WordPress 6.3免密码登录代码失效,求适配修改方案
适配WordPress 6.3的免密码登录代码修复
WordPress 6.3对登录流程的验证逻辑做了调整,原代码失效的核心原因是新增了密码字段非空检查,同时authenticate过滤器的执行优先级和默认验证逻辑被强化。以下是修复后的完整代码及说明:
修复后的代码
function bypass_password_login($user, $username, $password) { // 若已有验证通过的用户,直接返回 if ($user instanceof WP_User) { return $user; } // 根据用户名获取目标用户 $target_user = get_user_by('login', $username); if (!$target_user) { // 用户不存在时返回默认错误提示 return new WP_Error('invalid_username', __('<strong>错误</strong>: 用户名不存在。')); } // 跳过密码验证,直接设置认证Cookie wp_set_auth_cookie($target_user->ID, true); // 重定向至后台(可根据需求修改跳转地址) wp_safe_redirect(admin_url()); exit; } function remove_password_field_restrictions() { ?> <script type="text/javascript"> document.addEventListener('DOMContentLoaded', function() { const passwordField = document.getElementById('user_pass'); if (passwordField) { // 移除密码字段的必填属性 passwordField.removeAttribute('required'); // 隐藏密码字段容器 passwordField.closest('p').style.display = 'none'; } }); </script> <style type="text/css"> body.login div#login form#loginform p.user-pass-wrap { display: none !important; } </style> <?php } // 提高过滤器优先级,确保自定义逻辑先于默认验证执行 add_filter('authenticate', 'bypass_password_login', 5, 3); add_action('login_head', 'remove_password_field_restrictions');
关键修复点
- 调整过滤器优先级:将
authenticate的优先级设为5(默认是10),保证自定义验证逻辑在WordPress默认校验之前运行。 - 新增用户对象判断:避免重复处理已通过其他方式验证的用户,防止逻辑冲突。
- 动态移除必填属性:通过JavaScript清除密码字段的
required标记,绕过6.3新增的非空检查。 - 更稳定的字段隐藏:使用
.user-pass-wrap类选择器定位密码字段容器,避免因DOM结构变动导致样式失效。 - 主动终止后续流程:设置认证Cookie后直接重定向并退出,阻止默认密码验证逻辑继续执行。
内容的提问来源于stack exchange,提问作者Konrad Bartczak
相关产品推荐
相关产品推荐

