如何正确使用wp_signon?自定义授权表单跳转失效排查求助
Hey there! Let's dig into why your redirect isn't working even though var_dump($_POST) confirms your form data is coming through correctly. I'll break down the most common pitfalls with wp_signon() and walk you through fixing them in your my_auth.php file.
1. You're Outputting Content Before Sending Headers (The #1 Culprit)
If you're using var_dump() to debug, that's sending content to the browser before WordPress tries to send the redirect header. PHP can't modify headers once any output has been sent—this will trigger a "headers already sent" error (check your PHP error logs to confirm this is happening).
Fix:
- Remove any
var_dump(),echo, or stray HTML from your script before callingwp_redirect(). - If you need to debug, use
error_log()instead to write data to your PHP error log without outputting to the page:error_log(print_r($_POST, true)); // Writes POST data to error log safely
2. You're Not Properly Handling wp_signon() Return Values
wp_signon() doesn't just log the user in—it returns either a WP_User object (on success) or a WP_Error object (on failure). Skipping this check means you might try to redirect even if login failed, or miss critical error details that break the flow.
Correct Usage Example:
// First, load WordPress core (if this is a standalone file) require_once(__DIR__ . '/../wp-load.php'); // Adjust path to your wp-load.php // Validate nonce (critical for security and stability) if (!isset($_POST['login_nonce']) || !wp_verify_nonce($_POST['login_nonce'], 'custom_auth_nonce')) { wp_die('Security check failed. Please try again.'); } // Sanitize and prepare login credentials $credentials = array( 'user_login' => sanitize_text_field($_POST['username']), 'user_password' => $_POST['password'], 'remember' => isset($_POST['rememberme']) ? true : false ); // Attempt login (use secure cookie if your site uses SSL) $login_result = wp_signon($credentials, is_ssl()); // Handle login results if (is_wp_error($login_result)) { // Login failed—redirect back to form with error code $error_code = $login_result->get_error_code(); wp_redirect(add_query_arg('login_error', $error_code, wp_login_url())); exit; } else { // Login succeeded—redirect to your target page wp_redirect(home_url('/dashboard/')); // Replace with your desired URL exit; // ALWAYS call exit after wp_redirect to stop script execution! }
3. You Forgot to Call exit() After wp_redirect()
Even if wp_redirect() sends the correct header, if your script continues to run afterward, it can interfere with the redirect. Always add exit; or die(); immediately after wp_redirect() to halt execution.
4. Your Script Isn't Loading WordPress Core Correctly
If my_auth.php is a standalone file (not part of a theme or plugin), you need to explicitly load WordPress's wp-load.php to access functions like wp_signon() and wp_redirect(). Double-check the path to wp-load.php—a wrong path will cause these functions to be undefined.
5. Missing Nonce Validation (Security + Stability)
While not directly causing redirect failures, skipping nonce validation leaves your form open to CSRF attacks and can lead to unexpected behavior. Add a nonce field to your login form:
<form method="POST" action="/path/to/my_auth.php"> <!-- Your username/password fields here --> <input type="hidden" name="login_nonce" value="<?php echo wp_create_nonce('custom_auth_nonce'); ?>"> <button type="submit">Log In</button> </form>
Then validate it in my_auth.php as shown in the example above.
Quick Debug Checklist
- Check PHP error logs for "headers already sent" messages.
- Remove all output before
wp_redirect(). - Confirm
wp_signon()returns a validWP_Userobject (useerror_log(print_r($login_result, true))to debug). - Ensure
exit;is called right afterwp_redirect(). - Verify the target URL in
wp_redirect()is correct (usehome_url()oradmin_url()to generate it dynamically).
内容的提问来源于stack exchange,提问作者Александр

