Skip to content
Draft
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
24 changes: 17 additions & 7 deletions class-two-factor-core.php
Original file line number Diff line number Diff line change
Expand Up @@ -984,7 +984,9 @@ public static function show_two_factor_login( $user ) {
wp_die( esc_html__( 'Failed to create a login nonce.', 'two-factor' ) );
}

$redirect_to = isset( $_REQUEST['redirect_to'] ) ? $_REQUEST['redirect_to'] : admin_url();
$redirect_to = isset( $_REQUEST['redirect_to'] )
? wp_unslash( $_REQUEST['redirect_to'] )
: apply_filters( 'login_redirect', admin_url(), '', $user );

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm not sure this necessarily should be part of the PR? It feels different in what it's trying to do. Also, I'm not certain this is the right application -- if we're letting the redirect be filtered by adding this, shouldn't we pass it higher up on the whole $redirect_to ?


self::login_html( $user, $login_nonce['key'], $redirect_to );
}
Expand Down Expand Up @@ -1250,13 +1252,21 @@ public static function login_url( $params = array(), $scheme = 'login' ) {
$params = array();
}

$params = urlencode_deep( $params );
// Use WordPress's own wp_login_url() so that plugins like WPML which
// hook the `login_url` filter can translate or rewrite the URL correctly.
// wp_login_url() applies the `login_url` filter, giving multilingual
// plugins a chance to redirect to a translated login page. Any requested
// scheme is applied below with set_url_scheme().
$action = isset( $params['action'] ) ? $params['action'] : '';
$url = wp_login_url( '', false );

// Compat: Match WordPress's usage of `site_url( wp-login.php )` by always passing the action if known.
if ( isset( $params['action'] ) ) {
$url = site_url( 'wp-login.php?action=' . $params['action'], $scheme );
} else {
$url = site_url( 'wp-login.php', $scheme );
// Re-apply the scheme since wp_login_url() doesn't expose it as a parameter.
$url = set_url_scheme( $url, $scheme );

// Compat: WordPress core passes action as a query argument on the login URL
// for certain actions (e.g. wp-login.php?action=validate_2fa). Preserve that behaviour.
if ( $action ) {
$url = add_query_arg( 'action', $action, $url );
}

if ( $params ) {
Expand Down
Loading