���� JFIF H H ��(ICC_PROFILE 0 mntrRGB XYZ acsp �� �- desc � trXYZ d gXYZ x bXYZ � rTRC � (gTRC � (bTRC � (wtpt � cprt � ب���V�7eud�akt��!Q,*R����G�PQ�NČzŬb 56��6��6p�z��"c8�3'���'Mq�6����G�i�t�q��l@�9��0.ۚA�����c���N|li:�9�蠃p���/��^�Zn���L���x84�v�����;[#$��n����h�'�����c���3���2o�8Ɛ5K��Av*_�?n�X�?��p��y�ֆ����̈́#�z�����2�3�F0O���e>{�Gu�.�V �(C���'h/�o%>�x1X�r:(>}�{�yc��X�8b��]�U�:�dO�Ms���VA�����p�'Z�3'3E�-�y��bj:�>��j�Ov�Uw�#�2cl~�@gF�C����jț���bz�
^:����-t��df��j{XTh���8aU���M��^+d�Al��"(KK�
m1$$
X�K�K�q�rž�o�q��g� VFF#pG~����:�]�֦��!!Ң�:pC+ �A�����zӬ�].��t�`=�'�h�_/�}����� �@L�\�,�x㌼��z+�J�-��v�+�Y��������[�'8�'��
�%�� Xq=������[4�Sj~�4�ݢ�#�d�ʂē�R�L5k��X؊���>��l���:t\��ba��B��A\Q3�8�(�<���A�;�d�)�n�ӓLr�Œ��*�|J�:
Ƒ���2rF
������G�A�8��&\�A�-�J) ��/j�`t.���E��
���A�:�T �m�"%Cb"!��7��w��
�Æ��%�;���[�]�U�zmF������kx�+��7�^�Ү�R��"7�����N+-��b7�c�,.55�H�T���E`)��P�T ci 20y=MڭyٽS��Odc�i�UJnq&~zn$�Rp��)fG'�2�'����.�mEϙ���Z����oV���u�S�]�|�A�@.���)<��+�'>�� ө����:&�$� '��L�#���d{q�H�>*5;��jDo�����
˷�����Y��m���Ԉ*[9*�5���t�Uf��%3��=
�GU������W\�'�����AR��_�W��4�_��P
�պ��
��-���|�4R��F��JZ�v0�d[ˠzJ|��PU�8��;鯌� '�V��cL�,���κ�>���*e��b)f,�0�"j1���� �1������v;�b�J��++�C�Oz7�%�>�N�U��,=z�\�c�EV�K�>Ic�7}.��jHn;^觱GHI����� �H�V����ǂO:�ߊ{mSV?K|@��
���A��iA����T`2��j �� 1�~�K8$� �~]=9ឦG�*����9�E�Mּm5X�f�9�Q�ĸ}i
D%��+t+;F��:v�:�-�&����h�_�rD�|�!� �Ә�;Z�l��븂'�������:�C�&�Ҁae��Kkm6����
�uT".}J&\� hci�B2B�+�T�7�t?EPþЌ��m�A�F\�l���c2�ЊABm�E,cն\Q���J�]d�5������������`O��
Y@�8�?lx#���K�iI&��Ri1f��R2f1N�%_�g�*T���Ө��??N:����}+ל�ɀ�h٭�q��L��,ʈ�B�r����c��u��Bmz��̢TV^� 뙏8' ����u��fUX�3㓏��>NG�:���/�;�H�p饕�B�1�K��
���/%iɫ
V�Q%�:�_ -��1o����L�?�R��oa\i^����F|����W*Na)��P��
�X�#y㯨�z+C���ح\��в�j��i�rm����*d��W�ҡQb�BȨ��i'%�NEb�?���'[����h�=`Oi��U϶�u�
���n��R�}GW�4f�VJm������i�R���~��J|l%m'��%�"�LW�� V��2���7���Ns�X�b�?_�=����{s�}ij4�Ý=SN����jx�FV�"ԎI(�E���)]�ӝ�Ж���m�[4
m��`5�-7W�����f��b�Z�K�a#Vb%��K��Y����5���T�$y`�4�6�̼�p �C�7�HM������'l{Oi�
+���Pw~j,S5T4(F�Ԩ;�A��`*HJ��TP�g�t��(6/�cg��5�U�1@Qb8�Y!����r�<���r�6h��)��[{h�h�8
���3���� ��0<�y+V�>BzOQ�KF+6�v�%=��~XD��PpW���c�_-:߈����#c�坣���C�W1�:�^�Q�� 06Ӭ�q@
Dj�$
�UW���$�?9���F�\cS���M5�=��2>�hב\,(�)�JB�k���;
�J���#j徻W�(p=�o��Q�D�
#U�Mh��U�*F��c?N���=�n���F5��Ӑ12��w�0�5Z���뀩4ڣ���霅�uC1������y�����%n���J�8Ԑ���*c��r������R���
��9W=�H�����9�,�A�,��.���ZF�b�� QEGVNs, �q�'�����;O����Mm�btN���Vq�Ow*֙kPѬ؈����X�J���I��ӯ��E������Wo�k�+��R�{��%�����j;��� ���Y��x�����
��7&&���,���LԜ���Y�bw"�lI���(*���`۹F� ����A�S����-
