Use wp_login_url() for login URLs and defer the redirect decision to core logic - #1000
Merged
Merged
Conversation
|
The following accounts have interacted with this PR and/or linked issues. I will continue to update these lists as activity occurs. You can also manually ask me to refresh this list by adding the If you're merging code through a pull request on GitHub, copy and paste the following into the bottom of the merge commit message. To understand the WordPress project's expectations around crediting contributors, please review the Contributor Attribution page in the Core Handbook. |
kasparsd
commented
Sep 26, 2026
| } | ||
|
|
||
| $redirect_to = isset( $_REQUEST['redirect_to'] ) ? esc_url_raw( wp_unslash( $_REQUEST['redirect_to'] ) ) : admin_url(); // phpcs:ignore WordPress.Security.NonceVerification.Recommended -- Value only used for redirect; auth protected by 2FA login nonce later. | ||
| $redirect_to = isset( $_REQUEST['redirect_to'] ) ? esc_url_raw( wp_unslash( $_REQUEST['redirect_to'] ) ) : ''; // phpcs:ignore WordPress.Security.NonceVerification.Recommended -- Value only used for redirect; auth protected by 2FA login nonce later. |
Collaborator
Author
There was a problem hiding this comment.
delay the redirect decision to the very late, if nothing custom is provided here.
kasparsd
commented
Sep 27, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What?
This PR completes the switch of
Two_Factor_Core::login_url()to WordPress's nativewp_login_url()and reworks how the post-2FAredirect_tovalue flows through the login, validation, and revalidation steps.Closes #886 as superseded.
Why?
Fixes #885.
PR #886 ("replace wp-login.php to wp_login_url") fixes an important multilingual bug: since 0.15.0, multilingual plugins (WPML, Polylang, TranslatePress) that hook the
login_urlfilter were never applied, sending 2FA form actions and redirects to the wrong domain on multi-language setups. This PR supersedes it because it takes the same core idea further and addresses the review concerns raised there:apply_filters( 'login_redirect', admin_url(), '', null )fallback inshow_two_factor_login()passed an empty$requested_redirect_toand anulluser to a filter that expects aWP_User, applied the filter too early (before validation), and conflicted with the secondlogin_redirectapplication in the validation step. Instead, theredirect_todefault is now simply empty at the render step (show_two_factor_login(),login_form_revalidate_2fa()), and core's decision-making happens once, at the very last step beforewp_safe_redirect().login_redirectfilter is applied exactly once per flow, with the actual requestedredirect_toand a realWP_User.How?
login_url()now builds onwp_login_url( '', false )+set_url_scheme(), so thelogin_urlfilter (and the multilingual plugins hooking it) affects all generated URLs. Parameters — includingredirect_to— are added viaadd_query_arg()only when passed.show_two_factor_login()andlogin_form_revalidate_2fa()no longer defaultredirect_totoadmin_url(); the value stays empty unless it was actually requested or provided by thelogin_redirectfilter, letting core decide.get_login_redirect_fallback()centralizes the final decision: it applies thelogin_redirectfilter once, and when the destination is still empty it mirrors the capability-based fallback from thecase 'login'block inwp-login.php(multisite dashboard destinations,profile.phpfor users withoutedit_posts, front end for users withoutread), so 2FA logins land in the same place a regular login would.login_url()(includingredirect_tobeing added when present and absent otherwise), the redirect decision table (role capabilities, filter overrides, empty fallback), and end-to-end redirect tests for both the validation and revalidation flows.Use of AI Tools
AI assistance: Yes
Tool(s): Pi (coding agent)
Model(s): GLM
Used for: test scaffolding and data providers; implementation and tests reviewed and edited by me.
Testing Instructions
npm run env startfollowed bynpm test— all tests should pass.redirect_toparameter as (a) an editor and (b) a subscriber, and verify you are redirected to the admin dashboard and your profile page respectively, mirroring a non-2FA login.login_redirectto return a custom URL and verify it is respected after 2FA.Changelog Entry