From 61494eceac057a65114ded5aea23a7628e6c86ab Mon Sep 17 00:00:00 2001 From: Bob Matyas <45246438+bobmatyas@users.noreply.github.com> Date: Wed, 23 Sep 2026 11:15:29 -0400 Subject: [PATCH] Account Protection: Do not activate by default on new connections Set the module's Auto Activate header to No so new Jetpack connections and upgrades no longer turn it on, and stop Jetpack Protect from activating it on plugin activation. Existing sites keep their current setting, since neither activation path deactivates modules. Co-Authored-By: Claude Opus 5.5 (1M context) --- ...update-account-protection-no-auto-activate | 4 ++ .../jetpack/modules/account-protection.php | 2 +- ..._Account_Protection_Auto_Activate_Test.php | 37 +++++++++++++++++++ ...update-account-protection-no-auto-activate | 4 ++ .../protect/src/class-jetpack-protect.php | 1 - 5 files changed, 46 insertions(+), 2 deletions(-) create mode 100644 projects/plugins/jetpack/changelog/update-account-protection-no-auto-activate create mode 100644 projects/plugins/jetpack/tests/php/general/Jetpack_Account_Protection_Auto_Activate_Test.php create mode 100644 projects/plugins/protect/changelog/update-account-protection-no-auto-activate diff --git a/projects/plugins/jetpack/changelog/update-account-protection-no-auto-activate b/projects/plugins/jetpack/changelog/update-account-protection-no-auto-activate new file mode 100644 index 000000000000..2a55700422e9 --- /dev/null +++ b/projects/plugins/jetpack/changelog/update-account-protection-no-auto-activate @@ -0,0 +1,4 @@ +Significance: minor +Type: enhancement + +Account Protection: Do not activate the module by default on new connections. Existing sites keep their current setting. diff --git a/projects/plugins/jetpack/modules/account-protection.php b/projects/plugins/jetpack/modules/account-protection.php index 17e14a8d1fe7..2296950fc613 100644 --- a/projects/plugins/jetpack/modules/account-protection.php +++ b/projects/plugins/jetpack/modules/account-protection.php @@ -6,7 +6,7 @@ * First Introduced: 14.5 * Requires Connection: Yes * Requires User Connection: No - * Auto Activate: Yes + * Auto Activate: No * Module Tags: Account Protection * Feature: Security * diff --git a/projects/plugins/jetpack/tests/php/general/Jetpack_Account_Protection_Auto_Activate_Test.php b/projects/plugins/jetpack/tests/php/general/Jetpack_Account_Protection_Auto_Activate_Test.php new file mode 100644 index 000000000000..d1b98093ee38 --- /dev/null +++ b/projects/plugins/jetpack/tests/php/general/Jetpack_Account_Protection_Auto_Activate_Test.php @@ -0,0 +1,37 @@ +assertNotContains( 'account-protection', Jetpack::get_default_modules() ); + } + + /** + * An upgrade from a version before the module was introduced (14.5) must not activate it. + */ + public function test_account_protection_is_not_activated_on_upgrade_from_before_14_5() { + $this->assertNotContains( 'account-protection', Jetpack::get_default_modules( '14.4', JETPACK__VERSION ) ); + } +} diff --git a/projects/plugins/protect/changelog/update-account-protection-no-auto-activate b/projects/plugins/protect/changelog/update-account-protection-no-auto-activate new file mode 100644 index 000000000000..4118b4bb20bb --- /dev/null +++ b/projects/plugins/protect/changelog/update-account-protection-no-auto-activate @@ -0,0 +1,4 @@ +Significance: minor +Type: changed + +Account Protection: Do not activate the module when Protect is activated. Existing sites keep their current setting. diff --git a/projects/plugins/protect/src/class-jetpack-protect.php b/projects/plugins/protect/src/class-jetpack-protect.php index 88d4f496f695..df2d2ffa8e96 100644 --- a/projects/plugins/protect/src/class-jetpack-protect.php +++ b/projects/plugins/protect/src/class-jetpack-protect.php @@ -304,7 +304,6 @@ public static function do_plugin_activation_activities() { */ public static function activate_modules() { delete_option( self::JETPACK_PROTECT_ACTIVATION_OPTION ); - ( new Modules() )->activate( self::JETPACK_ACCOUNT_PROTECTION_MODULE_SLUG, false, false ); ( new Modules() )->activate( self::JETPACK_WAF_MODULE_SLUG, false, false ); ( new Modules() )->activate( self::JETPACK_BRUTE_FORCE_PROTECTION_MODULE_SLUG, false, false ); }