#$�������4����13)Q���pڤ3Rx�O�J�$c�P]v�i�uq�{��k��y�N.��-��B���,@ڸ�Ao���r%��X0�U��N��b��9 �����������7)*��23�3���|�Rn�b���@�q��|E���U���y��́$!7����&���["X�O�y� �~ƓtADhP���]��m�G�파�9�p=�ԜZ]ӭ�ሎ�O�eyq��!�b�I �GU����:�5~�F��o�L �S�T[е�$]$g��*�w]��!��;��m@�ޠ�&IU�ڬ{�҄բ-.Sm�Ғ�`���� �������vU"o�L��;�'��5s�"�W�)��@��ä���L�1i��}�^Y5�$+�P���v0o������HU
@ȓ��s�Q�M�)��?�M\��4�Q�� ��$2���;g� �WJ�/NwF�JG�D�:�y�� ��ό���Mf��W!���QUZ%a�zҳ����DK�_��X�h��M�^r�ԝ^!d��'<#ﴛ�O���{����/F�?�+�$ �Y�'
wg'$��l������jG�AH�7l�4�������x�Ѷ�c��}���I�*e�s��g�~��;ͤ��t@����B�����2�iB'�9C�a�8���f�TR:�� �����%���N�O���@�
m����3�s�v�� ��w� .@�濾��� ��,FYrT0m��UW�_v>>d�[���A�6��ڊx�:�Y�����T�L�����Hv��Ӻ!�n�S�D}�>[m�E�T0��_�,'C]���p����j�����V���ᅷ��PDZ[-��V0`����>�}��ܟpmֻ�2O6�O*����ݹ�X�HS�N(J�� /�+1՟�#(��P�*g�����EO�#�w&j�6�?;��ڡ�)+�U���]l��\�/{莄��*�I���/�����9�<'$�'#'��y�t/&�-\\WP�L`/p9�q��a'�e��¨��E]�� f��A�A�E�Y�nGtm,�ϮwXT�>AaN#���F��j��ŵj�Q�Fd������q^<�H?��y���J�܃2�*���3� T4�Ч����H���**W;�(ꭽ�¾�P�f=����e���yA���4�FJ��6{e�]J��q��OC��f#3��S�J�fi�MM\i�T�$�rG�8$��9>2��:��M)���Q�#N��K��e��&"�E�8�����.��z�<��mHk�?�#��t��˒��A���];
G0H�:��f!�i�! ���j�{���1�m�}���o��7�u;�$����99Ӱ���\n�c��z:zA�Lq�w�y��K���T<�����4�X,�'!Y;���Ͱ6�q� G�M~_�~܂}��t>���(��z�l�}:r
�L�9
fe}.-���R*<`c6��o�ܛ=�pr��ҽGB)nQ%���������)s*&i��%Zb{���m[��N�Nkb���wB����w
Q*��d��F ��HP � � iܛ�;
aV68j}\e�I��GI'͔B����;yA
�:^���bn��-�m�#�@������S6�ˎr���� ;��~�cm�ƻgU��:�X6�G��%�<�r�' dzX^}�-� �H�X�D�������-C�W`#���کpNH5�E�y��=�1���G�#�꽁���C�5Yx��z�Y_"&�A�*�C��+q7Km�1Pm��@in�88�� N��
^c.d �p� � �>[�g�c��������{]c�4�)����f�psgY��˅����>��*"1���}2<1���7����5)]���������V5)kd�kM��~`������:{���4���nG��PTT�����b�� �� �� ����뎱�϶wFFᓂG8���>z��F����_�H��9_r��D��l:������ҶH5��Z!Bj.y��k}�e�rb:SOT��]!ǎ?n:H�ε�Z�s��y�z�tn���[�7N��Z#UQO$�.�J�#]Cr#�Y��X���9���c�<��'$�������z���
9�������.�$��$P���nDS�n��2��u5���X ���g\��� �?�����|A���ᬰⶵ���
�>>�bE)�Cb����-ruMc����*,\)`^���m�
ge�\k�.�۫8��گ��oK�1��gWM�p�UzI=EE�rz:�#���6�-�-/�Wm��\z8�מ�0x
�t��A���_c�?Ծ���c�^Mژ�������I�MyO>�l0�ċ�}t7[�\�ʲ9̜��m_a[�姯�rְ�j��P�\k�x��1�'�CdmvF70e���+����m-�]a��?ݝK��uSMUm 8f� ��Yb!�)�2Z.U���D� ���\~:��ܽ8z��R�̪K�c�b�s����&ߦ��������1�$�,� w�\gc�����3F$��iU#<�`��:�I�4{w���.���2���a��Q�$�EX�<��p}�x>N���o?Gm ��N�N
rE��$#J�n҉�!��A��H'<�w���i���i͗k�;��S;(PY����y,��|� v��G!H���$��4�ƴ��@��V��!қ
7����� �$�����{��O�y���W�SY��:��I�doI�5b�_���s��G��q��$�qIOg�-���B�H]_�V���������G����!��w0�p$����n�U����#ROMB��$Zn:�BD�U���KE�4�����ec�q������}���3�������^���n��BZ�j�b��W��`l��� �Z�d�"��"�b�]nm!ij.��{&*������F���O?��c�u�]�������u�VQbj:�J�B��.Xg�J�Fsq�d祚N�
�x�ʣR��;!�$�� � �:��F�cU��$R1-�K�'ɋ� I���x8�Ϗoߠ�F~�� ���z
"��_^v�2��-����f��K ������kW8
c�.�Ms-����6�=eV�=����ev�\����������L�=� g�n22p<�?r�Fۏ�>z��eP��z��Rog�8u�(�tJ�P߁�Z���.p�Ð���͢A��ռ65�X��syvm��� 6R�W7W��;��|0�� >O��үG��@������ٳ<�>�om��Լ()���kZJlK,����F
