Hey guys, thank you so much for this plugin! I would like to do a feature request.
Could you please add an option to link OAuth2-authenticated users to existing WordPress accounts by username (user_login), similar to the existing “Link OIDC/CAS accounts to WordPress accounts by their username” settings?
Current behavior
For OAuth2 SSO, Authorizer always looks up existing WordPress users by email:
- In
custom_authenticate(), only CAS and OIDC support link_on_username.
- OAuth2 always uses
get_user_by( 'email', ... ).
- If no user is found, a new account is created using the OAuth2 username (from
oauth2_attr_username or derived from email).
So oauth2_attr_username affects new user creation, but not matching existing users.
Expected behavior
Add an OAuth2 setting (e.g. oauth2_link_on_username) that, when enabled:
- Looks up existing WordPress users with
get_user_by( 'login', $result['username'] ) instead of (or before) email matching.
- Mirrors the existing OIDC/CAS behavior and admin UI pattern.
- Works per OAuth2 server when multiple servers are configured (e.g.
oauth2_link_on_username_2).
Use case
We have existing WordPress users whose user_login matches the IdP username, but whose stored email may differ from the email returned by the OAuth2 provider. Today, OAuth2 login creates duplicate accounts instead of linking to the existing user.
OIDC and CAS already support username-based linking for this scenario; OAuth2 does not, even though the plugin already extracts a username from the OAuth2 response.
Suggested implementation
- Add checkbox in OAuth2 settings (same label/help text pattern as OIDC/CAS).
- Extend the
link_on_username logic in class-authentication.php to include authenticated_by === 'oauth2'.
- Register/sanitize the new option like
oidc_link_on_username / cas_link_on_username.
- Email-based linking should remain the default (documented as more secure).
Hey guys, thank you so much for this plugin! I would like to do a feature request.
Could you please add an option to link OAuth2-authenticated users to existing WordPress accounts by username (
user_login), similar to the existing “Link OIDC/CAS accounts to WordPress accounts by their username” settings?Current behavior
For OAuth2 SSO, Authorizer always looks up existing WordPress users by email:
custom_authenticate(), only CAS and OIDC supportlink_on_username.get_user_by( 'email', ... ).oauth2_attr_usernameor derived from email).So
oauth2_attr_usernameaffects new user creation, but not matching existing users.Expected behavior
Add an OAuth2 setting (e.g.
oauth2_link_on_username) that, when enabled:get_user_by( 'login', $result['username'] )instead of (or before) email matching.oauth2_link_on_username_2).Use case
We have existing WordPress users whose
user_loginmatches the IdP username, but whose stored email may differ from the email returned by the OAuth2 provider. Today, OAuth2 login creates duplicate accounts instead of linking to the existing user.OIDC and CAS already support username-based linking for this scenario; OAuth2 does not, even though the plugin already extracts a username from the OAuth2 response.
Suggested implementation
link_on_usernamelogic inclass-authentication.phpto includeauthenticated_by === 'oauth2'.oidc_link_on_username/cas_link_on_username.