wp-login.php 28.6 KB
Newer Older
godog's avatar
godog committed
1 2 3 4 5 6 7 8 9 10 11 12 13 14
<?php
/**
 * WordPress User Page
 *
 * Handles authentication, registering, resetting passwords, forgot password,
 * and other user handling.
 *
 * @package WordPress
 */

/** Make sure that the WordPress bootstrap has run before continuing. */
require( dirname(__FILE__) . '/wp-load.php' );

// Redirect to https login if forced to use SSL
lechuck's avatar
lechuck committed
15
if ( force_ssl_admin() && ! is_ssl() ) {
godog's avatar
godog committed
16
	if ( 0 === strpos($_SERVER['REQUEST_URI'], 'http') ) {
lechuck's avatar
lechuck committed
17
		wp_redirect( set_url_scheme( $_SERVER['REQUEST_URI'], 'https' ) );
godog's avatar
godog committed
18 19
		exit();
	} else {
lechuck's avatar
lechuck committed
20
		wp_redirect( 'https://' . $_SERVER['HTTP_HOST'] . $_SERVER['REQUEST_URI'] );
godog's avatar
godog committed
21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41
		exit();
	}
}

/**
 * Outputs the header for the login page.
 *
 * @uses do_action() Calls the 'login_head' for outputting HTML in the Log In
 *		header.
 * @uses apply_filters() Calls 'login_headerurl' for the top login link.
 * @uses apply_filters() Calls 'login_headertitle' for the top login title.
 * @uses apply_filters() Calls 'login_message' on the message to display in the
 *		header.
 * @uses $error The error global, which is checked for displaying errors.
 *
 * @param string $title Optional. WordPress Log In Page title to display in
 *		<title/> element.
 * @param string $message Optional. Message to display in header.
 * @param WP_Error $wp_error Optional. WordPress Error Object
 */
function login_header($title = 'Log In', $message = '', $wp_error = '') {
lechuck's avatar
lechuck committed
42
	global $error, $interim_login, $current_site, $action;
godog's avatar
godog committed
43 44

	// Don't index any of these forms
root's avatar
root committed
45
	add_action( 'login_head', 'wp_no_robots' );
godog's avatar
godog committed
46 47 48 49 50 51 52 53 54 55 56

	if ( empty($wp_error) )
		$wp_error = new WP_Error();

	// Shake it!
	$shake_error_codes = array( 'empty_password', 'empty_email', 'invalid_email', 'invalidcombo', 'empty_username', 'invalid_username', 'incorrect_password' );
	$shake_error_codes = apply_filters( 'shake_error_codes', $shake_error_codes );

	if ( $shake_error_codes && $wp_error->get_error_code() && in_array( $wp_error->get_error_code(), $shake_error_codes ) )
		add_action( 'login_head', 'wp_shake_js', 12 );

lechuck's avatar
lechuck committed
57 58 59
	?><!DOCTYPE html>
	<html xmlns="http://www.w3.org/1999/xhtml" <?php language_attributes(); ?>>
	<head>
godog's avatar
godog committed
60
	<meta http-equiv="Content-Type" content="<?php bloginfo('html_type'); ?>; charset=<?php bloginfo('charset'); ?>" />
shammash's avatar
shammash committed
61
	<title><?php bloginfo('name'); ?> &rsaquo; <?php echo $title; ?></title>
lechuck's avatar
lechuck committed
62 63
	<?php

root's avatar
root committed
64
	wp_admin_css( 'wp-admin', true );
godog's avatar
godog committed
65 66
	wp_admin_css( 'colors-fresh', true );

lechuck's avatar
lechuck committed
67 68
	if ( wp_is_mobile() ) { ?>
		<meta name="viewport" content="width=320; initial-scale=0.9; maximum-scale=1.0; user-scalable=0;" /><?php
godog's avatar
godog committed
69 70
	}

root's avatar
root committed
71
	do_action( 'login_enqueue_scripts' );
lechuck's avatar
lechuck committed
72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88
	do_action( 'login_head' );

	if ( is_multisite() ) {
		$login_header_url   = network_home_url();
		$login_header_title = $current_site->site_name;
	} else {
		$login_header_url   = __( 'http://wordpress.org/' );
		$login_header_title = __( 'Powered by WordPress' );
	}

	$login_header_url   = apply_filters( 'login_headerurl',   $login_header_url   );
	$login_header_title = apply_filters( 'login_headertitle', $login_header_title );

	// Don't allow interim logins to navigate away from the page.
	if ( $interim_login )
		$login_header_url = '#';

lechuck's avatar
lechuck committed
89 90 91 92 93 94
	$classes = array( 'login-action-' . $action, 'wp-core-ui' );
	if ( wp_is_mobile() )
		$classes[] = 'mobile';
	if ( is_rtl() )
		$classes[] = 'rtl';
	$classes = apply_filters( 'login_body_class', $classes, $action );
lechuck's avatar
lechuck committed
95 96
	?>
	</head>
lechuck's avatar
lechuck committed
97
	<body class="login <?php echo esc_attr( implode( ' ', $classes ) ); ?>">
lechuck's avatar
lechuck committed
98 99 100 101 102
	<div id="login">
		<h1><a href="<?php echo esc_url( $login_header_url ); ?>" title="<?php echo esc_attr( $login_header_title ); ?>"><?php bloginfo( 'name' ); ?></a></h1>
	<?php

	unset( $login_header_url, $login_header_title );
godog's avatar
godog committed
103 104