4��)sn��������O�Q�{u㌏�=� A��o���,ծ����?eKB�zG �6e6������
������ f|�C�U�� �_�4�C[j͕M�8,%em��M���8�\� ��c�v� COwTGi�
_9��4���BDf%���'ns��8�M�P��c���������&�-�y"8R��_j���� �3a��+z+��N� �9���Q�lDQ�40�E �V���ۋ�rH�2�I�_���Y�O�',:뿉�WN�Hvﵐ0�B}n�����a*E
zUb�N#��0�e"�f.Q���� ��H��5"��-�H�Vn=�+ #� �Eiy-
�v8=�g��`���o�[
鼛�2�.�D�^�����Q����eB� q��Ͽ�R�C~
B+J�ۍ��8 ���4���*�Ӗ������Ν1��R�B��I\
�1[0
�I�9y��)���Y " 7�]6�q��g\� ��vP� ��s�= Ѭ֕)פ��E��<���c`��ϷU9�W��,:�?�y����1h�s�U(�T
g��e�/룮����J�A�]|��������4a�ZV�AI�eIhBI!�l�$��3![q�Hnw\7R�{��o�M�/�ִ��>�5&��
gw�j�F�E��� dc@K:V&�W�/k�+�=�Y�k[�@fU��5�zzmF��ȖH,[��� n�-dc� �w�d[��z"��g�4��ϘR�r�0`B��8_;�� #�$^Z�������o5K�ZYKj�GY%�����s�"!a�[9I2TF�����-�������w#a�]���˒����I�tٮ�ei_��F�pVЧ૱W�3e�Ci�7����"���}��H��A�pG>�h��֝������5i��T٧-'�`d�X1���AF$�$<���y��9~��,��n���e�boW�>ޙ_��Z]ڷ�T���C��
���U�y�
��J���G��O��}���� ���>���A"����5��a> Z�U��R�-��Z�\9�
jrW��ݖQ�Rݳ�*�ļ��]�$ڵ�Xq�=�/��w�� ��z\��I��I�#�{�ӭ��l�^;�F_R쵎�[ָ[gK�KͰ�o�Q� )W녕��і��s�*kuz�ŨQde`�WU_��KLE��~"��g r<�2G�y��އ����L�(�-V�Y��� -Z(�I�U�����0� �|�\���;�8��C���
��m����hl��:̄D��k�YHO�k��|:��*D��Y�
ts�س�|��zrO;�s�T3���1���=�j�w���y��Ш��^nZ��H���m��_G̮��0W����������S�;�����_$�mٛI��D�V��=f�-H�}����U����]H��A��*�vԶ����3\�Wh*I#$�@6�����x��^��O�Z���C&J�U� 16� X�D*��if&��B��DGFY�YP�[KL�X
u�X �.Z��h��q
Ghb��8��M#�Mq�t�\c�>��
��aT �� 00=�㎨ʕ�G�Q�Ԫ�R�����,Ĝ�I9����zӦ��JO��3Rn��`�C�5����܊@Q�O1�N.ؔ"I\�YÖ�Đ�H�d���L���������\}IP~jm�$ y�����;�����:ZG��ZV�Jv
��=&*UF#`�`R`*S+p��\=)����ҭ�9�k������̮R�x��0'����**ԑL�kɺk��+zJb�#�:|M��Z�
��?�j$ݼ &�X�)$���6�F���Y6ѕ/������;�� ��J�*n����l��C�*ų_�
�ԕ{�_�6�:\47ڷ�s��4R���m�Ċ�=����z����*��ʪ��XT��[��������]�5�Bl#a�-˙bv�8�@�H���|R���we9A%5&�M����%�Z02T���N)&&GfM
儀o�����M�;=���./�/k~ E"a9/3���y���,>��l��j��>������Z��X��y�&ε��Y�P��&h �g�e�c<�``����]!}i'c
�KQ�ulF�Iʓ_\T58��(�+cJ��q~
����[d�����gm�m/`��Xڙ�ht�k�q���ו$���"�c[P�VY�[uɜ�몵��"���Ⱦ�qC���"�Ü��Ȕ!���<����M�j8��u-�d��x��*�g��ϫ�t�T�Ld�K�laWڭ��\���~�|����7�u`��h(����w���c�L=�����˼�=�F��vcG��s�}��зU����BS�М;�FI;���Q�$8�+V|[C�S��쮙���1�%�YP��Q%�L�����VVK+&�,�c�Ib��]���Vy�i�
�~h��?y��F4��"5��A�s-���F�
݆x5���5P&E�:W@f;}��G�y���^�]U���
ITki�� ��1���� �d���*c���N���h��'�c�ؗY�n�s�L����:b��?��H� :k���M~�@����8#�I�qɔ�~��:f�]��P*i]H��'f��jhx�Tҗ�1��O��:���^t�$�1]�����UXz&������t�OD�T�����>�(^�s��&3��#N_�/�x��-�䬦?��� ~��v��U-����W$4����'�ӎ�v�������RG�|jy��SW?�u���4�(�1 G[��ِ2��2jʎ�hr�m�oյ�ش��gRͮ%ϟ�Ѭ��9� �o���R n-�����&F�-�����@����hgY�����_qN��;"2 �!K�J � šA��^, ��"�aG�8`�=1�4�=5�Mq�k�>��U@UT �:�R�gj����rK�F.�O$�I9'���=i�}.�_��
403 Forbidden
- Your IP: 216.73.216.38
- Server IP: 54.36.91.62
