Access Control

The General → Access Control page controls access to the WordPress Dashboard and protected pages on the front end of your website.

You can hide the WordPress Admin bar for selected roles, prevent those roles from accessing normal wp-admin screens, automatically protect HMDIA Account pages, and require users to sign in before viewing other selected pages.

Access Control


WordPress Admin Access

The WordPress Admin access section controls which user roles can access the WordPress Dashboard and see the Admin bar on the front end.

Add User Role

Select a WordPress role and click Add role to restrict it.

Selected roles appear underneath as individual tags. Click the × beside a role to remove its restriction.

For each selected role, HMDIA does two things:

  • Hides the WordPress Admin bar on the front end.
  • Blocks access to normal wp-admin Dashboard screens.

 

For example, in the screenshot the following roles are restricted:

  • Editor
  • Author
  • Contributor
  • Code Snippets Editor
  • Customer
  • Subscriber

 

Where Restricted Users Are Sent

If a restricted user attempts to open a normal WordPress Dashboard page, HMDIA redirects them to the published HMDIA Account page.

If no published Account page is available, the user is redirected to the website’s Home page instead.

Administrators Are Protected

Administrators always retain access to the WordPress Dashboard.

HMDIA also protects super administrators and users with administrative manage_options permission from being locked out by this setting.

Background WordPress Requests Continue Working

This restriction applies to normal Dashboard screens. HMDIA does not block necessary background endpoints such as AJAX, form handlers, uploads, REST requests and scheduled tasks.

This allows front-end forms and other WordPress functionality to continue working normally.

Default Setting

On a fresh installation, HMDIA selects the site’s existing non-Administrator roles by default.

Remove a role from the list if you want users with that role to keep their normal WordPress Dashboard access.

Front-End Page Access

The Front-end page access section protects private pages on the public side of your website.

HMDIA applies these rules on the server before the protected page is rendered.

HMDIA Account Pages Are Automatically Protected

You do not need to manually add your HMDIA Account page to Additional protected pages.

HMDIA automatically requires sign-in for:

  • The page assigned as the HMDIA Account page.
  • Pages containing the main HMDIA Account shortcode.
  • Pages containing HMDIA Account-section shortcodes.

 

All signed-in users can access their HMDIA Account area.

The role restriction under Who can access additional pages does not apply to Account pages.

Authentication Pages Remain Public

HMDIA keeps authentication entry pages public so visitors can reach the forms required to access their accounts.

This includes HMDIA:

  • Login
  • Registration
  • Password Reset

 

The independently selected WordPress login destination is also kept public.

These pages are excluded from Additional protected pages to prevent login and redirect loops.

Additional Protected Pages

Use Additional protected pages to protect other published WordPress pages.

Open the selector and choose one or more pages. Selected pages appear underneath as removable tags.

You can also search the list when your website contains many pages.

For example, you could protect:

  • Member content
  • Customer resources
  • Private downloads
  • Internal dashboards
  • Client-only pages

 

Only published WordPress pages are available for selection.

HMDIA Account and authentication pages are excluded because their access behavior is managed automatically.

Who Can Access Additional Pages

Choose who is allowed to view the pages selected under Additional protected pages.

There are two options.

Any Logged-In User

Any authenticated WordPress user can access the selected protected pages.
Visitors who are not signed in must first authenticate.
This is the option selected in your screenshot.

Selected User Roles

Choose this option when only certain WordPress roles should be allowed to access the selected pages.

A role selector appears so you can add the permitted roles.

For example, you could allow:

  • Customer
  • Subscriber

 

while preventing other roles from viewing those pages.

You must select at least one allowed role when using Selected user roles. Otherwise, HMDIA will not save the role-restricted page configuration.

Administrator Access

Administrators and super administrators always retain access to protected pages.

Important

Role restrictions apply only to Additional protected pages.

They do not restrict access to the user’s HMDIA Account page.

When a Signed-Out Visitor Opens a Protected Page

Choose what HMDIA should do when someone who is not signed in attempts to visit a protected page.

Two options are available.

Redirect to the Login Page

The visitor is redirected to the site’s login page.

HMDIA uses the published HMDIA Login page when available and safely falls back to the configured WordPress login flow when necessary.

This is the option selected in your screenshot.

Show an Access-Denied Message

Instead of redirecting, HMDIA displays the configured Access-denied message and returns an HTTP 403 Forbidden response.

A signed-out visitor is also given a Sign in link.

What Happens to a Signed-In User Without Permission?

If Selected user roles is enabled and a signed-in user does not have one of the permitted roles, HMDIA does not redirect that user back to the Login page.

Instead, HMDIA shows the Access-denied message with a secure 403 Forbidden response.

This prevents redirect loops for users who are already authenticated but do not have permission to view the page.

Return Users to the Requested Page After Sign-In

Enable Return users to the requested page after sign-in to remember which protected page a signed-out visitor originally attempted to open.

For example:

  1. A visitor opens a protected Downloads page.
  2. HMDIA sends the visitor to the Login page.
  3. The visitor successfully signs in.
  4. HMDIA returns the user to Downloads, provided that user has permission to access it.

This works with the HMDIA authentication flow, including supported Pro authentication steps such as 2FA.

Redirect Priority

The requested protected page takes priority over the normal general After sign-in redirect.

However, a configured role-specific sign-in redirect has higher priority and can send the user to the destination assigned to their role instead.

Access-Denied Message

Use Access-denied message to customize the message shown when access to a protected page is denied.

The default message is:

You must be signed in and permitted to access this page.

This message is displayed when:

  • Show an access-denied message is selected for signed-out visitors, or
  • A signed-in user does not have an allowed role.

If the field is left empty, HMDIA restores its default access-denied message.

Example Configuration

Using the settings shown in your screenshot:

WordPress Admin access
Editor, Author, Contributor, Code Snippets Editor, Customer and Subscriber cannot access normal WordPress Dashboard screens and do not see the front-end Admin bar.

Additional protected pages
My Account is shown as selected in the screenshot; however, HMDIA Account pages are automatically protected by the plugin and normally do not need to be added manually.

Who can access additional pages
Any logged-in user

Any authenticated user can view the additional protected pages.

Signed-out visitor behavior
Redirect to the login page

Visitors must sign in before accessing a protected page.

Return after sign-in
Enabled

After successfully signing in, an authorized user is returned to the protected page they originally requested.

Access-denied message
You must be signed in and permitted to access this page.

That message is used when HMDIA needs to display a 403 access-denied screen.