WordPress.org

Make WordPress Core

Ticket #9682: 9682.2.diff

File 9682.2.diff, 3.0 KB (added by Denis-de-Bernardy, 9 years ago)

action validation, with filter on top

  • wp-login.php

     
    147147        $message .= sprintf(__('Username: %s'), $user_login) . "\r\n\r\n";
    148148        $message .= __('To reset your password visit the following address, otherwise just ignore this email and nothing will happen.') . "\r\n\r\n";
    149149        $message .= site_url("wp-login.php?action=rp&key=$key", 'login') . "\r\n";
    150 
    151         if ( !wp_mail($user_email, sprintf(__('[%s] Password Reset'), get_option('blogname')), $message) )
     150       
     151        $title = sprintf(__('[%s] Password Reset'), get_option('blogname'));
     152       
     153        $title = apply_filters('retrieve_password_title', $title);
     154        $message = apply_filters('retrieve_password_message', $message, $key);
     155       
     156        if ( $message && !wp_mail($user_email, $title, $message) )
    152157                die('<p>' . __('The e-mail could not be sent.') . "<br />\n" . __('Possible reason: your host may have disabled the mail() function...') . '</p>');
    153158
    154159        return true;
     
    174179        if ( empty( $user ) )
    175180                return new WP_Error('invalid_key', __('Invalid key'));
    176181
    177         do_action('password_reset', $user);
    178 
    179182        // Generate something random for a password...
    180183        $new_pass = wp_generate_password();
     184       
     185        do_action('password_reset', $user, $new_pass);
     186
    181187        wp_set_password($new_pass, $user->ID);
    182188        $message  = sprintf(__('Username: %s'), $user->user_login) . "\r\n";
    183189        $message .= sprintf(__('Password: %s'), $new_pass) . "\r\n";
    184190        $message .= site_url('wp-login.php', 'login') . "\r\n";
     191       
     192        $title = sprintf(__('[%s] Your new password'), get_option('blogname'));
     193       
     194        $title = apply_filters('password_reset_title', $title);
     195        $message = apply_filters('password_reset_message', $message, $new_pass);
    185196
    186         if (  !wp_mail($user->user_email, sprintf(__('[%s] Your new password'), get_option('blogname')), $message) )
     197        if ( $message && !wp_mail($user->user_email, $title, $message) )
    187198                die('<p>' . __('The e-mail could not be sent.') . "<br />\n" . __('Possible reason: your host may have disabled the mail() function...') . '</p>');
    188199
    189200        wp_password_change_notification($user);
     
    251262if ( isset($_GET['key']) )
    252263        $action = 'resetpass';
    253264
     265// validate action so as to default to the login screen
     266if ( !in_array($action, array('logout', 'lostpassword', 'retrievepassword', 'resetpass', 'rp', 'register', 'login', '')) && false !== has_filter('login_form_' . $action) )
     267        $action = '';
     268
     269// allow plugins to override the wp actions
     270$action = apply_filters('login_form_action', $action);
     271
    254272nocache_headers();
    255273
    256274header('Content-Type: '.get_bloginfo('html_type').'; charset='.get_bloginfo('charset'));
     
    403421break;
    404422
    405423case 'login' :
    406 default:
     424case '':
    407425        $secure_cookie = '';
    408426
    409427        // If the user wants ssl but the session is not ssl, force a secure cookie.
     
    514532<?php
    515533
    516534break;
     535
     536// allow plugins to add extra actions if they want
     537default:
     538do_action('login_form_' . $action);
    517539} // end action switch
    518 ?>
     540?>
     541 No newline at end of file