	$message = apply_filters('login_message', $message);
lechuck's avatar
lechuck committed
105 106
	if ( !empty( $message ) )
		echo $message . "\n";
godog's avatar
godog committed
107

shammash's avatar
shammash committed
108
	// In case a plugin uses $error rather than the $wp_errors object
godog's avatar
godog committed
109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131
	if ( !empty( $error ) ) {
		$wp_error->add('error', $error);
		unset($error);
	}

	if ( $wp_error->get_error_code() ) {
		$errors = '';
		$messages = '';
		foreach ( $wp_error->get_error_codes() as $code ) {
			$severity = $wp_error->get_error_data($code);
			foreach ( $wp_error->get_error_messages($code) as $error ) {
				if ( 'message' == $severity )
					$messages .= '	' . $error . "<br />\n";
				else
					$errors .= '	' . $error . "<br />\n";
			}
		}
		if ( !empty($errors) )
			echo '<div id="login_error">' . apply_filters('login_errors', $errors) . "</div>\n";
		if ( !empty($messages) )
			echo '<p class="message">' . apply_filters('login_messages', $messages) . "</p>\n";
	}
} // End of login_header()
root's avatar
root committed
132 133 134 135 136 137 138

/**
 * Outputs the footer for the login page.
 *
 * @param string $input_id Which input to auto-focus
 */
function login_footer($input_id = '') {
lechuck's avatar
lechuck committed
139 140 141 142
	global $interim_login;

	// Don't allow interim logins to navigate away from the page.
	if ( ! $interim_login ): ?>
root's avatar
root committed
143
	<p id="backtoblog"><a href="<?php echo esc_url( home_url( '/' ) ); ?>" title="<?php esc_attr_e( 'Are you lost?' ); ?>"><?php printf( __( '&larr; Back to %s' ), get_bloginfo( 'title', 'display' ) ); ?></a></p>
lechuck's avatar
lechuck committed
144
	<?php endif; ?>
root's avatar
root committed
145

lechuck's avatar
lechuck committed
146
	</div>
shammash's avatar
shammash committed
147

lechuck's avatar
lechuck committed
148 149 150 151 152 153 154 155 156 157 158 159
	<?php if ( !empty($input_id) ) : ?>
	<script type="text/javascript">
	try{document.getElementById('<?php echo $input_id; ?>').focus();}catch(e){}
	if(typeof wpOnload=='function')wpOnload();
	</script>
	<?php endif; ?>

	<?php do_action('login_footer'); ?>
	<div class="clear"></div>
	</body>
	</html>
	<?php
root's avatar
root committed
160 161
}

godog's avatar
godog committed
162
function wp_shake_js() {
lechuck's avatar
lechuck committed
163
	if ( wp_is_mobile() )
godog's avatar
godog committed
164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187
		return;
?>
<script type="text/javascript">
addLoadEvent = function(func){if(typeof jQuery!="undefined")jQuery(document).ready(func);else if(typeof wpOnload!='function'){wpOnload=func;}else{var oldonload=wpOnload;wpOnload=function(){oldonload();func();}}};
function s(id,pos){g(id).left=pos+'px';}
function g(id){return document.getElementById(id).style;}
function shake(id,a,d){c=a.shift();s(id,c);if(a.length>0){setTimeout(function(){shake(id,a,d);},d);}else{try{g(id).position='static';wp_attempt_focus();}catch(e){}}}
addLoadEvent(function(){ var p=new Array(15,30,15,0,-15,-30,-15,0);p=p.concat(p.concat(p));var i=document.forms[0].id;g(i).position='relative';shake(i,p,20);});
</script>
<?php
}

/**
 * Handles sending password retrieval email to user.
 *
 * @uses $wpdb WordPress Database object
 *
 * @return bool|WP_Error True: when finish. WP_Error on error
 */
function retrieve_password() {
	global $wpdb, $current_site;

	$errors = new WP_Error();

root's avatar
root committed
188
	if ( empty( $_POST['user_login'] ) ) {
godog's avatar
godog committed
189
		$errors->add('empty_username', __('<strong>ERROR</strong>: Enter a username or e-mail address.'));
root's avatar
root committed
190 191 192
	} else if ( strpos( $_POST['user_login'], '@' ) ) {
		$user_data = get_user_by( 'email', trim( $_POST['user_login'] ) );
		if ( empty( $user_data ) )
godog's avatar
godog committed
193 194 195
			$errors->add('invalid_email', __('<strong>ERROR</strong>: There is no user registered with that email address.'));
	} else {
		$login = trim($_POST['user_login']);
root's avatar
root committed
196
		$user_data = get_user_by('login', $login);
godog's avatar
godog committed
197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230
	}

	do_action('lostpassword_post');

	if ( $errors->get_error_code() )
		return $errors;

	if ( !$user_data ) {
		$errors->add('invalidcombo', __('<strong>ERROR</strong>: Invalid username or e-mail.'));
		return $errors;
	}

	// redefining user_login ensures we return the right case in the email
	$user_login = $user_data->user_login;
	$user_email = $user_data->user_email;

	do_action('retreive_password', $user_login);  // Misspelled and deprecated
	do_action('retrieve_password', $user_login);

