=== Teydea Password Reset - Force Password Reset & Expiration ===
Contributors: teydeastudio, bartoszgadomski
Tags: reset password, force password change, WordPress security, password enforcement, secure login
Requires at least: 6.6
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 1.13.0
License: GPLv3
License URI: https://www.gnu.org/licenses/gpl-3.0.html
Plugin URI: https://teydeastudio.com/?utm_source=Teydea+Password+Reset

Easily enforce password reset for WordPress users. Choose to force password changes site-wide, by user and/or by role, to boost your site's security.

== Description ==

**Enhance your WordPress website's security by forcing users to reset their passwords.**

Teydea Password Reset is a simple yet powerful security plugin that allows site administrators to require users to update their passwords—ideal after a potential data breach, routine security checks, or during onboarding/offboarding processes.

== Features ==

- **Force password reset for all users**, specific user roles, or individual users.
- **Optional email notification** to users with a direct reset link.
- **Flexible login behavior**:
  - *Allow login before resetting*: users log in with the old password, are immediately prompted to set a new one.
  - *Block login until reset*: users must reset their password before accessing the dashboard.
- **Choose reset timing**:
  - *Immediately*: forces logout and password reset on next login.
  - *After session expiry*: users are asked to reset after their current session ends.
- **WP-CLI support** for command-line password management and automation.
- **Multisite compatible** (network-wide reset only).
- Optimized for performance on large-scale and enterprise WordPress installations.

== Use Cases ==

- Responding to a **security breach** or suspected compromise.
- Enforcing **routine password changes** in corporate environments.
- Applying **onboarding/offboarding security policies** for teams or membership sites.

== Compatibility ==

- Works on both single-site and multisite (network) WordPress setups.
- Supports PHP 7.4+ and WordPress 6.6 through 7.1.
- Compatible with modern WordPress admin experience.

== Screenshots ==

1. Settings page: force a password reset for all users, choose whether to email the reset link, whether the current password may be used to start the reset, and when the reset takes effect.
2. Targeted coverage: turn "All users" off to apply the reset to selected roles and individual users, with a live count of how many users will be affected.
3. Users screen: a "Password Reset Enforced?" column, plus a "Force Password Reset and Logout" row action and matching bulk action.
4. Processing: the action runs in batches with a live progress indicator, so large user bases can be handled in one pass.

== Installation ==

1. Upload the plugin to the `/wp-content/plugins/` directory or install via the WordPress admin panel.
2. Activate the plugin.
3. Go to **Settings → Password Reset** to initiate resets.

== WP-CLI Commands ==

This plugin provides WP-CLI commands for automated password reset management:

**Force Password Reset**
`wp password-reset-enforcement force [--to_all] [--to_roles=<roles>] [--to_users=<user_ids>] [--applicability=<when>] [--with_email] [--with_current_password_allowed] [--limit=<number>] [--paged=<page>]`

**Clear Password Reset Enforcement**
`wp password-reset-enforcement clear [--to_all] [--to_roles=<roles>] [--to_users=<user_ids>] [--limit=<number>] [--paged=<page>]`

**List Users with Enforced Password Reset**
`wp password-reset-enforcement list [--limit=<number>] [--paged=<page>]`

**Check Password Reset Status**
`wp password-reset-enforcement status [--to_all] [--to_roles=<roles>] [--to_users=<user_ids>] [--limit=<number>] [--paged=<page>]`

= Command Options =

- `--to_all`: Target all users on the site
- `--to_roles=<roles>`: Comma-separated list of user roles (e.g., editor,administrator)
- `--to_users=<user_ids>`: Comma-separated list of specific user IDs (e.g., 1,5,10)
- `--applicability=<when>`: When reset takes effect (immediately, after_session_expiry)
- `--with_email`: Send email notifications to affected users (default: true)
- `--with_current_password_allowed`: Allow users to reuse current password (default: false)
- `--limit=<number>`: Maximum users to process in single operation
- `--paged=<page>`: Page number for pagination

= Command Examples =

`wp password-reset-enforcement force --to_all`
`wp password-reset-enforcement force --to_roles=editor,administrator --applicability=after_session_expiry`
`wp password-reset-enforcement clear --to_users=1,5,10`
`wp password-reset-enforcement list --limit=50 --paged=2`
`wp password-reset-enforcement status --to_all --limit=50 --paged=2`

== Related Plugins ==

Want to go beyond forced password resets? Check our [Teydea Login Security](https://teydeastudio.com/plugins/login-security/?utm_source=Teydea+Password+Reset) plugin to enforce strong password rules, block weak passwords, and set automatic expiry policies. The [free version is available on WordPress.org](https://wordpress.org/plugins/password-requirements/).

