{"id":353598,"date":"2026-08-23T04:23:24","date_gmt":"2026-08-23T04:23:24","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/user-drive\/"},"modified":"2026-08-23T04:18:15","modified_gmt":"2026-08-23T04:18:15","slug":"haq-member-document-drive","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/haq-member-document-drive\/","author":14236429,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"2.1.0","stable_tag":"2.1.0","tested":"7.1","requires":"6.0","requires_php":"7.4","requires_plugins":null,"header_name":"HAQ Member Document Drive","header_author":"Husain Ahmed","header_description":"Private, permission controlled file drive for approved members. Administrators create folders, grant per-folder view, upload and create rights to each member, and review registrations, deletion requests and activity logs from the WordPress admin.","assets_banners_color":"","last_updated":"2026-08-23 04:18:15","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"","rating":0,"author_block_rating":0,"active_installs":0,"downloads":53,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"2.1.0":{"tag":"2.1.0","author":"husainahmedqureshi","date":"2026-08-23 04:18:15"}},"upgrade_notice":{"2.1.0":"<p>Addresses WordPress.org review feedback: text domain, unique prefixes and late escaping. Preferred shortcodes are now <code>[haqmedod_drive]<\/code> and related tags; previous <code>haq_drive*<\/code> shortcodes still work. Existing installs migrate options, meta and tables automatically.<\/p>","2.0.3":"<p>Renamed to HAQ Member Document Drive. Update shortcodes to <code>[haq_drive]<\/code>, <code>[haq_drive_login]<\/code>, <code>[haq_drive_register]<\/code>, <code>[haq_drive_lost_password]<\/code> and <code>[haq_drive_profile]<\/code>. Custom CSS and the member-role setting were removed; self-registered accounts are always Subscribers.<\/p>","2.0.2":"<p>WordPress.org Plugin Check compatibility fixes. No settings changes required.<\/p>","2.0.1":"<p>Security and permission fixes. Re-save HAQ Member Document Drive &gt; Settings once so storage protection rules refresh, and re-grant create-folder rights if members should create sub folders.<\/p>","2.0.0":"<p>Major security and structure update. Existing files and permissions are migrated automatically on the first load. Review HAQ Member Document Drive &gt; Settings afterwards, as several values that used to be hard coded are now configurable.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3661334,"resolution":"128x128","location":"assets","locale":"","width":297,"height":296}},"assets_banners":[],"assets_blueprints":{},"all_blocks":[],"tagged_versions":["2.1.0"],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[],"plugin_tags":[9054,5440,8848,1919,895],"plugin_category":[54,58],"plugin_contributors":[158224],"plugin_business_model":[],"class_list":["post-353598","plugin","type-plugin","status-publish","hentry","plugin_tags-documents","plugin_tags-downloads","plugin_tags-file-manager","plugin_tags-members","plugin_tags-permissions","plugin_category-security-and-spam-protection","plugin_category-user-management","plugin_contributors-husainahmedqureshi","plugin_committers-husainahmedqureshi"],"banners":[],"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/haq-member-document-drive\/assets\/icon-128x128.png?rev=3661334","icon_2x":false,"generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>HAQ Member Document Drive gives your site a private document area. Administrators create folders and decide, member by member and folder by folder, who may view, download, upload or create sub folders. Members sign in, see only the folders they were granted, and work with their own files.<\/p>\n\n<p>Files are stored outside the reach of the browser and are served through a permission check on every request, so a shared link is useless to anyone without rights to the folder.<\/p>\n\n<h4>For administrators<\/h4>\n\n<ul>\n<li>Create, rename and delete folders and sub folders.<\/li>\n<li>Upload files on behalf of members, rename them and remove them in bulk.<\/li>\n<li>Approve, reject or block each registration before the account can be used.<\/li>\n<li>Grant download, upload and create folder rights per member and per folder.<\/li>\n<li>Review and action account deletion requests.<\/li>\n<li>Browse a full activity log of uploads, downloads, renames and deletions, filter it and export it to CSV.<\/li>\n<li>Configure organisation name, notification addresses, upload limits, allowed file types and more from a single settings screen.<\/li>\n<\/ul>\n\n<h4>For members<\/h4>\n\n<ul>\n<li>Browse only the folders they have been granted.<\/li>\n<li>Download single files or select several and download them as one archive.<\/li>\n<li>Upload files by drag and drop, with a progress bar and clear error messages.<\/li>\n<li>Create sub folders where an administrator has granted that right.<\/li>\n<li>Edit their profile, change their password and request that their account be closed.<\/li>\n<\/ul>\n\n<h4>Privacy<\/h4>\n\n<p>The plugin stores the account status, profile details and per folder rights of each member, plus a log of the file actions they perform. Nothing is sent to any third party service by default.