	$allow = apply_filters('allow_password_reset', true, $user_data->ID);

	if ( ! $allow )
		return new WP_Error('no_password_reset', __('Password reset is not allowed for this user'));
	else if ( is_wp_error($allow) )
		return $allow;

	$key = $wpdb->get_var($wpdb->prepare("SELECT user_activation_key FROM $wpdb->users WHERE user_login = %s", $user_login));
	if ( empty($key) ) {
		// Generate something random for a key...
		$key = wp_generate_password(20, false);
		do_action('retrieve_password_key', $user_login, $key);
		// Now insert the new md5 key into the db
		$wpdb->update($wpdb->users, array('user_activation_key' => $key), array('user_login' => $user_login));
	}
root's avatar
root committed
231
	$message = __('Someone requested that the password be reset for the following account:') . "\r\n\r\n";
lechuck's avatar
lechuck committed
232
	$message .= network_home_url( '/' ) . "\r\n\r\n";
godog's avatar
godog committed
233
	$message .= sprintf(__('Username: %s'), $user_login) . "\r\n\r\n";
root's avatar
root committed
234 235 236
	$message .= __('If this was a mistake, just ignore this email and nothing will happen.') . "\r\n\r\n";
	$message .= __('To reset your password, visit the following address:') . "\r\n\r\n";
	$message .= '<' . network_site_url("wp-login.php?action=rp&key=$key&login=" . rawurlencode($user_login), 'login') . ">\r\n";
godog's avatar
godog committed
237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256

	if ( is_multisite() )
		$blogname = $GLOBALS['current_site']->site_name;
	else
		// The blogname option is escaped with esc_html on the way into the database in sanitize_option
		// we want to reverse this for the plain text arena of emails.
		$blogname = wp_specialchars_decode(get_option('blogname'), ENT_QUOTES);

	$title = sprintf( __('[%s] Password Reset'), $blogname );

	$title = apply_filters('retrieve_password_title', $title);
	$message = apply_filters('retrieve_password_message', $message, $key);

	if ( $message && !wp_mail($user_email, $title, $message) )
		wp_die( __('The e-mail could not be sent.') . "<br />\n" . __('Possible reason: your host may have disabled the mail() function...') );

	return true;
}

/**
root's avatar
root committed
257
 * Retrieves a user row based on password reset key and login
godog's avatar
godog committed
258 259 260 261
 *
 * @uses $wpdb WordPress Database object
 *
 * @param string $key Hash to validate sending user's password
root's avatar
root committed
262
 * @param string $login The user login
lechuck's avatar
lechuck committed
263
 * @return object|WP_Error User's database row on success, error object for invalid keys
godog's avatar
godog committed
264
 */
root's avatar
root committed
265
function check_password_reset_key($key, $login) {
godog's avatar
godog committed
266 267 268 269 270 271 272 273 274 275 276
	global $wpdb;

	$key = preg_replace('/[^a-z0-9]/i', '', $key);

	if ( empty( $key ) || !is_string( $key ) )
		return new WP_Error('invalid_key', __('Invalid key'));

	if ( empty($login) || !is_string($login) )
		return new WP_Error('invalid_key', __('Invalid key'));

	$user = $wpdb->get_row($wpdb->prepare("SELECT * FROM $wpdb->users WHERE user_activation_key = %s AND user_login = %s", $key, $login));
root's avatar
root committed
277

godog's avatar
godog committed
278 279 280
	if ( empty( $user ) )
		return new WP_Error('invalid_key', __('Invalid key'));

root's avatar
root committed
281 282
	return $user;
}
godog's avatar
godog committed
283

root's avatar
root committed
284 285 286
/**
 * Handles resetting the user's password.
 *
lechuck's avatar
lechuck committed
287 288
 * @param object $user The user
 * @param string $new_pass New password for the user in plaintext
root's avatar
root committed
289 290
 */
function reset_password($user, $new_pass) {
godog's avatar
godog committed
291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317
	do_action('password_reset', $user, $new_pass);

	wp_set_password($new_pass, $user->ID);

	wp_password_change_notification($user);
}

/**
 * Handles registering a new user.
 *
 * @param string $user_login User's username for logging in
 * @param string $user_email User's email address to send password and add
 * @return int|WP_Error Either user's ID or error on failure.
 */
function register_new_user( $user_login, $user_email ) {
	$errors = new WP_Error();

	$sanitized_user_login = sanitize_user( $user_login );
	$user_email = apply_filters( 'user_registration_email', $user_email );

	// Check the username
	if ( $sanitized_user_login == '' ) {
		$errors->add( 'empty_username', __( '<strong>ERROR</strong>: Please enter a username.' ) );
	} elseif ( ! validate_username( $user_login ) ) {
		$errors->add( 'invalid_username', __( '<strong>ERROR</strong>: This username is invalid because it uses illegal characters. Please enter a valid username.' ) );
		$sanitized_user_login = '';
	} elseif ( username_exists( $sanitized_user_login ) ) {
lechuck's avatar
lechuck committed
318
		$errors->add( 'username_exists', __( '<strong>ERROR</strong>: This username is already registered. Please choose another one.' ) );
godog's avatar
godog committed
319 320 321 322 323 324 325 326 327 328 329 330 331 332 333 334 335 336 337
	}

