health_findings
Filters the findings of the
Health check
before they are sorted. Each finding is an array with id, severity (risk,
warning or notice), title, detail, remedy and context.
| Parameter | Type | Meaning |
|---|---|---|
$findings |
array | The findings so far |
// This site has one administrator on purpose.
add_filter( 'plugixa_aure_health_findings', function ( $findings ) {
return array_values( array_filter(
$findings,
fn ( $finding ) => 'single_administrator' !== $finding['id']
) );
} );
plugixa_aure_settings_defaults
Filters the default values of the plugin’s settings. Stored settings still win over defaults.
| Parameter | Type | Meaning |
|---|---|---|
$defaults |
array | show_deprecated (false), show_administrator (false), confirm_dangerous (true), snapshot_retention (30), delegate_roles (empty) |
add_filter( 'plugixa_aure_settings_defaults', function ( $defaults ) {
$defaults['snapshot_retention'] = 60;
return $defaults;
} );
plugixa_aure_admin_i18n_strings
Filters the translated strings sent to the admin app. Keys are string ids, values are the text.
| Parameter | Type | Meaning |
|---|---|---|
$strings |
array | String id to text |
add_filter( 'plugixa_aure_admin_i18n_strings', function ( $strings ) {
$strings['my_addon_title'] = __( 'My add-on', 'my-addon' );
return $strings;
} );
plugixa_aure_modules
Filters the list of feature classes the plugin loads. An add-on uses it to
contribute a feature of its own without living inside the plugin’s folder. A
class that does not exist, or does not implement
PlugixaAure\Core\Modules\ModuleInterface, is skipped.
It runs while the plugin boots on plugins_loaded, so add the filter before
then.
| Parameter | Type | Meaning |
|---|---|---|
$classes |
string[] | Fully-qualified class names |
add_filter( 'plugixa_aure_modules', function ( $classes ) {
$classes[] = \MyAddon\Module::class;
return $classes;
} );
plugixa_aure_current_restore_point
Asks which restore point covers the changes made in the current request. The
plugin answers it itself; read it with apply_filters() after a write rather
than adding a callback. The answer is 0 when no restore point has been taken in
this request.
| Parameter | Type | Meaning |
|---|---|---|
$id |
int | The restore point’s id. Starts at 0 |
add_action( 'plugixa_aure_written', function () {
$restore_point = (int) apply_filters( 'plugixa_aure_current_restore_point', 0 );
} );
What to do next
- Call the plugin from a script instead: REST API.
- See what the guardrails refuse before writing an integration: Safety guardrails.
- Record every change these actions announce: Activity log PRO.