# Block User

<!-- meta: type=block-user; location=Users; category=Step (action); platforms=Joomla and WordPress (where applicable) -->

## Overview

Blocks a Joomla user account so they can no longer log in (sets the block flag). Use this for security lockouts, subscription expiry, or offboarding without deleting the account and audit history.

When the flow reaches this step, JOrchestrator executes **Block User** against your linked site or an external integration, using the field values you set on **General** and **Design**. Downstream steps can read the output payload fields defined for this node.

## Why use this node

Block User is a **action step** in the **Users** group. Action steps run in the middle or end of a flow. They perform work on your CMS, call external services, or transform data for the next step.

Typical reasons teams add **Block User** to a flow:

- Lock accounts after repeated failed login attempts detected upstream
- Disable access when a subscription expires without deleting the user record
- Automate offboarding while preserving audit history (prefer over delete-user)

## Example workflows

Common patterns on the canvas:

1. **Trigger or Webhook** → upstream steps → **Block User** → **Send Email** or CMS update
2. **Scheduled trigger** → **Block User** → **Debug** (while testing) → production action

## How to set it up

Provide User ID or username on the Design tab; user id 1 (super user) cannot be blocked.

## Good to know

Pair with security flows on repeated login failures, or use unblock-user to restore access later.

## Properties panel

The designer shows these tabs for this node:

| Tab | Purpose |
|-----|---------|
| **Info** | Plain-language description and output payload fields for downstream steps |
| **General** | Canvas label and read-only node ID |
| **AI** | Optional assistant to help draft settings from plain language |
| **Design** | Node-specific configuration fields |

### System (automatic — not edited by the user)

These fields are managed by the designer or runtime — you do not type into them directly:

| Property key | Label | Type | Required | Visible when | Notes |
|--------------|-------|------|----------|--------------|-------|
| `_nodeId` | Node ID | `node-id` | No | — | — |
| `_payloadFields` | Available Fields | `payload-panel` | No | — | — |

### User-configured — General tab

| Property key | Label | Type | Required | Visible when | Notes |
|--------------|-------|------|----------|--------------|-------|
| `label` | Label | `text` | No | — | Node label |

### User-configured — Design tab

| Property key | Label | Type | Required | Visible when | Notes |
|--------------|-------|------|----------|--------------|-------|
| `username` | Username | `text` | No | — | Login name if User ID is empty |

### CMS-backed or hybrid (loaded from the linked site at design time)

These fields can pull live options or values from the Joomla/WordPress site linked to the flow:

| Property key | Label | Type | Required | Visible when | Notes |
|--------------|-------|------|----------|--------------|-------|
| `userId` | User ID | `email-recipient` | **Yes** | — | Numeric id, {{placeholder}}, or select Joomla user… Value kind: `userId` |

### CMS site configuration (not on this node's properties panel)

Credentials, API keys, mailers, SMTP, and integration defaults are configured in the CMS plugin under **Node Configuration**, not per step on this node. Link the flow to a domain before testing CMS-backed fields.

## Output payload fields

After this step runs, later nodes can reference these fields using placeholders such as
`{{block_user.id}}`.

| Field key | Type | Description |
|-----------|------|-------------|
| `id` | string | Primary record identifier. |
| `username` | string | Text value from this node's output. |
| `success` | boolean | Whether the operation completed successfully. |

## Related nodes

Other steps in the same area of the palette:

- **Create User** (`create-user`) — Users
- **Create User** (`wp-create-user`) — Users
- **Delete User** (`delete-user`) — Users
- **Delete User** (`wp-delete-user`) — Users
- **Get User** (`get-user`) — Users