	// Check the e-mail address
	if ( $user_email == '' ) {
		$errors->add( 'empty_email', __( '<strong>ERROR</strong>: Please type your e-mail address.' ) );
	} elseif ( ! is_email( $user_email ) ) {
		$errors->add( 'invalid_email', __( '<strong>ERROR</strong>: The email address isn&#8217;t correct.' ) );
		$user_email = '';
	} elseif ( email_exists( $user_email ) ) {
		$errors->add( 'email_exists', __( '<strong>ERROR</strong>: This email is already registered, please choose another one.' ) );
	}

	do_action( 'register_post', $sanitized_user_login, $user_email, $errors );

	$errors = apply_filters( 'registration_errors', $errors, $sanitized_user_login, $user_email );

	if ( $errors->get_error_code() )
		return $errors;

root's avatar
root committed
338
	$user_pass = wp_generate_password( 12, false);
godog's avatar
godog committed
339 340 341 342 343 344 345 346 347 348 349 350 351 352 353 354 355 356 357 358 359 360 361 362
	$user_id = wp_create_user( $sanitized_user_login, $user_pass, $user_email );
	if ( ! $user_id ) {
		$errors->add( 'registerfail', sprintf( __( '<strong>ERROR</strong>: Couldn&#8217;t register you... please contact the <a href="mailto:%s">webmaster</a> !' ), get_option( 'admin_email' ) ) );
		return $errors;
	}

	update_user_option( $user_id, 'default_password_nag', true, true ); //Set up the Password change nag.

	wp_new_user_notification( $user_id, $user_pass );

	return $user_id;
}

//
// Main
//

$action = isset($_REQUEST['action']) ? $_REQUEST['action'] : 'login';
$errors = new WP_Error();

if ( isset($_GET['key']) )
	$action = 'resetpass';

// validate action so as to default to the login screen
lechuck's avatar
lechuck committed
363
if ( !in_array( $action, array( 'postpass', 'logout', 'lostpassword', 'retrievepassword', 'resetpass', 'rp', 'register', 'login' ), true ) && false === has_filter( 'login_form_' . $action ) )
godog's avatar
godog committed
364 365 366 367 368 369
	$action = 'login';

nocache_headers();

header('Content-Type: '.get_bloginfo('html_type').'; charset='.get_bloginfo('charset'));

lechuck's avatar
lechuck committed
370
if ( defined( 'RELOCATE' ) && RELOCATE ) { // Move flag is set
godog's avatar
godog committed
371 372 373
	if ( isset( $_SERVER['PATH_INFO'] ) && ($_SERVER['PATH_INFO'] != $_SERVER['PHP_SELF']) )
		$_SERVER['PHP_SELF'] = str_replace( $_SERVER['PATH_INFO'], '', $_SERVER['PHP_SELF'] );

lechuck's avatar
lechuck committed
374 375 376
	$url = dirname( set_url_scheme( 'http://' .  $_SERVER['HTTP_HOST'] . $_SERVER['PHP_SELF'] ) );
	if ( $url != get_option( 'siteurl' ) )
		update_option( 'siteurl', $url );
godog's avatar
godog committed
377 378 379 380 381 382 383 384
}

//Set a cookie now to see if they are supported by the browser.
setcookie(TEST_COOKIE, 'WP Cookie check', 0, COOKIEPATH, COOKIE_DOMAIN);
if ( SITECOOKIEPATH != COOKIEPATH )
	setcookie(TEST_COOKIE, 'WP Cookie check', 0, SITECOOKIEPATH, COOKIE_DOMAIN);

// allow plugins to override the default actions, and to add extra actions if they want
shammash's avatar
shammash committed
385 386
do_action( 'login_init' );
do_action( 'login_form_' . $action );
godog's avatar
godog committed
387 388 389 390

$http_post = ('POST' == $_SERVER['REQUEST_METHOD']);
switch ($action) {

lechuck's avatar
lechuck committed
391 392 393 394 395 396 397 398
case 'postpass' :
	if ( empty( $wp_hasher ) ) {
		require_once( ABSPATH . 'wp-includes/class-phpass.php' );
		// By default, use the portable hash from phpass
		$wp_hasher = new PasswordHash(8, true);
	}

	// 10 days
lechuck's avatar
lechuck committed
399
	setcookie( 'wp-postpass_' . COOKIEHASH, $wp_hasher->HashPassword( stripslashes( $_POST['post_password'] ) ), time() + 10 * DAY_IN_SECONDS, COOKIEPATH );
lechuck's avatar
lechuck committed
400 401 402 403 404 405

	wp_safe_redirect( wp_get_referer() );
	exit();

break;

godog's avatar
godog committed
406 407 408 409 410 411 412 413 414 415 416 417
case 'logout' :
	check_admin_referer('log-out');
	wp_logout();

