Login and Registration: Allow email logins to be more flexible.
Allows a login to have an apostorphe. Which would normally be created as a mistake, but this allows the login to happen. Fixes #38744 Props wpkuf, desrosj, socalchristina, bibliofille, santilinwp, nsubugak, sncoker, cafenoirdesign, whyisjake. Built from https://develop.svn.wordpress.org/trunk@46640 git-svn-id: http://core.svn.wordpress.org/trunk@46440 1a063a9b-81f0-0310-95a4-ce76da25c4cd
This commit is contained in:
parent
44db7e4f6f
commit
a87271af60
|
@ -41,7 +41,7 @@ function edit_user( $user_id = 0 ) {
|
||||||
}
|
}
|
||||||
|
|
||||||
if ( ! $update && isset( $_POST['user_login'] ) ) {
|
if ( ! $update && isset( $_POST['user_login'] ) ) {
|
||||||
$user->user_login = sanitize_user( $_POST['user_login'], true );
|
$user->user_login = sanitize_user( wp_unslash( $_POST['user_login'] ), true );
|
||||||
}
|
}
|
||||||
|
|
||||||
$pass1 = '';
|
$pass1 = '';
|
||||||
|
|
|
@ -35,7 +35,7 @@ function wp_signon( $credentials = array(), $secure_cookie = '' ) {
|
||||||
$credentials = array(); // Back-compat for plugins passing an empty string.
|
$credentials = array(); // Back-compat for plugins passing an empty string.
|
||||||
|
|
||||||
if ( ! empty( $_POST['log'] ) ) {
|
if ( ! empty( $_POST['log'] ) ) {
|
||||||
$credentials['user_login'] = $_POST['log'];
|
$credentials['user_login'] = wp_unslash( $_POST['log'] );
|
||||||
}
|
}
|
||||||
if ( ! empty( $_POST['pwd'] ) ) {
|
if ( ! empty( $_POST['pwd'] ) ) {
|
||||||
$credentials['user_password'] = $_POST['pwd'];
|
$credentials['user_password'] = $_POST['pwd'];
|
||||||
|
|
|
@ -13,7 +13,7 @@
|
||||||
*
|
*
|
||||||
* @global string $wp_version
|
* @global string $wp_version
|
||||||
*/
|
*/
|
||||||
$wp_version = '5.4-alpha-46638';
|
$wp_version = '5.4-alpha-46640';
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Holds the WordPress DB revision, increments when changes are made to the WordPress DB schema.
|
* Holds the WordPress DB revision, increments when changes are made to the WordPress DB schema.
|
||||||
|
|
|
@ -1032,7 +1032,7 @@ switch ( $action ) {
|
||||||
|
|
||||||
if ( $http_post ) {
|
if ( $http_post ) {
|
||||||
if ( isset( $_POST['user_login'] ) && is_string( $_POST['user_login'] ) ) {
|
if ( isset( $_POST['user_login'] ) && is_string( $_POST['user_login'] ) ) {
|
||||||
$user_login = $_POST['user_login'];
|
$user_login = wp_unslash( $_POST['user_login'] );
|
||||||
}
|
}
|
||||||
|
|
||||||
if ( isset( $_POST['user_email'] ) && is_string( $_POST['user_email'] ) ) {
|
if ( isset( $_POST['user_email'] ) && is_string( $_POST['user_email'] ) ) {
|
||||||
|
@ -1150,7 +1150,7 @@ switch ( $action ) {
|
||||||
|
|
||||||
// If the user wants SSL but the session is not SSL, force a secure cookie.
|
// If the user wants SSL but the session is not SSL, force a secure cookie.
|
||||||
if ( ! empty( $_POST['log'] ) && ! force_ssl_admin() ) {
|
if ( ! empty( $_POST['log'] ) && ! force_ssl_admin() ) {
|
||||||
$user_name = sanitize_user( $_POST['log'] );
|
$user_name = sanitize_user( wp_unslash( $_POST['log'] ) );
|
||||||
$user = get_user_by( 'login', $user_name );
|
$user = get_user_by( 'login', $user_name );
|
||||||
|
|
||||||
if ( ! $user && strpos( $user_name, '@' ) ) {
|
if ( ! $user && strpos( $user_name, '@' ) ) {
|
||||||
|
|
Loading…
Reference in New Issue