请求实现WordPress中基于会话存储用户ID与PIN的单字段PIN登录功能
Alright, let's tweak your code to build that PIN-based login system you want, using the user ID and PIN stored in the session to avoid conflicts from duplicate PINs across users. Here's a revised implementation that follows your core requirements:
Key Changes Explained
- Added session initialization (WordPress doesn't start sessions automatically, so we need to trigger it manually)
- Simplified the login form to only ask for a PIN, per your requirements
- Updated authentication logic to match the submitted PIN against the session-stored PIN, then use the session's user ID to log the user in
- Removed username-based checks entirely, focusing on session-stored user data to eliminate duplicate PIN conflicts
Full Code Implementation
<?php // Initialize PHP session (must be called before any HTML output) session_start(); global $user_ID; // Redirect logged-in users right away if ($user_ID) { wp_redirect(home_url()); exit(); } // Handle PIN login form submission if ($_SERVER['REQUEST_METHOD'] === 'POST') { // Check if session has the required login data (user ID and PIN) if (!isset($_SESSION['pin_login_user_id'], $_SESSION['pin_login_pin'])) { echo 'No session data found - please register first on this device.'; exit(); } // Sanitize the submitted PIN to avoid messy input $submitted_pin = sanitize_text_field($_POST['pin']); // Match submitted PIN with the one stored in the session if ($submitted_pin === $_SESSION['pin_login_pin']) { // Fetch the user object using the session-stored user ID $user = get_user_by('id', $_SESSION['pin_login_user_id']); if ($user) { // Authenticate the user wp_set_current_user($user->ID, $user->user_login); wp_set_auth_cookie($user->ID); // Redirect to the home page after successful login wp_redirect(home_url()); exit(); } else { echo 'Invalid user ID stored in your session.'; } } else { echo 'Incorrect PIN. Please try again.'; } } else { // Display the simplified PIN login form ?> <form method="post"> <p> <label for="pin">PIN</label> <input type="text" id="pin" name="pin" placeholder="Enter your PIN" required> </p> <p> <button type="submit" name="submit">Log In</button> </p> </form> <?php } ?>
Critical Registration Flow Addition
Don't forget to add this logic to your user registration process (to populate the session with user data):
// After successful user registration (replace $user_id with your actual new user ID) $user_pin = sanitize_text_field($_POST['user_pin']); // The PIN the user entered during registration // Save PIN as user meta (for future reference if needed) update_user_meta($user_id, 'user_pin', $user_pin); // Store user ID and PIN in the session for login verification $_SESSION['pin_login_user_id'] = $user_id; $_SESSION['pin_login_pin'] = $user_pin;
This setup ensures that when a user registers on a device, their unique user ID and chosen PIN are saved to the session. When they attempt to log in later, the system only verifies the PIN against the session's stored value, then uses the session's user ID to authenticate them—completely eliminating the problem of duplicate PINs logging into the wrong account.
内容的提问来源于stack exchange,提问作者George Obonyo