	$redirect_to = !empty( $_REQUEST['redirect_to'] ) ? $_REQUEST['redirect_to'] : 'wp-login.php?loggedout=true';
	wp_safe_redirect( $redirect_to );
	exit();

break;

case 'lostpassword' :
case 'retrievepassword' :
root's avatar
root committed
418

godog's avatar
godog committed
419 420 421 422 423 424 425 426 427 428 429 430 431
	if ( $http_post ) {
		$errors = retrieve_password();
		if ( !is_wp_error($errors) ) {
			$redirect_to = !empty( $_REQUEST['redirect_to'] ) ? $_REQUEST['redirect_to'] : 'wp-login.php?checkemail=confirm';
			wp_safe_redirect( $redirect_to );
			exit();
		}
	}

	if ( isset($_GET['error']) && 'invalidkey' == $_GET['error'] ) $errors->add('invalidkey', __('Sorry, that key does not appear to be valid.'));
	$redirect_to = apply_filters( 'lostpassword_redirect', !empty( $_REQUEST['redirect_to'] ) ? $_REQUEST['redirect_to'] : '' );

	do_action('lost_password');
root's avatar
root committed
432
	login_header(__('Lost Password'), '<p class="message">' . __('Please enter your username or email address. You will receive a link to create a new password via email.') . '</p>', $errors);
godog's avatar
godog committed
433 434 435 436 437

	$user_login = isset($_POST['user_login']) ? stripslashes($_POST['user_login']) : '';

?>

root's avatar
root committed
438
<form name="lostpasswordform" id="lostpasswordform" action="<?php echo esc_url( site_url( 'wp-login.php?action=lostpassword', 'login_post' ) ); ?>" method="post">
godog's avatar
godog committed
439
	<p>
root's avatar
root committed
440
		<label for="user_login" ><?php _e('Username or E-mail:') ?><br />
lechuck's avatar
lechuck committed
441
		<input type="text" name="user_login" id="user_login" class="input" value="<?php echo esc_attr($user_login); ?>" size="20" /></label>
godog's avatar
godog committed
442 443 444
	</p>
<?php do_action('lostpassword_form'); ?>
	<input type="hidden" name="redirect_to" value="<?php echo esc_attr( $redirect_to ); ?>" />
lechuck's avatar
lechuck committed
445
	<p class="submit"><input type="submit" name="wp-submit" id="wp-submit" class="button button-primary button-large" value="<?php esc_attr_e('Get New Password'); ?>" /></p>
godog's avatar
godog committed
446 447 448
</form>

<p id="nav">
root's avatar
root committed
449 450 451
<a href="<?php echo esc_url( wp_login_url() ); ?>"><?php _e('Log in') ?></a>
<?php if ( get_option( 'users_can_register' ) ) : ?>
 | <a href="<?php echo esc_url( site_url( 'wp-login.php?action=register', 'login' ) ); ?>"><?php _e( 'Register' ); ?></a>
godog's avatar
godog committed
452 453 454 455
<?php endif; ?>
</p>

<?php
root's avatar
root committed
456
login_footer('user_login');
godog's avatar
godog committed
457 458 459 460
break;

case 'resetpass' :
case 'rp' :
root's avatar
root committed
461
	$user = check_password_reset_key($_GET['key'], $_GET['login']);
godog's avatar
godog committed
462

root's avatar
root committed
463 464 465
	if ( is_wp_error($user) ) {
		wp_redirect( site_url('wp-login.php?action=lostpassword&error=invalidkey') );
		exit;
godog's avatar
godog committed
466 467
	}

lechuck's avatar
lechuck committed
468 469 470 471 472 473
	$errors = new WP_Error();

	if ( isset($_POST['pass1']) && $_POST['pass1'] != $_POST['pass2'] )
		$errors->add( 'password_reset_mismatch', __( 'The passwords do not match.' ) );

	do_action( 'validate_password_reset', $errors, $user );
root's avatar
root committed
474

lechuck's avatar
lechuck committed
475
	if ( ( ! $errors->get_error_code() ) && isset( $_POST['pass1'] ) && !empty( $_POST['pass1'] ) ) {
root's avatar
root committed
476
		reset_password($user, $_POST['pass1']);
root's avatar
root committed
477
		login_header( __( 'Password Reset' ), '<p class="message reset-pass">' . __( 'Your password has been reset.' ) . ' <a href="' . esc_url( wp_login_url() ) . '">' . __( 'Log in' ) . '</a></p>' );
root's avatar
root committed
478 479 480
		login_footer();
		exit;
	}
godog's avatar
godog committed
481

root's avatar
root committed
482 483 484 485 486 487
	wp_enqueue_script('utils');
	wp_enqueue_script('user-profile');

	login_header(__('Reset Password'), '<p class="message reset-pass">' . __('Enter your new password below.') . '</p>', $errors );

?>
root's avatar
root committed
488
<form name="resetpassform" id="resetpassform" action="<?php echo esc_url( site_url( 'wp-login.php?action=resetpass&key=' . urlencode( $_GET['key'] ) . '&login=' . urlencode( $_GET['login'] ), 'login_post' ) ); ?>" method="post">
root's avatar
root committed
489 490 491
	<input type="hidden" id="user_login" value="<?php echo esc_attr( $_GET['login'] ); ?>" autocomplete="off" />

	<p>
root's avatar
root committed
492
		<label for="pass1"><?php _e('New password') ?><br />
root's avatar
root committed
493 494 495
		<input type="password" name="pass1" id="pass1" class="input" size="20" value="" autocomplete="off" /></label>
	</p>
	<p>
root's avatar
root committed
496
		<label for="pass2"><?php _e('Confirm new password') ?><br />
root's avatar
root committed
497 498 499 500 501 502 503
		<input type="password" name="pass2" id="pass2" class="input" size="20" value="" autocomplete="off" /></label>
	</p>