<\/p>\n\n<p>If you optionally enable Cloudflare Turnstile on the sign in and registration forms, those forms load a script from Cloudflare and each submission is verified with Cloudflare's siteverify API. This is an opt-in Software as a Service integration. See Cloudflare's <a href=\"https:\/\/www.cloudflare.com\/privacypolicy\/\">privacy policy<\/a> and <a href=\"https:\/\/www.cloudflare.com\/website-terms\/\">terms of use<\/a>.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>haq-member-document-drive<\/code> folder to <code>\/wp-content\/plugins\/<\/code>, or install the plugin through the Plugins screen in WordPress.<\/li>\n<li>Activate the plugin. The database tables, the protected storage directory and the four member pages are created for you.<\/li>\n<li>Go to <strong>HAQ Member Document Drive &gt; Settings<\/strong> and set your organisation name and notification email addresses.<\/li>\n<li>Go to <strong>HAQ Member Document Drive &gt; Folders<\/strong> and create your first folder.<\/li>\n<li>Go to <strong>HAQ Member Document Drive &gt; Members<\/strong> to approve accounts, then use <strong>Access rights<\/strong> to grant folder permissions.<\/li>\n<\/ol>\n\n<p>The four pages created on activation are My Drive, Sign In, Register and Reset Password. You can move the shortcodes to pages of your own and select them under <strong>Settings &gt; Pages<\/strong>.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"where%20are%20uploaded%20files%20kept%3F\"><h3>Where are uploaded files kept?<\/h3><\/dt>\n<dd><p>In <code>wp-content\/uploads\/haq-member-document-drive<\/code> by default. The plugin writes an <code>.htaccess<\/code> file, a <code>web.config<\/code> file and an <code>index.php<\/code> file into that directory so the files cannot be fetched directly. Every download goes through a WordPress request that checks the member's rights and a one-time nonce first.<\/p><\/dd>\n<dt id=\"what%20if%20my%20server%20ignores%20.htaccess%3F\"><h3>What if my server ignores .htaccess?<\/h3><\/dt>\n<dd><p>Move the storage directory somewhere outside your web root by defining <code>HAQMEDOD_STORAGE_DIR<\/code> in <code>wp-config.php<\/code> with an absolute path. The plugin will use it and the files will be unreachable by URL regardless of server configuration. This is the recommended setup on nginx and similar hosts.<\/p><\/dd>\n<dt id=\"can%20i%20allow%20any%20file%20type%3F\"><h3>Can I allow any file type?<\/h3><\/dt>\n<dd><p>You can choose which extensions members may upload under <strong>Settings &gt; Uploads<\/strong>. Executable and script types such as <code>php<\/code>, <code>phtml<\/code>, <code>exe<\/code>, <code>sh<\/code>, <code>phar<\/code> and <code>svg<\/code> can never be allowed; they are rejected even if you add them to the list. Uploads are also checked so that a renamed executable cannot pass on its extension alone.<\/p><\/dd>\n<dt id=\"which%20shortcodes%20are%20available%3F\"><h3>Which shortcodes are available?<\/h3><\/dt>\n<dd><ul>\n<li><code>[haqmedod_drive]<\/code> \u2014 the member drive.<\/li>\n<li><code>[haqmedod_profile]<\/code> \u2014 profile, password and account closure.<\/li>\n<li><code>[haqmedod_login]<\/code> \u2014 sign in form.<\/li>\n<li><code>[haqmedod_register]<\/code> \u2014 registration form.<\/li>\n<li><code>[haqmedod_lost_password]<\/code> \u2014 password reset form.<\/li>\n<\/ul>\n\n<p>Legacy aliases <code>[haq_drive]<\/code>, <code>[haq_drive_profile]<\/code>, <code>[haq_drive_login]<\/code>, <code>[haq_drive_register]<\/code> and <code>[haq_drive_lost_password]<\/code> still work.<\/p><\/dd>\n<dt id=\"do%20new%20members%20get%20access%20straight%20away%3F\"><h3>Do new members get access straight away?<\/h3><\/dt>\n<dd><p>No. A new registration is held as pending and cannot sign in until an administrator approves it. If you would rather not review each one, clear <strong>Hold new accounts until an administrator approves them<\/strong> under <strong>Settings &gt; Membership<\/strong>.<\/p><\/dd>\n<dt id=\"i%20am%20upgrading%20from%20version%201.x.%20will%20i%20lose%20anything%3F\"><h3>I am upgrading from version 1.x. Will I lose anything?<\/h3><\/dt>\n<dd><p>No. On the first load after upgrading, the plugin moves existing uploads into the protected directory and converts the old per member access data to the new format. Your folders, files and logs are kept.<\/p><\/dd>\n<dt id=\"what%20happens%20to%20my%20data%20if%20i%20delete%20the%20plugin%3F\"><h3>What happens to my data if I delete the plugin?<\/h3><\/dt>\n<dd><p>Nothing is removed unless you ask for it. Deactivating never deletes anything. If you want the tables, files, options and member data cleared, tick <strong>Delete all folders, files, logs and settings when the plugin is deleted<\/strong> in the settings before you delete the plugin.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>2.1.0<\/h4>\n\n<ul>\n<li>Compliance: text domain is now <code>haq-member-document-drive<\/code> (matches the plugin slug).<\/li>\n<li>Compliance: unique <code>haqmedod<\/code> \/ <code>HAQMEDOD_<\/code> prefixes for classes, options, hooks, meta, AJAX, cache group and capabilities.