Skip to content

Feature request: Link OAuth2 accounts to WordPress users by username (user_login) #203

Description

@mateuswetah

Hey guys, thank you so much for this plugin! I would like to do a feature request.

Could you please add an option to link OAuth2-authenticated users to existing WordPress accounts by username (user_login), similar to the existing “Link OIDC/CAS accounts to WordPress accounts by their username” settings?

Current behavior

For OAuth2 SSO, Authorizer always looks up existing WordPress users by email:

  • In custom_authenticate(), only CAS and OIDC support link_on_username.
  • OAuth2 always uses get_user_by( 'email', ... ).
  • If no user is found, a new account is created using the OAuth2 username (from oauth2_attr_username or derived from email).

So oauth2_attr_username affects new user creation, but not matching existing users.

Expected behavior

Add an OAuth2 setting (e.g. oauth2_link_on_username) that, when enabled:

  1. Looks up existing WordPress users with get_user_by( 'login', $result['username'] ) instead of (or before) email matching.
  2. Mirrors the existing OIDC/CAS behavior and admin UI pattern.
  3. Works per OAuth2 server when multiple servers are configured (e.g. oauth2_link_on_username_2).

Use case

We have existing WordPress users whose user_login matches the IdP username, but whose stored email may differ from the email returned by the OAuth2 provider. Today, OAuth2 login creates duplicate accounts instead of linking to the existing user.

OIDC and CAS already support username-based linking for this scenario; OAuth2 does not, even though the plugin already extracts a username from the OAuth2 response.

Suggested implementation

  • Add checkbox in OAuth2 settings (same label/help text pattern as OIDC/CAS).
  • Extend the link_on_username logic in class-authentication.php to include authenticated_by === 'oauth2'.
  • Register/sanitize the new option like oidc_link_on_username / cas_link_on_username.
  • Email-based linking should remain the default (documented as more secure).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions