WooCommerce自定义重置密码页提交时提示密钥无效如何解决?
问题根因
- 重置链接生成代码存在多余空格,可能导致参数传递异常
- 短代码调用重置密码模板时,未显式传入当前URL中的
key和id参数,表单无法读取正确的校验值 - WooCommerce默认拦截重置密码请求仅在原生
/my-account/lost-password/端点处理,自定义页面的提交请求未被正确识别
修复步骤
1. 修正邮件重置链接的多余空格
把customer-reset-password.php里的链接代码中多余空格删掉,直接调用home_url传路径参数避免拼接错误,修改后代码如下:
<a class="link" href="<?php echo esc_url( add_query_arg( array( 'key' => $reset_key, 'id' => $user_id ), home_url( '/reset-password/' ) ) ); ?>"> <?php // phpcs:ignore ?> <?php esc_html_e( 'Click here to reset your password', 'woocommerce' ); ?> </a>
2. 修正短代码逻辑,显式传入校验参数
修改functions.php里的短代码注册逻辑,主动读取当前URL中的key和id参数传入模板:
function wc_custom_reset_password_form( $atts ) { // 读取URL中的重置参数 $reset_key = isset( $_GET['key'] ) ? sanitize_text_field( $_GET['key'] ) : ''; $user_id = isset( $_GET['id'] ) ? absint( $_GET['id'] ) : 0; // 传入模板参数 return wc_get_template( 'myaccount/form-reset-password.php', array( 'form' => 'reset_password', 'reset_key' => $reset_key, 'user_id' => $user_id ) ); } add_shortcode( 'reset_password_form', 'wc_custom_reset_password_form' );
3. 放行自定义页面的重置请求处理逻辑
在functions.php中添加如下代码,让自定义页面可以处理重置密码提交请求:
add_action( 'template_redirect', 'custom_handle_reset_password_request' ); function custom_handle_reset_password_request() { // 仅在自定义重置密码页面触发处理逻辑 if ( is_page( 'reset-password' ) && isset( $_POST['reset_password'] ) ) { WC()->shortcodes->my_account(); } }
如果上述代码不生效,可添加过滤器覆盖WooCommerce默认的重置端点绑定:
add_filter( 'woocommerce_get_endpoint_url', 'custom_override_reset_password_endpoint', 10, 4 ); function custom_override_reset_password_endpoint( $url, $endpoint, $value, $permalink ) { if ( $endpoint === 'lost-password' ) { $url = home_url( '/reset-password/' ); } return $url; }
额外注意
如果使用了WAF、安全插件或者CDN,需要将/reset-password/路径加入缓存排除列表,同时避免该路径的请求参数被拦截过滤。
所有修改完成后清空WPEngine服务器缓存和本地浏览器缓存,重新发起密码重置流程即可正常提交新密码。
内容的提问来源于stack exchange,提问作者Freddy
相关产品推荐
相关产品推荐