- Server: Linux webm008.cluster127.gra.hosting.ovh.net 6.18.42-ovh-vps-grsec-zfs+ #1 SMP PREEMPT_DYNAMIC Wed Aug 5 15:59:48 CEST 2026 x86_64
- Server Software: Apache
- PHP Version: 7.0.33
-
Buat File |
Buat Folder
. ?>
add( 'empty_username', __( 'Error: Enter a username or email address.' ) );
} elseif ( strpos( $_POST['user_login'], '@' ) ) {
$user_data = get_user_by( 'email', trim( wp_unslash( $_POST['user_login'] ) ) );
if ( empty( $user_data ) ) {
$errors->add( 'invalid_email', __( 'Error: There is no account with that username or email address.' ) );
}
} else {
$login = trim( wp_unslash( $_POST['user_login'] ) );
$user_data = get_user_by( 'login', $login );
}
/**
* Fires before errors are returned from a password reset request.
*
* @since 2.1.0
* @since 4.4.0 Added the `$errors` parameter.
* @since 5.4.0 Added the `$user_data` parameter.
*
* @param WP_Error $errors A WP_Error object containing any errors generated
* by using invalid credentials.
* @param WP_User|false WP_User object if found, false if the user does not exist.
*/
do_action( 'lostpassword_post', $errors, $user_data );
if ( $errors->has_errors() ) {
return $errors;
}
if ( ! $user_data ) {
$errors->add( 'invalidcombo', __( 'Error: There is no account with that username or email address.' ) );
return $errors;
}
// Redefining user_login ensures we return the right case in the email.
$user_login = $user_data->user_login;
$user_email = $user_data->user_email;
$key = get_password_reset_key( $user_data );
if ( is_wp_error( $key ) ) {
return $key;
}
if ( is_multisite() ) {
$site_name = get_network()->site_name;
} else {
/*
* The blogname option is escaped with esc_html on the way into the database
* in sanitize_option we want to reverse this for the plain text arena of emails.
*/
$site_name = wp_specialchars_decode( get_option( 'blogname' ), ENT_QUOTES );
}
$message = __( 'Someone has requested a password reset for the following account:' ) . "\r\n\r\n";
/* translators: %s: Site name. */
$message .= sprintf( __( 'Site Name: %s' ), $site_name ) . "\r\n\r\n";
/* translators: %s: User login. */
$message .= sprintf( __( 'Username: %s' ), $user_login ) . "\r\n\r\n";
$message .= __( 'If this was a mistake, just ignore this email and nothing will happen.' ) . "\r\n\r\n";
$message .= __( 'To reset your password, visit the following address:' ) . "\r\n\r\n";
$message .= network_site_url( "wp-login.php?action=rp&key=$key&login=" . rawurlencode( $user_login ), 'login' ) . "\r\n";
/* translators: Password reset notification email subject. %s: Site title. */
$title = sprintf( __( '[%s] Password Reset' ), $site_name );
/**
* Filters the subject of the password reset email.
*
* @since 2.8.0
* @since 4.4.0 Added the `$user_login` and `$user_data` parameters.
*
* @param string $title Default email title.
* @param string $user_login The username for the user.
* @param WP_User $user_data WP_User object.
*/
$title = apply_filters( 'retrieve_password_title', $title, $user_login, $user_data );
/**
* Filters the message body of the password reset mail.
*
* If the filtered message is empty, the password reset email will not be sent.
*
* @since 2.8.0
* @since 4.1.0 Added `$user_login` and `$user_data` parameters.
*
* @param string $message Default mail message.
* @param string $key The activation key.
* @param string $user_login The username for the user.
* @param WP_User $user_data WP_User object.
*/
$message = apply_filters( 'retrieve_password_message', $message, $key, $user_login, $user_data );
if ( $message && ! wp_mail( $user_email, wp_specialchars_decode( $title ), $message ) ) {
$errors->add(
'retrieve_password_email_failure',
sprintf(
/* translators: %s: Documentation URL. */
__( 'Error: The email could not be sent. Your site may not be correctly configured to send emails. Get support for resetting your password.' ),
esc_url( __( 'https://wordpress.org/support/article/resetting-your-password/' ) )
)
);
return $errors;
}
return true;
}
//
// Main.
//
$action = isset( $_REQUEST['action'] ) ? $_REQUEST['action'] : 'login';
$errors = new WP_Error();
if ( isset( $_GET['key'] ) ) {
$action = 'resetpass';
}
$default_actions = array(
'confirm_admin_email',
'postpass',
'logout',
'lostpassword',
'retrievepassword',
'resetpass',
'rp',
'register',
'login',
'confirmaction',
WP_Recovery_Mode_Link_Service::LOGIN_ACTION_ENTERED,
);
// Validate action so as to default to the login screen.
if ( ! in_array( $action, $default_actions, true ) && false === has_filter( 'login_form_' . $action ) ) {
$action = 'login';
}
nocache_headers();
header( 'Content-Type: ' . get_bloginfo( 'html_type' ) . '; charset=' . get_bloginfo( 'charset' ) );
if ( defined( 'RELOCATE' ) && RELOCATE ) { // Move flag is set.
if ( isset( $_SERVER['PATH_INFO'] ) && ( $_SERVER['PATH_INFO'] !== $_SERVER['PHP_SELF'] ) ) {
$_SERVER['PHP_SELF'] = str_replace( $_SERVER['PATH_INFO'], '', $_SERVER['PHP_SELF'] );
}
$url = dirname( set_url_scheme( 'http://' . $_SERVER['HTTP_HOST'] . $_SERVER['PHP_SELF'] ) );
if ( get_option( 'siteurl' ) !== $url ) {
update_option( 'siteurl', $url );
}
}
// Set a cookie now to see if they are supported by the browser.
$secure = ( 'https' === parse_url( wp_login_url(), PHP_URL_SCHEME ) );
setcookie( TEST_COOKIE, 'WP Cookie check', 0, COOKIEPATH, COOKIE_DOMAIN, $secure );
if ( SITECOOKIEPATH !== COOKIEPATH ) {
setcookie( TEST_COOKIE, 'WP Cookie check', 0, SITECOOKIEPATH, COOKIE_DOMAIN, $secure );
}
/**
* Fires when the login form is initialized.
*
* @since 3.2.0
*/
do_action( 'login_init' );
/**
* Fires before a specified login form action.
*
* The dynamic portion of the hook name, `$action`, refers to the action
* that brought the visitor to the login form. Actions include 'postpass',
* 'logout', 'lostpassword', etc.
*
* @since 2.8.0
*/
do_action( "login_form_{$action}" );
$http_post = ( 'POST' === $_SERVER['REQUEST_METHOD'] );
$interim_login = isset( $_REQUEST['interim-login'] );
/**
* Filters the separator used between login form navigation links.
*
* @since 4.9.0
*
* @param string $login_link_separator The separator used between login form navigation links.
*/
$login_link_separator = apply_filters( 'login_link_separator', ' | ' );
switch ( $action ) {
case 'confirm_admin_email':
/*
* Note that `is_user_logged_in()` will return false immediately after logging in
* as the current user is not set, see wp-includes/pluggable.php.
* However this action runs on a redirect after logging in.
*/
if ( ! is_user_logged_in() ) {
wp_safe_redirect( wp_login_url() );
exit;
}
if ( ! empty( $_REQUEST['redirect_to'] ) ) {
$redirect_to = $_REQUEST['redirect_to'];
} else {
$redirect_to = admin_url();
}
if ( current_user_can( 'manage_options' ) ) {
$admin_email = get_option( 'admin_email' );
} else {
wp_safe_redirect( $redirect_to );
exit;
}
/**
* Filters the interval for dismissing the admin email confirmation screen.
*
* If `0` (zero) is returned, the "Remind me later" link will not be displayed.
*
* @since 5.3.1
*
* @param int $interval Interval time (in seconds). Default is 3 days.
*/
$remind_interval = (int) apply_filters( 'admin_email_remind_interval', 3 * DAY_IN_SECONDS );
if ( ! empty( $_GET['remind_me_later'] ) ) {
if ( ! wp_verify_nonce( $_GET['remind_me_later'], 'remind_me_later_nonce' ) ) {
wp_safe_redirect( wp_login_url() );
exit;
}
if ( $remind_interval > 0 ) {
update_option( 'admin_email_lifespan', time() + $remind_interval );
}
wp_safe_redirect( $redirect_to );
exit;
}
if ( ! empty( $_POST['correct-admin-email'] ) ) {
if ( ! check_admin_referer( 'confirm_admin_email', 'confirm_admin_email_nonce' ) ) {
wp_safe_redirect( wp_login_url() );
exit;
}
/**
* Filters the interval for redirecting the user to the admin email confirmation screen.
*
* If `0` (zero) is returned, the user will not be redirected.
*
* @since 5.3.0
*
* @param int $interval Interval time (in seconds). Default is 6 months.
*/
$admin_email_check_interval = (int) apply_filters( 'admin_email_check_interval', 6 * MONTH_IN_SECONDS );
if ( $admin_email_check_interval > 0 ) {
update_option( 'admin_email_lifespan', time() + $admin_email_check_interval );
}
wp_safe_redirect( $redirect_to );
exit;
}
login_header( __( 'Confirm your administration email' ), '', $errors );
/**
* Fires before the admin email confirm form.
*
* @since 5.3.0
*
* @param WP_Error $errors A `WP_Error` object containing any errors generated by using invalid
* credentials. Note that the error object may not contain any errors.
*/
do_action( 'admin_email_confirm', $errors );
?>
HashPassword( wp_unslash( $_POST['post_password'] ) ), $expire, COOKIEPATH, COOKIE_DOMAIN, $secure );
wp_safe_redirect( wp_get_referer() );
exit();
case 'logout':
check_admin_referer( 'log-out' );
$user = wp_get_current_user();
wp_logout();
if ( ! empty( $_REQUEST['redirect_to'] ) ) {
$redirect_to = $_REQUEST['redirect_to'];
$requested_redirect_to = $redirect_to;
} else {
$redirect_to = add_query_arg(
array(
'loggedout' => 'true',
'wp_lang' => get_user_locale( $user ),
),
wp_login_url()
);
$requested_redirect_to = '';
}
/**
* Filters the log out redirect URL.
*
* @since 4.2.0
*
* @param string $redirect_to The redirect destination URL.
* @param string $requested_redirect_to The requested redirect destination URL passed as a parameter.
* @param WP_User $user The WP_User object for the user that's logging out.
*/
$redirect_to = apply_filters( 'logout_redirect', $redirect_to, $requested_redirect_to, $user );
wp_safe_redirect( $redirect_to );
exit();
case 'lostpassword':
case 'retrievepassword':
if ( $http_post ) {
$errors = retrieve_password();
if ( ! is_wp_error( $errors ) ) {
$redirect_to = ! empty( $_REQUEST['redirect_to'] ) ? $_REQUEST['redirect_to'] : 'wp-login.php?checkemail=confirm';
wp_safe_redirect( $redirect_to );
exit();
}
}
if ( isset( $_GET['error'] ) ) {
if ( 'invalidkey' === $_GET['error'] ) {
$errors->add( 'invalidkey', __( 'Your password reset link appears to be invalid. Please request a new link below.' ) );
} elseif ( 'expiredkey' === $_GET['error'] ) {
$errors->add( 'expiredkey', __( 'Your password reset link has expired. Please request a new link below.' ) );
}
}
$lostpassword_redirect = ! empty( $_REQUEST['redirect_to'] ) ? $_REQUEST['redirect_to'] : '';
/**
* Filters the URL redirected to after submitting the lostpassword/retrievepassword form.
*
* @since 3.0.0
*
* @param string $lostpassword_redirect The redirect destination URL.
*/
$redirect_to = apply_filters( 'lostpassword_redirect', $lostpassword_redirect );
/**
* Fires before the lost password form.
*
* @since 1.5.1
* @since 5.1.0 Added the `$errors` parameter.
*
* @param WP_Error $errors A `WP_Error` object containing any errors generated by using invalid
* credentials. Note that the error object may not contain any errors.
