You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

WordPress AJAX登录表单报错‘object url is not defined’求排查

Fixing the object_url is not defined Error in Your WordPress AJAX Login Form

Let's break down why you're seeing this error and how to fix it—this is a common issue with WordPress's wp_localize_script function, usually tied to script loading order or registration.

1. Make Sure Your ajax_event Script Is Properly Registered & Loaded

The first parameter in wp_localize_script is a script handle, and that handle must correspond to a script you've already registered or enqueued. If you skip this step, WordPress won't output the object_url variable to the frontend.

Here's the correct order of operations in your functions.php:

// First, enqueue your frontend JS file (adjust the path to match your actual file)
add_action('wp_enqueue_scripts', 'ginmagtheme_load_ajax_scripts');
function ginmagtheme_load_ajax_scripts() {
    wp_enqueue_script(
        'ajax_event',
        get_template_directory_uri() . '/js/login-script.js', // Replace with your JS file path
        array('jquery'), // Depend on jQuery since you're using it
        '1.0',
        true // Load in footer (better for performance)
    );

    // Now localize the script to pass your AJAX URL and nonce
    $translation_array = array(
        'url' => admin_url('admin-ajax.php'),
        'nonce' => wp_create_nonce('ajax-nonce')
    );
    wp_localize_script('ajax_event', 'object_url', $translation_array);
}

Note: If your JS code is inline in a template file (not an external .js), wp_localize_script won't work as expected because it binds variables to a specific enqueued script. Either move your JS to an external file, or localize to the jquery handle instead.

2. Verify object_url Is Output to the Frontend

Open your page's source code (Ctrl+U in most browsers) and search for object_url. If you don't see it, that means wp_localize_script isn't running correctly. Double-check that your code is wrapped in the wp_enqueue_scripts hook—WordPress requires this for all script-related operations.

3. Add Nonce Validation (Critical for Security)

You're passing a nonce but not using it—don't skip this! It prevents CSRF attacks. Update your JS to include it:

jQuery(document).ready(function($) { // Wrap in ready to ensure DOM is loaded
    $('#login-form button').on('click', function(e) {
        e.preventDefault(); // Move this up to prevent default action immediately

        var username = $('#login-form input[name=email]').val();
        var password = $('#login-form input[name=password]').val();

        var data = {
            'action': 'ginmagtheme_login',
            'user_login': username,
            'user_password': password,
            'security': object_url.nonce // Add the nonce here
        };

        $.ajax({
            type: 'post',
            url: object_url.url,
            data: data,
            cache: false,
            success: function(response) {
                window.location.href = "/profile/";
            },
            error: function(xhr, status, err) {
                console.log('AJAX Error:', err); // Useful for debugging
            }
        });
    });
});

And add validation in your PHP AJAX handler:

// Register the AJAX handler for logged-in and guest users
add_action('wp_ajax_ginmagtheme_login', 'ginmagtheme_login_handler');
add_action('wp_ajax_nopriv_ginmagtheme_login', 'ginmagtheme_login_handler');

function ginmagtheme_login_handler() {
    // Verify the nonce first
    check_ajax_referer('ajax-nonce', 'security');

    // Your login logic goes here (use wp_signon() for proper WordPress authentication)
    $creds = array(
        'user_login'    => $_POST['user_login'],
        'user_password' => $_POST['user_password'],
        'remember'      => true // Optional: add a "remember me" checkbox if needed
    );

    $user = wp_signon($creds, false);
    if (is_wp_error($user)) {
        wp_send_json_error($user->get_error_message());
    } else {
        wp_send_json_success();
    }

    wp_die(); // Required for AJAX handlers in WordPress
}

4. Ensure Your JS Runs After the DOM Is Ready

If your JS runs before the #login-form element exists, it won't bind the click event—and if object_url loads after your JS, you'll get the undefined error. Wrapping your code in jQuery(document).ready() fixes both issues.

Walk through these steps, and you should resolve the object_url is not defined error.

内容的提问来源于stack exchange,提问作者Victor S.

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.09 21:12:50