1

我在前端更改了密码,我正在使用 wp_user_update 功能,但是当用户更改密码时,它已经注销。问题是我的旧cookie没有更新,所以如何在不注销的情况下更新密码。有什么想法吗?..

global $wpdb, $current_user;

$user_id =  $current_user->ID;
wp_update_user(array('ID'=>$user_id,'user_pass'=>$_POST['user_pass']));
4

1 回答 1

1

Aaron Forgue在 WordPress 支持上的回答是 3 岁,但可能很有趣。我不得不改变它$wpdb->query()以使其工作:

global $wpdb;

$profile_id = $_POST['prof_id'];
$username = $_POST['log_name'];
$password = $_POST['wachtwoord'];
$md5password = wp_hash_password($password);

// You may want to use $wpdb->prepare() here. As it stands, malicous code could be passed in via $_POST['prof_id'] or $_POST['log_name']
$wpdb->query( $wpdb->prepare( 
        "
            UPDATE $wpdb->users SET user_pass = %s WHERE ID = %d
        ", 
        $md5password, 
        $profile_id 
    ) );

// Here is the magic:
wp_cache_delete($profile_id, 'users');
wp_cache_delete($username, 'userlogins'); // This might be an issue for how you are doing it. Presumably you'd need to run this for the ORIGINAL user login name, not the new one.
wp_logout();
wp_signon(array('user_login' => $username, 'user_password' => $password));

归功于上述技巧的这个插件:http ://wordpress.org/extend/plugins/change-password-e-mail/

正如Robahas所提到的,确保在发送标头之前运行此代码,否则wp_signon()将无法正常工作并且用户将被注销。

于 2015-03-11T13:15:52.720 回答