You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

WooCommerce订单详情页显示用户当前密码功能实现求助

解决方案:在WooCommerce订单详情页显示用户访问码

由于WordPress采用单向哈希算法存储用户密码,无法直接解密获取明文,因此要实现显示手动设置的访问码,需要在设置访问码时额外将明文存储为用户自定义元数据。以下是修改后的完整代码:

修改后的代码

1. 自定义Metabox内容(新增访问码显示)

// Custom Metabox content on WooCommerce single orders
function content_custom_shop_order_metabox() {
    global $post;

    $customer_id = get_post_meta( $post->ID, '_customer_user', true );
    // 获取存储的明文访问码
    $current_access_code = get_user_meta( $customer_id, '_customer_access_code', true );

    echo '<div class="options_group edit_password" style="min-height:4.5em;margin-top:12px;;">
        <input type="text" name="customer-password" class="customer-password" value="">
        <a class="button submit-password" style="text-align:center;">' . __('Submit', 'woocommerce') . '</a>
        <input type="hidden" name="customer-id" class="customer-id" value="' . $customer_id . '">
        <div class="message-response" style="margin-top:6px;"></div>';
        
    // 显示当前访问码(仅管理员可见)
    if (current_user_can('manage_options')) {
        echo '<div class="current-access-code" style="margin-top:10px;">
            <strong>' . __('Current Access Code:', 'woocommerce') . '</strong> 
            <span>' . ($current_access_code ? esc_html($current_access_code) : __('Not set', 'woocommerce')) . '</span>
        </div>';
    }
    
    echo '</div>';
}

2. Ajax接收函数(新增存储访问码)

// PHP Ajax receiver
add_action('wp_ajax_updating_customer_password', 'action_ajax_updating_customer_password');
function action_ajax_updating_customer_password() {
    if ( isset($_POST['customer-password']) && isset($_POST['customer-id']) ) {
        $password = sanitize_text_field( $_POST['customer-password'] );
        $user_id  = intval( esc_attr( $_POST['customer-id'] ) );

        if ( ! $password ) {
            echo 'empty'; // empty input
        } elseif ( strpos($password, ' ') !== false ) {
            echo 'whitespace'; // empty input
        } else {
            wp_set_password( $password, $user_id ); // Set new password
            // 存储明文访问码到用户元数据
            update_user_meta( $user_id, '_customer_access_code', $password );
            // 返回访问码用于前端更新显示
            echo $password;
        }
        wp_die();
    }
}

3. Ajax JS(新增更新当前访问码显示)

// Jquery Ajax
add_action( 'admin_footer', 'edit_password_orders_column_js' );
function edit_password_orders_column_js() {
    global $pagenow, $post_type;

    if ( 'post.php' === $pagenow && 'shop_order' === $post_type ) :
?>
<script type="text/javascript">
jQuery( function($){
    $('div.edit_password > .message-response').fadeOut(0);
    $('div.edit_password > .button.submit-password').on('click', function(e){
        e.preventDefault();
        e.stopImmediatePropagation();

        var $this = $(this),
            $parent = $this.parent(),
            password = $parent.find('.customer-password').val(),
            user_id  = $parent.find('.customer-id').val(),
            text = '',
            color = 'red';

        $.ajax({
            type: 'POST',
            url: '<?php echo admin_url('/admin-ajax.php'); ?>',
            data: {
                'action'           : 'updating_customer_password',
                'customer-password': password,
                'customer-id'      : user_id
            },
            success: function (response) {
                if ( response === 'empty' ) {
                    text  = '<?php echo __('Empty input, retry…', 'woocommerce'); ?>';
                } else if ( response === 'whitespace' ) {
                    text  = '<?php echo __('No white spaces…', 'woocommerce'); ?>';
                } else {
                    text  = '<?php echo __('Password Updated!', 'woocommerce'); ?>';
                    color = 'green';
                    // 更新当前访问码显示
                    $parent.find('.current-access-code span').text(response);
                }
                $parent.find('.customer-password').val('');
                $parent.find('.message-response').html('<small>'+text+'<small>').css('color',color).fadeIn();
                setTimeout(function(){
                    $parent.find('.message-response').fadeOut( function(){ $(this).css('color','black').html(''); });
                }, 2000)
            }
        });
    });
});
</script>
<?php
    endif;
}

关键说明

  • 新增_customer_access_code用户元字段,专门存储明文访问码,仅管理员可查看
  • 修改Ajax逻辑,设置密码时同步存储明文访问码,并在更新成功后返回给前端实时更新显示
  • 权限控制:通过current_user_can('manage_options')确保只有管理员能看到明文访问码,提升安全性
  • 若感谢页自动生成访问码的逻辑也需要显示,需在自动生成时调用update_user_meta($user_id, '_customer_access_code', $generated_code)同步存储

内容的提问来源于stack exchange,提问作者Karnak

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.25 11:47:57