*/
do_action( 'lost_password', $errors );
login_header( __( 'Lost Password' ), '' . __( 'Please enter your username or email address. You will receive an email message with instructions on how to reset your password.' ) . '
', $errors );
$user_login = '';
if ( isset( $_POST['user_login'] ) && is_string( $_POST['user_login'] ) ) {
$user_login = wp_unslash( $_POST['user_login'] );
}
?>
%s', esc_url( wp_registration_url() ), __( 'Register' ) );
echo esc_html( $login_link_separator );
/** This filter is documented in wp-includes/general-template.php */
echo apply_filters( 'register', $registration_url );
}
?>
get_error_code() === 'expired_key' ) {
wp_redirect( site_url( 'wp-login.php?action=lostpassword&error=expiredkey' ) );
} else {
wp_redirect( site_url( 'wp-login.php?action=lostpassword&error=invalidkey' ) );
}
exit;
}
$errors = new WP_Error();
if ( isset( $_POST['pass1'] ) && $_POST['pass1'] !== $_POST['pass2'] ) {
$errors->add( 'password_reset_mismatch', __( 'The passwords do not match.' ) );
}
/**
* Fires before the password reset procedure is validated.
*
* @since 3.5.0
*
* @param WP_Error $errors WP Error object.
* @param WP_User|WP_Error $user WP_User object if the login and reset key match. WP_Error object otherwise.
*/
do_action( 'validate_password_reset', $errors, $user );
if ( ( ! $errors->has_errors() ) && isset( $_POST['pass1'] ) && ! empty( $_POST['pass1'] ) ) {
reset_password( $user, $_POST['pass1'] );
setcookie( $rp_cookie, ' ', time() - YEAR_IN_SECONDS, $rp_path, COOKIE_DOMAIN, is_ssl(), true );
login_header( __( 'Password Reset' ), '' . __( 'Your password has been reset.' ) . ' ' . __( 'Log in' ) . '
' );
login_footer();
exit;
}
wp_enqueue_script( 'utils' );
wp_enqueue_script( 'user-profile' );
login_header( __( 'Reset Password' ), '' . __( 'Enter your new password below.' ) . '
', $errors );
?>
%s', esc_url( wp_registration_url() ), __( 'Register' ) );
echo esc_html( $login_link_separator );
/** This filter is documented in wp-includes/general-template.php */
echo apply_filters( 'register', $registration_url );
}
?>
' . __( 'Register For This Site' ) . '
', $errors );
?>
ID ) ) {
$secure_cookie = true;
force_ssl_admin( true );
}
}
}
if ( isset( $_REQUEST['redirect_to'] ) ) {
$redirect_to = $_REQUEST['redirect_to'];
// Redirect to HTTPS if user wants SSL.
if ( $secure_cookie && false !== strpos( $redirect_to, 'wp-admin' ) ) {
$redirect_to = preg_replace( '|^http://|', 'https://', $redirect_to );
}
} else {
$redirect_to = admin_url();
}
$reauth = empty( $_REQUEST['reauth'] ) ? false : true;
$user = wp_signon( array(), $secure_cookie );
if ( empty( $_COOKIE[ LOGGED_IN_COOKIE ] ) ) {
if ( headers_sent() ) {
$user = new WP_Error(
'test_cookie',
sprintf(
/* translators: 1: Browser cookie documentation URL, 2: Support forums URL. */
__( 'Error: Cookies are blocked due to unexpected output. For help, please see this documentation or try the support forums.' ),
__( 'https://wordpress.org/support/article/cookies/' ),
__( 'https://wordpress.org/support/forums/' )
)
);
} elseif ( isset( $_POST['testcookie'] ) && empty( $_COOKIE[ TEST_COOKIE ] ) ) {
// If cookies are disabled, we can't log in even with a valid user and password.
$user = new WP_Error(
'test_cookie',
sprintf(
/* translators: %s: Browser cookie documentation URL. */
__( 'Error: Cookies are blocked or not supported by your browser. You must enable cookies to use WordPress.' ),
__( 'https://wordpress.org/support/article/cookies/#enable-cookies-in-your-browser' )
)
);
}
}
$requested_redirect_to = isset( $_REQUEST['redirect_to'] ) ? $_REQUEST['redirect_to'] : '';
/**
* Filters the login redirect URL.
*
* @since 3.0.0
*
* @param string $redirect_to The redirect destination URL.
* @param string $requested_redirect_to The requested redirect destination URL passed as a parameter.
* @param WP_User|WP_Error $user WP_User object if login was successful, WP_Error object otherwise.
*/
$redirect_to = apply_filters( 'login_redirect', $redirect_to, $requested_redirect_to, $user );
if ( ! is_wp_error( $user ) && ! $reauth ) {
if ( $interim_login ) {
$message = '' . __( 'You have logged in successfully.' ) . '
';
$interim_login = 'success';
login_header( '', $message );
?>
exists() && $user->has_cap( 'manage_options' ) ) {
$admin_email_lifespan = (int) get_option( 'admin_email_lifespan' );
// If `0` (or anything "falsey" as it is cast to int) is returned, the user will not be redirected
// to the admin email confirmation screen.