	<div id="pass-strength-result" class="hide-if-no-js"><?php _e('Strength indicator'); ?></div>
	<p class="description indicator-hint"><?php _e('Hint: The password should be at least seven characters long. To make it stronger, use upper and lower case letters, numbers and symbols like ! " ? $ % ^ &amp; ).'); ?></p>

	<br class="clear" />
lechuck's avatar
lechuck committed
504
	<p class="submit"><input type="submit" name="wp-submit" id="wp-submit" class="button button-primary button-large" value="<?php esc_attr_e('Reset Password'); ?>" /></p>
root's avatar
root committed
505 506 507
</form>

<p id="nav">
root's avatar
root committed
508 509 510
<a href="<?php echo esc_url( wp_login_url() ); ?>"><?php _e( 'Log in' ); ?></a>
<?php if ( get_option( 'users_can_register' ) ) : ?>
 | <a href="<?php echo esc_url( site_url( 'wp-login.php?action=register', 'login' ) ); ?>"><?php _e( 'Register' ); ?></a>
root's avatar
root committed
511 512 513 514 515
<?php endif; ?>
</p>

<?php
login_footer('user_pass');
godog's avatar
godog committed
516 517 518 519 520
break;

case 'register' :
	if ( is_multisite() ) {
		// Multisite uses wp-signup.php
lechuck's avatar
lechuck committed
521
		wp_redirect( apply_filters( 'wp_signup_location', network_site_url('wp-signup.php') ) );
godog's avatar
godog committed
522 523 524 525
		exit;
	}

	if ( !get_option('users_can_register') ) {
root's avatar
root committed
526
		wp_redirect( site_url('wp-login.php?registration=disabled') );
godog's avatar
godog committed
527 528 529 530 531 532 533 534 535 536 537 538 539 540 541 542 543 544 545 546
		exit();
	}

	$user_login = '';
	$user_email = '';
	if ( $http_post ) {
		$user_login = $_POST['user_login'];
		$user_email = $_POST['user_email'];
		$errors = register_new_user($user_login, $user_email);
		if ( !is_wp_error($errors) ) {
			$redirect_to = !empty( $_POST['redirect_to'] ) ? $_POST['redirect_to'] : 'wp-login.php?checkemail=registered';
			wp_safe_redirect( $redirect_to );
			exit();
		}
	}

	$redirect_to = apply_filters( 'registration_redirect', !empty( $_REQUEST['redirect_to'] ) ? $_REQUEST['redirect_to'] : '' );
	login_header(__('Registration Form'), '<p class="message register">' . __('Register For This Site') . '</p>', $errors);
?>

root's avatar
root committed
547
<form name="registerform" id="registerform" action="<?php echo esc_url( site_url('wp-login.php?action=register', 'login_post') ); ?>" method="post">
godog's avatar
godog committed
548
	<p>
root's avatar
root committed
549
		<label for="user_login"><?php _e('Username') ?><br />
lechuck's avatar
lechuck committed
550
		<input type="text" name="user_login" id="user_login" class="input" value="<?php echo esc_attr(stripslashes($user_login)); ?>" size="20" /></label>
godog's avatar
godog committed
551 552
	</p>
	<p>
root's avatar
root committed
553
		<label for="user_email"><?php _e('E-mail') ?><br />
lechuck's avatar
lechuck committed
554
		<input type="text" name="user_email" id="user_email" class="input" value="<?php echo esc_attr(stripslashes($user_email)); ?>" size="25" /></label>
godog's avatar
godog committed
555 556 557 558 559
	</p>
<?php do_action('register_form'); ?>
	<p id="reg_passmail"><?php _e('A password will be e-mailed to you.') ?></p>
	<br class="clear" />
	<input type="hidden" name="redirect_to" value="<?php echo esc_attr( $redirect_to ); ?>" />
lechuck's avatar
lechuck committed
560
	<p class="submit"><input type="submit" name="wp-submit" id="wp-submit" class="button button-primary button-large" value="<?php esc_attr_e('Register'); ?>" /></p>
godog's avatar
godog committed
561 562 563
</form>

<p id="nav">
root's avatar
root committed
564 565
<a href="<?php echo esc_url( wp_login_url() ); ?>"><?php _e( 'Log in' ); ?></a> |
<a href="<?php echo esc_url( wp_lostpassword_url() ); ?>" title="<?php esc_attr_e( 'Password Lost and Found' ) ?>"><?php _e( 'Lost your password?' ); ?></a>
godog's avatar
godog committed
566 567 568
</p>

<?php
root's avatar
root committed
569
login_footer('user_login');
godog's avatar
godog committed
570 571 572 573 574 575
break;

case 'login' :
default:
	$secure_cookie = '';
	$interim_login = isset($_REQUEST['interim-login']);
lechuck's avatar
lechuck committed
576
	$customize_login = isset( $_REQUEST['customize-login'] );
lechuck's avatar
lechuck committed
577 578
	if ( $customize_login )
		wp_enqueue_script( 'customize-base' );
godog's avatar
godog committed
579 580 581 582

