WordPress:用户登录后销毁其他会话及重复登录销毁旧会话方案咨询
Absolutely, you can pull this off without touching your social login plugin’s code—WordPress gives us built-in hooks to handle exactly this scenario. Let’s walk through how to make it work for both standard and social logins:
Use the wp_login Action Hook (Works for Most Cases)
The wp_login hook fires right after any user successfully logs in, regardless of whether they used WordPress’ default login form or a social login plugin (as long as the plugin follows WordPress best practices and triggers this hook). This is our safest bet for a universal solution.
Add this code to your theme’s functions.php file, or (even better) a custom plugin (so your code doesn’t disappear if you switch themes later):
add_action('wp_login', 'terminate_old_user_sessions_on_login', 10, 2); function terminate_old_user_sessions_on_login($user_login, $user) { // Make sure we have access to WordPress' session token system if (!class_exists('WP_Session_Tokens')) { return; } // Get the session manager for the logged-in user $session_manager = WP_Session_Tokens::get_instance($user->ID); // Grab the current session token so we don't kill the one we just created $current_active_token = wp_get_session_token(); if ($current_active_token) { // Destroy all sessions EXCEPT the current one (keeps the user logged in) $session_manager->destroy_others($current_active_token); } else { // Fallback: if we can't get the current token, wipe all sessions $session_manager->destroy_all(); } }
What This Code Does:
- Targets the right hook:
wp_logingives us access to the user object immediately after authentication, so we can act on their sessions. - Preserves the current session: Using
destroy_others()instead ofdestroy_all()ensures the user doesn’t get logged out right after logging in—only their old sessions are terminated. - Fallback safety: If for some reason the current session token can’t be retrieved, we fall back to
destroy_all()to make sure old sessions are still cleared.
If Your Social Login Plugin Doesn’t Trigger wp_login
Rarely, some social login plugins might skip the standard wp_login hook. If that’s the case, check your plugin’s documentation for its custom authentication hook. For example:
- WP Social Login uses
wordpress_social_login_after_authenticate - Nextend Social Login uses
nextend_social_login_user_authenticated
Here’s how you’d adapt the code for WP Social Login:
add_action('wordpress_social_login_after_authenticate', 'terminate_old_sessions_social_login'); function terminate_old_sessions_social_login($user) { if (!class_exists('WP_Session_Tokens')) { return; } $session_manager = WP_Session_Tokens::get_instance($user->ID); $current_active_token = wp_get_session_token(); if ($current_active_token) { $session_manager->destroy_others($current_active_token); } else { $session_manager->destroy_all(); } }
Key Notes
- Use a custom plugin: If you’re not already using one, create a simple plugin for this code. Just make a folder in
wp-content/plugins/, create a file likecustom-session-management.php, add a plugin header (below), and paste the code. This way, your code stays intact even if you switch themes./* Plugin Name: Custom Session Management Description: Terminates old user sessions on login Version: 1.0 Author: Your Name */ - Compatibility: This works with WordPress 4.0+ (when
WP_Session_Tokenswas added to core), which covers almost all active WordPress sites.
This setup ensures that every time a user logs in—whether via email/password or social media—all their previous sessions are ended, exactly what you’re looking for. No plugin code edits required!
内容的提问来源于stack exchange,提问作者Subair