/** This filter is documented in wp-login.php */
$admin_email_check_interval = (int) apply_filters( 'admin_email_check_interval', 6 * MONTH_IN_SECONDS );
if ( $admin_email_check_interval > 0 && time() > $admin_email_lifespan ) {
$redirect_to = add_query_arg(
array(
'action' => 'confirm_admin_email',
'wp_lang' => get_user_locale( $user ),
),
wp_login_url( $redirect_to )
);
}
}
if ( ( empty( $redirect_to ) || 'wp-admin/' === $redirect_to || admin_url() === $redirect_to ) ) {
// If the user doesn't belong to a blog, send them to user admin. If the user can't edit posts, send them to their profile.
if ( is_multisite() && ! get_active_blog_for_user( $user->ID ) && ! is_super_admin( $user->ID ) ) {
$redirect_to = user_admin_url();
} elseif ( is_multisite() && ! $user->has_cap( 'read' ) ) {
$redirect_to = get_dashboard_url( $user->ID );
} elseif ( ! $user->has_cap( 'edit_posts' ) ) {
$redirect_to = $user->has_cap( 'read' ) ? admin_url( 'profile.php' ) : home_url();
}
wp_redirect( $redirect_to );
exit;
}
wp_safe_redirect( $redirect_to );
exit;
}
$errors = $user;
// Clear errors if loggedout is set.
if ( ! empty( $_GET['loggedout'] ) || $reauth ) {
$errors = new WP_Error();
}
if ( empty( $_POST ) && $errors->get_error_codes() === array( 'empty_username', 'empty_password' ) ) {
$errors = new WP_Error( '', '' );
}
if ( $interim_login ) {
if ( ! $errors->has_errors() ) {
$errors->add( 'expired', __( 'Your session has expired. Please log in to continue where you left off.' ), 'message' );
}
} else {
// Some parts of this script use the main login form to display a message.
if ( isset( $_GET['loggedout'] ) && $_GET['loggedout'] ) {
$errors->add( 'loggedout', __( 'You are now logged out.' ), 'message' );
} elseif ( isset( $_GET['registration'] ) && 'disabled' === $_GET['registration'] ) {
$errors->add( 'registerdisabled', __( 'User registration is currently not allowed.' ) );
} elseif ( isset( $_GET['checkemail'] ) && 'confirm' === $_GET['checkemail'] ) {
$errors->add( 'confirm', __( 'Check your email for the confirmation link.' ), 'message' );
} elseif ( isset( $_GET['checkemail'] ) && 'newpass' === $_GET['checkemail'] ) {
$errors->add( 'newpass', __( 'Check your email for your new password.' ), 'message' );
} elseif ( isset( $_GET['checkemail'] ) && 'registered' === $_GET['checkemail'] ) {
$errors->add( 'registered', __( 'Registration complete. Please check your email.' ), 'message' );
} elseif ( strpos( $redirect_to, 'about.php?updated' ) ) {
$errors->add( 'updated', __( 'You have successfully updated WordPress! Please log back in to see what’s new.' ), 'message' );
} elseif ( WP_Recovery_Mode_Link_Service::LOGIN_ACTION_ENTERED === $action ) {
$errors->add( 'enter_recovery_mode', __( 'Recovery Mode Initialized. Please log in to continue.' ), 'message' );
}
}
/**
* Filters the login page errors.
*
* @since 3.6.0
*
* @param WP_Error $errors WP Error object.
* @param string $redirect_to Redirect destination URL.
*/
$errors = apply_filters( 'wp_login_errors', $errors, $redirect_to );
// Clear any stale cookies.
if ( $reauth ) {
wp_clear_auth_cookie();
}
login_header( __( 'Log In' ), '', $errors );
if ( isset( $_POST['log'] ) ) {
$user_login = ( 'incorrect_password' === $errors->get_error_code() || 'empty_password' === $errors->get_error_code() ) ? esc_attr( wp_unslash( $_POST['log'] ) ) : '';
}
$rememberme = ! empty( $_POST['rememberme'] );
if ( $errors->has_errors() ) {
$aria_describedby_error = ' aria-describedby="login_error"';
} else {
$aria_describedby_error = '';
}
wp_enqueue_script( 'user-profile' );
?>
%s', esc_url( wp_registration_url() ), __( 'Register' ) );
/** This filter is documented in wp-includes/general-template.php */
echo apply_filters( 'register', $registration_url );
echo esc_html( $login_link_separator );
}
?>
get_error_code() === 'invalid_username' ) {
$login_script .= 'd.value = "";';
}
}
$login_script .= 'd.focus(); d.select();';
$login_script .= '} catch( er ) {}';
$login_script .= '}, 200);';
$login_script .= "}\n"; // End of wp_attempt_focus().
/**
* Filters whether to print the call to `wp_attempt_focus()` on the login screen.
*
* @since 4.8.0
*
* @param bool $print Whether to print the function call. Default true.
*/
if ( apply_filters( 'enable_login_autofocus', true ) && ! $error ) {
$login_script .= "wp_attempt_focus();\n";
}
// Run `wpOnload()` if defined.
$login_script .= "if ( typeof wpOnload === 'function' ) { wpOnload() }";
?>