	// If the user wants ssl but the session is not ssl, force a secure cookie.
	if ( !empty($_POST['log']) && !force_ssl_admin() ) {
		$user_name = sanitize_user($_POST['log']);
root's avatar
root committed
583
		if ( $user = get_user_by('login', $user_name) ) {
godog's avatar
godog committed
584 585 586 587 588 589 590 591 592 593 594 595 596 597 598 599 600 601 602
			if ( get_user_option('use_ssl', $user->ID) ) {
				$secure_cookie = true;
				force_ssl_admin(true);
			}
		}
	}

	if ( isset( $_REQUEST['redirect_to'] ) ) {
		$redirect_to = $_REQUEST['redirect_to'];
		// Redirect to https if user wants ssl
		if ( $secure_cookie && false !== strpos($redirect_to, 'wp-admin') )
			$redirect_to = preg_replace('|^http://|', 'https://', $redirect_to);
	} else {
		$redirect_to = admin_url();
	}

	$reauth = empty($_REQUEST['reauth']) ? false : true;

	// If the user was redirected to a secure login form from a non-secure admin page, and secure login is required but secure admin is not, then don't use a secure
lechuck's avatar
lechuck committed
603
	// cookie and redirect back to the referring non-secure admin page. This allows logins to always be POSTed over SSL while allowing the user to choose visiting
godog's avatar
godog committed
604 605 606 607 608 609 610 611 612 613 614
	// the admin via http or https.
	if ( !$secure_cookie && is_ssl() && force_ssl_login() && !force_ssl_admin() && ( 0 !== strpos($redirect_to, 'https') ) && ( 0 === strpos($redirect_to, 'http') ) )
		$secure_cookie = false;

	$user = wp_signon('', $secure_cookie);

	$redirect_to = apply_filters('login_redirect', $redirect_to, isset( $_REQUEST['redirect_to'] ) ? $_REQUEST['redirect_to'] : '', $user);

	if ( !is_wp_error($user) && !$reauth ) {
		if ( $interim_login ) {
			$message = '<p class="message">' . __('You have logged in successfully.') . '</p>';
lechuck's avatar
lechuck committed
615 616 617 618 619 620 621 622 623 624
			login_header( '', $message ); ?>

			<?php if ( ! $customize_login ) : ?>
			<script type="text/javascript">setTimeout( function(){window.close()}, 8000);</script>
			<p class="alignright">
			<input type="button" class="button-primary" value="<?php esc_attr_e('Close'); ?>" onclick="window.close()" /></p>
			<?php endif; ?>
			</div>
			<?php do_action( 'login_footer' ); ?>
			<?php if ( $customize_login ) : ?>
lechuck's avatar
lechuck committed
625
				<script type="text/javascript">setTimeout( function(){ new wp.customize.Messenger({ url: '<?php echo wp_customize_url(); ?>', channel: 'login' }).send('login') }, 1000 );</script>
lechuck's avatar
lechuck committed
626
			<?php endif; ?>
lechuck's avatar
lechuck committed
627
			</body></html>
godog's avatar
godog committed
628 629
<?php		exit;
		}
root's avatar
root committed
630 631 632

		if ( ( empty( $redirect_to ) || $redirect_to == 'wp-admin/' || $redirect_to == admin_url() ) ) {
			// If the user doesn't belong to a blog, send them to user admin. If the user can't edit posts, send them to their profile.
root's avatar
root committed
633
			if ( is_multisite() && !get_active_blog_for_user($user->ID) && !is_super_admin( $user->ID ) )
root's avatar
root committed
634 635
				$redirect_to = user_admin_url();
			elseif ( is_multisite() && !$user->has_cap('read') )
root's avatar
root committed
636
				$redirect_to = get_dashboard_url( $user->ID );
root's avatar
root committed
637 638 639
			elseif ( !$user->has_cap('edit_posts') )
				$redirect_to = admin_url('profile.php');
		}
godog's avatar
godog committed
640 641 642 643 644 645 646 647 648 649 650 651 652 653
		wp_safe_redirect($redirect_to);
		exit();
	}

	$errors = $user;
	// Clear errors if loggedout is set.
	if ( !empty($_GET['loggedout']) || $reauth )
		$errors = new WP_Error();

	// If cookies are disabled we can't log in even with a valid user+pass
	if ( isset($_POST['testcookie']) && empty($_COOKIE[TEST_COOKIE]) )
		$errors->add('test_cookie', __("<strong>ERROR</strong>: Cookies are blocked or not supported by your browser. You must <a href='http://www.google.com/cookies.html'>enable cookies</a> to use WordPress."));

	// Some parts of this script use the main login form to display a message
lechuck's avatar
lechuck committed
654
	if		( isset($_GET['loggedout']) && true == $_GET['loggedout'] )
godog's avatar
godog committed
655 656 657 658 659 660 661 662 663 664 665
		$errors->add('loggedout', __('You are now logged out.'), 'message');
	elseif	( isset($_GET['registration']) && 'disabled' == $_GET['registration'] )
		$errors->add('registerdisabled', __('User registration is currently not allowed.'));
	elseif	( isset($_GET['checkemail']) && 'confirm' == $_GET['checkemail'] )
		$errors->add('confirm', __('Check your e-mail for the confirmation link.'), 'message');
	elseif	( isset($_GET['checkemail']) && 'newpass' == $_GET['checkemail'] )
		$errors->add('newpass', __('Check your e-mail for your new password.'), 'message');
	elseif	( isset($_GET['checkemail']) && 'registered' == $_GET['checkemail'] )
		$errors->add('registered', __('Registration complete. Please check your e-mail.'), 'message');
	elseif	( $interim_login )
		$errors->add('expired', __('Your session has expired. Please log-in again.'), 'message');
lechuck's avatar
lechuck committed
666 667
	elseif ( strpos( $redirect_to, 'about.php?updated' ) )
		$errors->add('updated', __( '<strong>You have successfully updated WordPress!</strong> Please log back in to experience the awesomeness.' ), 'message' );
godog's avatar
godog committed
668 669 670 671 672 673 674 675 676 677 678 679

