You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何正确使用wp_signon?自定义授权表单跳转失效排查求助

Troubleshooting Your Custom WordPress Auth Form Redirect Issue

Hey there! Let's dig into why your redirect isn't working even though var_dump($_POST) confirms your form data is coming through correctly. I'll break down the most common pitfalls with wp_signon() and walk you through fixing them in your my_auth.php file.

1. You're Outputting Content Before Sending Headers (The #1 Culprit)

If you're using var_dump() to debug, that's sending content to the browser before WordPress tries to send the redirect header. PHP can't modify headers once any output has been sent—this will trigger a "headers already sent" error (check your PHP error logs to confirm this is happening).

Fix:

  • Remove any var_dump(), echo, or stray HTML from your script before calling wp_redirect().
  • If you need to debug, use error_log() instead to write data to your PHP error log without outputting to the page:
    error_log(print_r($_POST, true)); // Writes POST data to error log safely
    

2. You're Not Properly Handling wp_signon() Return Values

wp_signon() doesn't just log the user in—it returns either a WP_User object (on success) or a WP_Error object (on failure). Skipping this check means you might try to redirect even if login failed, or miss critical error details that break the flow.

Correct Usage Example:

// First, load WordPress core (if this is a standalone file)
require_once(__DIR__ . '/../wp-load.php'); // Adjust path to your wp-load.php

// Validate nonce (critical for security and stability)
if (!isset($_POST['login_nonce']) || !wp_verify_nonce($_POST['login_nonce'], 'custom_auth_nonce')) {
    wp_die('Security check failed. Please try again.');
}

// Sanitize and prepare login credentials
$credentials = array(
    'user_login'    => sanitize_text_field($_POST['username']),
    'user_password' => $_POST['password'],
    'remember'      => isset($_POST['rememberme']) ? true : false
);

// Attempt login (use secure cookie if your site uses SSL)
$login_result = wp_signon($credentials, is_ssl());

// Handle login results
if (is_wp_error($login_result)) {
    // Login failed—redirect back to form with error code
    $error_code = $login_result->get_error_code();
    wp_redirect(add_query_arg('login_error', $error_code, wp_login_url()));
    exit;
} else {
    // Login succeeded—redirect to your target page
    wp_redirect(home_url('/dashboard/')); // Replace with your desired URL
    exit; // ALWAYS call exit after wp_redirect to stop script execution!
}

3. You Forgot to Call exit() After wp_redirect()

Even if wp_redirect() sends the correct header, if your script continues to run afterward, it can interfere with the redirect. Always add exit; or die(); immediately after wp_redirect() to halt execution.

4. Your Script Isn't Loading WordPress Core Correctly

If my_auth.php is a standalone file (not part of a theme or plugin), you need to explicitly load WordPress's wp-load.php to access functions like wp_signon() and wp_redirect(). Double-check the path to wp-load.php—a wrong path will cause these functions to be undefined.

5. Missing Nonce Validation (Security + Stability)

While not directly causing redirect failures, skipping nonce validation leaves your form open to CSRF attacks and can lead to unexpected behavior. Add a nonce field to your login form:

<form method="POST" action="/path/to/my_auth.php">
    <!-- Your username/password fields here -->
    <input type="hidden" name="login_nonce" value="<?php echo wp_create_nonce('custom_auth_nonce'); ?>">
    <button type="submit">Log In</button>
</form>

Then validate it in my_auth.php as shown in the example above.

Quick Debug Checklist

  1. Check PHP error logs for "headers already sent" messages.
  2. Remove all output before wp_redirect().
  3. Confirm wp_signon() returns a valid WP_User object (use error_log(print_r($login_result, true)) to debug).
  4. Ensure exit; is called right after wp_redirect().
  5. Verify the target URL in wp_redirect() is correct (use home_url() or admin_url() to generate it dynamically).

内容的提问来源于stack exchange,提问作者Александр

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 04:23:27