<\/li>\n<li>Compliance: late escaping with <code>esc_*<\/code> \/ <code>wp_kses<\/code> on echoed output (Plugin Check EscapeOutput).<\/li>\n<li>Shortcodes: preferred tags are <code>[haqmedod_drive]<\/code>, <code>[haqmedod_login]<\/code>, <code>[haqmedod_register]<\/code>, <code>[haqmedod_lost_password]<\/code> and <code>[haqmedod_profile]<\/code> (legacy <code>haq_drive*<\/code> aliases kept).<\/li>\n<li>Upgrade: automatic migration from former <code>udrv_*<\/code> \/ <code>user_drive*<\/code> options, meta, tables and capabilities.<\/li>\n<\/ul>\n\n<h4>2.0.3<\/h4>\n\n<ul>\n<li>Distinctive plugin name: HAQ Member Document Drive. Text domain matches the plugin slug (<code>haq-member-document-drive<\/code>).<\/li>\n<li>Security: public registration always creates Subscriber accounts; the member-role setting was removed.<\/li>\n<li>Security: removed the Custom CSS setting so the plugin no longer stores or outputs arbitrary CSS.<\/li>\n<li>Contributors list now uses the WordPress.org username.<\/li>\n<\/ul>\n\n<h4>2.0.2<\/h4>\n\n<ul>\n<li>Compatibility: passed WordPress.org Plugin Check blockers for review-ready packaging.<\/li>\n<li>Fixed: translators comment placement for Cloudflare policy links in settings.<\/li>\n<li>Fixed: Cloudflare Turnstile loads via <code>wp_enqueue_script()<\/code> when the optional captcha is enabled (required Cloudflare API host).<\/li>\n<li>Security: tightened sanitization of AJAX\/profile input and clarified nonce-verified upload handling.<\/li>\n<li>Database: direct queries now use <code>$wpdb-&gt;prefix<\/code> (or <code>esc_sql()<\/code>) in line with Plugin Check guidance.<\/li>\n<li>Removed: manual <code>load_plugin_textdomain()<\/code> call (WordPress.org loads translations automatically).<\/li>\n<li>Removed: discouraged <code>set_time_limit()<\/code> usage during downloads.<\/li>\n<\/ul>\n\n<h4>2.0.1<\/h4>\n\n<ul>\n<li>Security: storage protection rules are rewritten when settings are saved, and removed when protection is turned off.<\/li>\n<li>Security: download links now require a nonce in addition to folder rights.<\/li>\n<li>Security: SVG and SVGZ uploads are refused by default as forbidden types.<\/li>\n<li>Security: registration no longer reveals whether an email address is already registered.<\/li>\n<li>Fixed: Settings can be saved by users who hold the drive management capability.<\/li>\n<li>Fixed: members with the create folders right can create sub folders and inherit access on them.<\/li>\n<li>Accessibility \/ i18n: admin prompts are localised; Cloudflare Terms of Use linked in settings and readme.<\/li>\n<li>Packaging: removed placeholder Plugin URI \/ Author URI; added directory index.php files; updated Tested up to.<\/li>\n<\/ul>\n\n<h4>2.0.0<\/h4>\n\n<ul>\n<li>Rewritten as a standard WordPress plugin with an autoloader, a settings screen and admin pages for every feature.<\/li>\n<li>Added: database tables are created and upgraded automatically on activation.<\/li>\n<li>Added: settings for organisation name, notification addresses, membership rules, upload limits, allowed file types, logging, Cloudflare Turnstile and page assignments.<\/li>\n<li>Added: activity log filtering and CSV export.<\/li>\n<li>Added: full translation support and a <code>haq-member-document-drive.pot<\/code> template.<\/li>\n<li>Added: opt in data removal on uninstall.<\/li>\n<li>Added: automatic migration of files and access data from 1.x.<\/li>\n<li>Changed: uploads are stored in a protected directory and served through a permission check instead of being publicly reachable.<\/li>\n<li>Changed: the front end is rendered by shortcodes rather than page templates, so it works with any theme.<\/li>\n<li>Changed: assets are local and dependency free; the bundled jQuery copy, Bootstrap and CDN requests are gone.<\/li>\n<li>Security: every AJAX endpoint now verifies a nonce and checks capabilities and folder rights.<\/li>\n<li>Security: all database queries are prepared and all output is escaped.<\/li>\n<li>Security: allowed file types are an allowlist, executable types are refused outright and file contents are checked against the extension.<\/li>\n<li>Security: download archives are built in the system temp directory instead of the web root.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release.<\/li>\n<\/ul>","raw_excerpt":"A private, permission controlled file drive for approved members. Share documents with the right people and keep everything else out of reach.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/353598","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=353598"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/husainahmedqureshi"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=353598"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=353598"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=353598"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=353598"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=353598"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=353598"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}