Dreamfox Client Edit Mode

Descripción

Dreamfox Client Edit Mode is built for agencies and freelancers who deliver WordPress sites and then hand them over. Your client gets a restricted Client Editor role: they can update text, swap images and change links on exactly the pages you assign — and nothing else. Layout, styling and page structure are locked, and the lock is enforced on the server, not just hidden in the editor UI.

How it works

  1. Protect the pages the client may edit.
  2. Assign one or more Client Editor users to those pages.
  3. Choose per page (and optionally per user) whether text, images and links may be changed.

Every save by a Client Editor is compared against the stored page by a permission diff engine: only allowed changes go through. Adding, removing, moving or restyling elements is rejected with a clear message — the layout you delivered cannot be broken.

Server-side enforcement

The editor UI is locked down for the role (content-only editing, no style panels, no block inserter), but that is comfort, not the security. The real protection runs on the server on every save route:

  • The block editor’s REST save — rejected with a clear per-violation error in the editor.
  • Classic admin saves and XML-RPC — a late wp_insert_post_data guard.
  • Page-level access — map_meta_cap pins Client Editors to their assigned protected pages; everything else (including deleting and creating posts) is denied.
  • Elementor-built pages — Client Editors can open the Elementor editor, and saving plus direct _elementor_data writes are validated the same way as everywhere else.

What the client sees

  • A simplified admin: a My Pages screen with an Edit button per assigned page, irrelevant menus and toolbar items hidden.
  • An optional “Edit this page” toolbar link on their assigned pages.
  • Clear error messages when a change is not allowed, instead of a broken layout.

What you keep

  • Every allowed change creates a normal WordPress revision — nothing is ever overwritten without a trace.
  • An activity log of allowed and blocked saves (summaries only: element IDs and attribute names, never full content, never IP addresses), with configurable retention.
  • Text / image / link permissions per page, with per-user overrides.

Built by Dreamfox Media. Guides and frequently asked questions are in the knowledge base; need help? Contact support.

Capturas de pantalla

Instalación

  1. Upload the plugin files to /wp-content/plugins/dreamfox-client-edit-mode, or install through the WordPress plugins screen.
  2. Activate the plugin through the ‘Plugins’ screen.
  3. Open Client Edit in the admin menu, protect a page and assign a Client Editor.
  4. Create client users under Users Add New with the “Client Editor” role.

FAQ

Is the protection just hidden editor buttons?

No. The editor UI is locked for the role, but every save is additionally validated on the server against the stored page. Even a hand-crafted REST API request with a Client Editor’s credentials cannot add, remove, move or restyle elements — the whole save is rejected with a 403 and a list of violations.

What exactly can a Client Editor change?

Only what you allow per page, in three categories: text (headings, paragraphs, button labels …), images (replace an image, its alt text or caption) and links (URLs and link targets). Layout, styling, element structure and everything else is always locked. You can override the three categories per user.

What happens when a Client Editor tries something that is not allowed?

The save is rejected as a whole — no partial merge — and the editor shows a clear message explaining what was not allowed. The attempt is recorded in the activity log.

Does it work with Elementor?

Yes. Client Editors can open the Elementor editor on their assigned pages, and every save (plus direct _elementor_data writes) is validated against the same text/image/link rules as the block editor.

How many pages can I protect?

As many as you like — there is no limit.

Are changes traceable?

Yes, twice over: every allowed save creates a regular WordPress revision (so you can compare and restore), and the activity log records who changed what, when, linked to that revision — plus every blocked attempt.

A block I added later is not editable for the client. Why?

Blocks get a persistent internal ID when a page is protected. Blocks added afterwards do not have one yet and are read-only for Client Editors until you press Re-sync IDs on the Protected Pages screen.

Which hooks can developers use?

  • dreamfox_client_edit_permissions — filter the permission set used for a protected page.
  • dreamfox_client_edit_can_modify — filter a single per-element/attribute permission decision (structural changes never reach this filter; they are always denied).
  • dreamfox_client_edit_allowed_attributes — classify attributes of custom blocks/widgets into the text / image / link / layout / style / advanced categories.
  • dfce_protected_post_types — post types guarded by the block editor save guard (default: page, post).
  • dfce_save_blocked (action) — fires whenever an enforcement path blocks a save.

Where can I find documentation and support?

Does it delete my data on uninstall?

Not by default. Enable “Delete all plugin data when the plugin is uninstalled” under Client Edit Settings Advanced first if you want a clean removal. The Client Editor role itself is always removed on uninstall.

Reseñas

No hay reseñas para este plugin.

Colaboradores & Desarrolladores

“Dreamfox Client Edit Mode” es software de código abierto. Las siguientes personas han contribuido a este plugin.

Colaboradores

Traduce “Dreamfox Client Edit Mode” a tu idioma.

¿Interesado en el desarrollo?

Revisa el código, echa un vistazo al repositorio SVN, o suscríbete al registro de desarrollo por RSS .

Historial de cambios

1.0.3

  • Added the plugin icon, banner and screenshots for the WordPress.org plugin page.
  • Readme: added links to dreamfoxmedia.com and the knowledge base.

1.0.2

  • Remove all Pro feature gating: unlimited protected pages, Elementor editing and per-element permission rules are now standard, unrestricted functionality.
  • Move the “My Pages” admin menu item to the default (lower) position instead of a prominent top position.

1.0.1

  • Bump “Tested up to” to WordPress 7.1.
  • Trim short description to meet the wp.org 150 character limit.
  • Harden activity log queries with esc_sql() on the table name.

1.0.0

  • Initial release.
  • Client Editor role restricted to assigned protected pages (map_meta_cap).
  • Permission diff engine: server-side validation of every save (block editor REST, classic admin, XML-RPC, Elementor) with all-or-nothing rejection and per-violation messages.
  • Text / image / link permissions per page and per user; layout, styling and structure always locked.
  • Content-only block editor experience for the role; persistent block IDs with re-sync.
  • Simplified client dashboard (My Pages), pruned admin menus/toolbar, login redirect, frontend edit link.
  • Activity log with revision linking, configurable retention and daily cleanup.