== Frequently Asked Questions ==

= Will this log users out immediately? =
Only if you choose the “Immediately” option. Otherwise, users will be asked to reset after their current session expires.

= Is it compatible with other login plugins or 2FA solutions? =
Yes, Teydea Password Reset is designed for compatibility and works well alongside popular authentication and security plugins.

= Can I use this on a WooCommerce site? =
Absolutely. Works seamlessly with WooCommerce and other membership or eCommerce platforms.

= Does this plugin support WP-CLI? =
Yes! The plugin includes comprehensive WP-CLI commands for forcing password resets, clearing enforcement, and checking status. Perfect for automation, server management, and bulk operations.

= Where can I find the unminified source code? =
All source ships with the plugin: the plugin's own JavaScript is in `src/`, and the bundled `@teydeastudio/components` and `@teydeastudio/utils` libraries are in `deps/js/components/src/` and `deps/js/utils/src/`. To rebuild, install Node.js 20 and run `npm install && npm run build` in the plugin directory.

== Changelog ==

= 1.13.0 (2026-08-28) =
* Plugin renamed to "Teydea Password Reset"; the settings screen now lives under Settings → Password Reset
* Compatibility with WordPress 7.1 confirmed
* Plugin icon, banners, and screenshots refreshed
* Accessibility improvements on the settings page form controls
* The forced reset action is now held back while the affected-users count is unknown or still loading, instead of acting on an unreliable count
* Faster plugin loading - the class map file is now read once per request instead of on every class the autoloader resolves
* Dependencies updated
* Code improvements

= 1.12.1 (2026-06-22) =
* Security hardening: per-target authorization check added to the Force Password Reset row and bulk actions (defense-in-depth)
* Added a clear admin notice for unmet server requirements (minimum PHP/WordPress version, required extensions)
* Accessibility improvements on the settings page and the Users-screen reset indicator
* Reliability improvements to the forced password reset flow
* Dependencies updated
* Code improvements

= 1.12.0 (2026-04-16) =
* Compatibility with WordPress 7.0 confirmed
* Direct access protection added to all PHP files
* Unnecessary translation files removed since these are loaded from WordPress.org
* Security hardening - added missing escaping
* Do not hardcode `wp-login.php` path for login form
* Formatting updates
* Dependencies updated

= 1.11.1 (2025-11-28) =
* Compatibility with WordPress 6.9 confirmed
* Dependencies updated

= 1.11.0 (2025-10-31) =
* Direct links to force password reset have been added to the Users page along with bulk action
* Clear indicators that a password reset has been enforced for a given user have been added to the Users and User Profile screens
* User selector component has been improved
* WP-CLI commands have been added, allowing power users to force password reset, clear the enforcement, check the status, and list users for whom the password reset has been enforced
* Dependencies updated
* Code improvements

= 1.10.2 (2025-05-08) =
* Plugin links and references to Teydea Studio updated
* Dependencies updated

= 1.10.1 (2025-04-04) =
* Compatibility with WordPress 6.8 confirmed
* Issue of requesting the translated string too early fixed
* Dependencies updated
* Code improvements

= 1.10.0 (2025-02-21) =
* Dependencies updated
* Code improvements

= 1.9.0 (2024-12-13) =
* Dependencies updated
* Code improvements

= 1.8.0 (2024-11-08) =
* Custom capabilities for managing the plugin settings implemented
* Compatibility with WordPress 6.7 confirmed
* Dependencies updated
* Code improvements

(For older records, see the `changelog.txt` file).
