Production-ready WordPress integration for synchronizing public Spacebring locations, resources, and events.
  • PHP 94.7%
  • TypeScript 3.6%
  • Hack 0.9%
  • JavaScript 0.7%
  • CSS 0.1%
Find a file
Ryan Allen 10ab9edada
All checks were successful
CI / php (8.0) (push) Successful in 1m3s
CI / php (8.3) (push) Successful in 43s
CI / frontend (push) Successful in 19s
Lock dependencies for PHP 8.0 compatibility
2026-08-24 17:04:01 +01:00
.github/workflows Fix Forgejo CI and Spacebring pagination 2026-08-24 16:41:54 +01:00
assets Add persistent sync history and health dashboard 2026-08-24 16:47:42 +01:00
src Handle structured Spacebring pagination 2026-08-24 16:54:50 +01:00
templates Add persistent sync history and health dashboard 2026-08-24 16:47:42 +01:00
tests Handle structured Spacebring pagination 2026-08-24 16:54:50 +01:00
.gitignore Harden Spacebring synchronization for production 2026-08-24 15:31:34 +01:00
changelog.txt Prepare Spacebring 1.3.0 release 2026-08-24 16:55:13 +01:00
composer.json Lock dependencies for PHP 8.0 compatibility 2026-08-24 17:04:01 +01:00
composer.lock Lock dependencies for PHP 8.0 compatibility 2026-08-24 17:04:01 +01:00
LICENSE Add LICENSE file and update README with development setup instructions 2026-02-11 11:25:29 +10:00
package-lock.json Fix frontend release manifest 2026-08-24 16:56:06 +01:00
package.json Fix frontend release manifest 2026-08-24 16:56:06 +01:00
phpunit.xml.dist Harden Spacebring synchronization for production 2026-08-24 15:31:34 +01:00
README.md Add verified Spacebring webhooks 2026-08-24 16:53:18 +01:00
spacebring.php Prepare Spacebring 1.3.0 release 2026-08-24 16:55:13 +01:00
tsconfig.json init commit 2026-02-11 11:16:43 +10:00
vite.config.js Add input entry for events script in Vite configuration 2026-02-11 14:13:54 +10:00

Spacebring for WordPress

Spacebring for WordPress synchronizes public locations and resources from Spacebring into WordPress and renders upcoming public events with the [spacebring_events] shortcode.

Spacebring remains the system of record and booking application. WordPress acts as a public presentation layer and links visitors to configured Spacebring portal pages.

Features

  • Spacebring customer API authentication
  • Encrypted credential storage, with wp-config.php constant overrides
  • Explicit all-locations or single-location display selection
  • Selectable synchronization for all 12 documented resource types
  • Capacity, pricing, plans, schedule, permissions, duration, check-in, refund, and parent metadata
  • Filterable Spacebring booking deep links for every resource
  • Public-visibility enforcement for resources and events
  • Complete cursor pagination for list endpoints
  • Durable, privacy-allowlisted event snapshots with last-known-good fallback
  • Background event refreshes every 30 minutes
  • Automatic synchronization every six hours, twice daily, or daily
  • Overlap protection, retry/backoff, stale-record reconciliation, and sync status
  • Persistent 30-day sync history, Site Health checks, and WP-CLI commands
  • Svix-compatible signed, timestamp-checked, idempotent webhook receiver
  • Multiple-location event aggregation
  • Upcoming, public, uncanceled event filtering
  • Multi-instance event list/calendar shortcode
  • Theme-overridable frontend templates

Requirements

  • WordPress 6.2 or newer
  • PHP 8.0 or newer with OpenSSL
  • Composer for source installations
  • Node.js 18 or newer for frontend development

Installation from source

composer install --no-dev --optimize-autoloader
npm ci
npm run build

Place the plugin directory in wp-content/plugins, then activate Spacebring in WordPress.

Configuration

Open Spacebring → Settings and enter the Spacebring customer API username and password. Configure the portal base URL to enable event links.

For managed environments, credentials can be supplied without storing them in the database:

define('SPACEBRING_API_USERNAME', 'your-client-id');
define('SPACEBRING_API_PASSWORD', getenv('SPACEBRING_API_PASSWORD'));

Do not commit credentials to source control. Spacebring content that is not marked public is never publicly published by this plugin.

To enable webhook-driven refreshes, save the signing secret and configure this endpoint in Spacebring:

https://your-wordpress-site.example/wp-json/spacebring/v1/webhook

Webhook requests are verified against the raw body, timestamp, message ID, and signature. Only receipt metadata is retained; webhook payloads are not stored.

Synchronization behavior

The automatic schedule is configured under Spacebring → Synchronization. A complete successful run:

  1. Fetches current locations.
  2. Retrieves every page of each selected resource type for every location.
  3. Creates or updates the corresponding WordPress posts.
  4. Keeps non-public resources private.
  5. Drafts imported records that disappeared from a fully successful upstream scope.

Failed or partial scopes are not reconciled, preventing transient API failures from removing valid content. A manual sync can be run from the same page.

Upcoming events are stored in a dedicated WordPress table using an explicit public-field allowlist. Frontend requests normally read this local snapshot, reducing API traffic and keeping the calendar available during a Spacebring outage. A failed location refresh never replaces that location's last-known-good data.

Events shortcode

[spacebring_events]
[spacebring_events limit="10"]
[spacebring_events assets="false"]

The shortcode displays upcoming public events across synchronized locations. Set the Spacebring portal URL in plugin settings to link each event back to Spacebring.

Override the template by copying:

templates/frontend/shortcodes/events.php

to:

your-theme/spacebring/shortcodes/events.php

Development

composer install
composer test
composer audit --locked
npm ci
npm run typecheck
npm run build

Production cron and diagnostics can use:

wp spacebring status
wp spacebring sync
wp spacebring events

Privacy and security

The plugin intentionally does not synchronize bookings, memberships, visitors, invoices, transactions, or other customer records. Sync logs contain operational summaries rather than complete API payloads.

Report security issues privately to the repository owner instead of opening a public issue.

License

MIT