	// Clear any stale cookies.
	if ( $reauth )
		wp_clear_auth_cookie();

	login_header(__('Log In'), '', $errors);

	if ( isset($_POST['log']) )
		$user_login = ( 'incorrect_password' == $errors->get_error_code() || 'empty_password' == $errors->get_error_code() ) ? esc_attr(stripslashes($_POST['log'])) : '';
	$rememberme = ! empty( $_POST['rememberme'] );
?>

root's avatar
root committed
680
<form name="loginform" id="loginform" action="<?php echo esc_url( site_url( 'wp-login.php', 'login_post' ) ); ?>" method="post">
godog's avatar
godog committed
681
	<p>
root's avatar
root committed
682
		<label for="user_login"><?php _e('Username') ?><br />
lechuck's avatar
lechuck committed
683
		<input type="text" name="log" id="user_login" class="input" value="<?php echo esc_attr($user_login); ?>" size="20" /></label>
godog's avatar
godog committed
684 685
	</p>
	<p>
root's avatar
root committed
686
		<label for="user_pass"><?php _e('Password') ?><br />
lechuck's avatar
lechuck committed
687
		<input type="password" name="pwd" id="user_pass" class="input" value="" size="20" /></label>
godog's avatar
godog committed
688 689
	</p>
<?php do_action('login_form'); ?>
lechuck's avatar
lechuck committed
690
	<p class="forgetmenot"><label for="rememberme"><input name="rememberme" type="checkbox" id="rememberme" value="forever" <?php checked( $rememberme ); ?> /> <?php esc_attr_e('Remember Me'); ?></label></p>
godog's avatar
godog committed
691
	<p class="submit">
lechuck's avatar
lechuck committed
692
		<input type="submit" name="wp-submit" id="wp-submit" class="button button-primary button-large" value="<?php esc_attr_e('Log In'); ?>" />
godog's avatar
godog committed
693 694 695 696 697
<?php	if ( $interim_login ) { ?>
		<input type="hidden" name="interim-login" value="1" />
<?php	} else { ?>
		<input type="hidden" name="redirect_to" value="<?php echo esc_attr($redirect_to); ?>" />
<?php 	} ?>
lechuck's avatar
lechuck committed
698 699 700
<?php   if ( $customize_login ) : ?>
		<input type="hidden" name="customize-login" value="1" />
<?php   endif; ?>
godog's avatar
godog committed
701 702 703 704 705 706 707 708
		<input type="hidden" name="testcookie" value="1" />
	</p>
</form>

<?php if ( !$interim_login ) { ?>
<p id="nav">
<?php if ( isset($_GET['checkemail']) && in_array( $_GET['checkemail'], array('confirm', 'newpass') ) ) : ?>
<?php elseif ( get_option('users_can_register') ) : ?>
root's avatar
root committed
709 710
<a href="<?php echo esc_url( site_url( 'wp-login.php?action=register', 'login' ) ); ?>"><?php _e( 'Register' ); ?></a> |
<a href="<?php echo esc_url( wp_lostpassword_url() ); ?>" title="<?php esc_attr_e( 'Password Lost and Found' ); ?>"><?php _e( 'Lost your password?' ); ?></a>
godog's avatar
godog committed
711
<?php else : ?>
root's avatar
root committed
712
<a href="<?php echo esc_url( wp_lostpassword_url() ); ?>" title="<?php esc_attr_e( 'Password Lost and Found' ); ?>"><?php _e( 'Lost your password?' ); ?></a>
godog's avatar
godog committed
713 714 715 716 717 718 719 720 721
<?php endif; ?>
</p>
<?php } ?>

<script type="text/javascript">
function wp_attempt_focus(){
setTimeout( function(){ try{
<?php if ( $user_login || $interim_login ) { ?>
d = document.getElementById('user_pass');
root's avatar
root committed
722
d.value = '';
godog's avatar
godog committed
723 724
<?php } else { ?>
d = document.getElementById('user_login');
root's avatar
root committed
725 726
<?php if ( 'invalid_username' == $errors->get_error_code() ) { ?>
if( d.value != '' )
godog's avatar
godog committed
727
d.value = '';
root's avatar
root committed
728 729 730
<?php
}
}?>
godog's avatar
godog committed
731
d.focus();
root's avatar
root committed
732
d.select();
godog's avatar
godog committed
733 734 735 736 737 738 739 740 741 742
} catch(e){}
}, 200);
}

<?php if ( !$error ) { ?>
wp_attempt_focus();
<?php } ?>
if(typeof wpOnload=='function')wpOnload();
</script>

shammash's avatar
shammash committed
743 744
<?php
login_footer();
godog's avatar
godog committed
745 746
break;
} // end action switch