You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

WordPress 6.3免密码登录代码失效,求适配修改方案

适配WordPress 6.3的免密码登录代码修复

WordPress 6.3对登录流程的验证逻辑做了调整,原代码失效的核心原因是新增了密码字段非空检查,同时authenticate过滤器的执行优先级和默认验证逻辑被强化。以下是修复后的完整代码及说明:

修复后的代码

function bypass_password_login($user, $username, $password) {
    // 若已有验证通过的用户,直接返回
    if ($user instanceof WP_User) {
        return $user;
    }

    // 根据用户名获取目标用户
    $target_user = get_user_by('login', $username);
    if (!$target_user) {
        // 用户不存在时返回默认错误提示
        return new WP_Error('invalid_username', __('<strong>错误</strong>: 用户名不存在。'));
    }

    // 跳过密码验证,直接设置认证Cookie
    wp_set_auth_cookie($target_user->ID, true);
    // 重定向至后台(可根据需求修改跳转地址)
    wp_safe_redirect(admin_url());
    exit;
}

function remove_password_field_restrictions() {
    ?>
    <script type="text/javascript">
        document.addEventListener('DOMContentLoaded', function() {
            const passwordField = document.getElementById('user_pass');
            if (passwordField) {
                // 移除密码字段的必填属性
                passwordField.removeAttribute('required');
                // 隐藏密码字段容器
                passwordField.closest('p').style.display = 'none';
            }
        });
    </script>
    <style type="text/css">
        body.login div#login form#loginform p.user-pass-wrap {
            display: none !important;
        }
    </style>
    <?php
}

// 提高过滤器优先级,确保自定义逻辑先于默认验证执行
add_filter('authenticate', 'bypass_password_login', 5, 3);
add_action('login_head', 'remove_password_field_restrictions');

关键修复点

  • 调整过滤器优先级:将authenticate的优先级设为5(默认是10),保证自定义验证逻辑在WordPress默认校验之前运行。
  • 新增用户对象判断:避免重复处理已通过其他方式验证的用户,防止逻辑冲突。
  • 动态移除必填属性:通过JavaScript清除密码字段的required标记,绕过6.3新增的非空检查。
  • 更稳定的字段隐藏:使用.user-pass-wrap类选择器定位密码字段容器,避免因DOM结构变动导致样式失效。
  • 主动终止后续流程:设置认证Cookie后直接重定向并退出,阻止默认密码验证逻辑继续执行。

内容的提问来源于stack exchange,提问作者Konrad Bartczak

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.12 06:06:17