自定义应用与WordPress统一登录实现及跳转问题技术问询
Alright, let's break down your requirements and fix the issues you're facing step by step. Your core idea of syncing logins via WordPress auth cookies is totally on the right track—we just need to tweak the implementation to avoid that unwanted redirect and cover all your other needs.
1. Fix the Redirect Problem When Setting WP Auth Cookie
The issue with your original code is that loading wp-load.php triggers WordPress's full initialization, which can fire hooks that cause unexpected redirects. Here's how to fix that:
When your custom app validates a user's login, add these safeguards before loading WordPress files, then explicitly redirect to your app dashboard afterward:
if ($login_valid) { // Prevent WordPress from loading themes/templates (avoids redirects) define('WP_USE_THEMES', false); // Load WordPress core without triggering frontend logic require_once '<path_to_wordpress>/wp-load.php'; // Make sure $user_id_var is the *WordPress user ID* (you said you sync these on registration) $wp_user_id = $user_id_var; // Set the auth cookie with proper parameters for your domain wp_set_auth_cookie( $wp_user_id, true, // Set to false if you don't want "remember me" functionality is_ssl(), // Use true if your site uses HTTPS '/', // Cookie path (covers your entire domain) '.domain.tld' // Cookie domain (works for main domain and /blog subpath) ); // Optional: Update the user's last login time in WordPress wp_update_user([ 'ID' => $wp_user_id, 'last_login' => current_time('mysql') ]); // Force redirect to your app dashboard—don't let WordPress take over header('Location: /dashboard'); exit; }
By defining WP_USE_THEMES as false, we skip WordPress's theme loading and frontend initialization, which eliminates the unwanted redirect to your blog. Then we explicitly send the user to your app dashboard.
2. Disable WordPress Admin Access for Non-Admins
Since regular users don't need the WP backend, add this code to your WordPress theme's functions.php file (or a custom plugin) to block non-admins:
add_action('admin_init', 'restrict_non_admin_access'); function restrict_non_admin_access() { // Only block users who can't manage options (non-admins) // Exclude AJAX requests to avoid breaking frontend WP functionality if (!current_user_can('manage_options') && !wp_doing_ajax()) { wp_redirect(get_home_url()); // Redirect to blog homepage (or your app's homepage) exit; } }
This will redirect any non-admin user trying to access /wp-admin back to your blog (or adjust the redirect URL to your app if preferred).
3. Implement Dynamic Menus in WordPress
To show login/register when users are logged out, and dashboard/logout when they're logged in, edit your WordPress theme's header.php (or wherever your menu lives) with this code:
<nav class="site-nav"> <?php if (is_user_logged_in()) : ?> <a href="/dashboard">仪表盘</a> <a href="/logout">登出</a> <?php else : ?> <a href="/login">登录</a> <a href="/register">注册</a> <?php endif; ?> </nav>
Make sure the /logout link points to your custom app's logout endpoint. In that endpoint, don't forget to destroy both your app's session AND WordPress's auth cookie:
// Destroy your custom app's session session_destroy(); // Clear WordPress auth cookie define('WP_USE_THEMES', false); require_once '<path_to_wordpress>/wp-load.php'; wp_clear_auth_cookie(); // Redirect to login page header('Location: /login'); exit;
4. Key Notes to Ensure Everything Works
- User ID Sync: Double-check that when users register in your custom app, you're creating a matching WordPress user and storing the WordPress user ID in your app's user database—this is critical for
wp_set_auth_cookieto work correctly. - HTTPS Considerations: If your site uses HTTPS, keep the
is_ssl()parameter inwp_set_auth_cookieto ensure cookies are only sent over secure connections. - Cookie Testing: Use your browser's developer tools (Application > Cookies) to verify that the WordPress auth cookies (like
wordpress_logged_in_*) are set for the.domain.tlddomain and path/—this ensures they work on both your main app and/blog.
内容的提问来源于stack exchange,提问作者master03

