# give/4.18.0/src/DonationForms/Actions/AuthenticateFormRequestWithToken.php

GiveWP – Donation Plugin and Fundraising Platform, version 4.18.0. 75 lines.

- Page: https://pluginprobe.com/plugins/give/4.18.0/code/src/DonationForms/Actions/AuthenticateFormRequestWithToken.php
- Raw: https://pluginprobe.com/plugins/give/4.18.0/raw/src/DonationForms/Actions/AuthenticateFormRequestWithToken.php
- Modified: 2026-09-23T17:56:52+00:00

Line numbers below start at 1. Link to a line or a range by appending a fragment to the
page URL, for example `https://pluginprobe.com/plugins/give/4.18.0/code/src/DonationForms/Actions/AuthenticateFormRequestWithToken.php#L10-L20`.

```php
<?php

namespace Give\DonationForms\Actions;

/**
 * Signs the donor in for a donate or validate request from a signed auth
 * token instead of the login cookie.
 *
 * A donation form embedded on another website cannot rely on cookies: the
 * browser drops WordPress auth cookies set from a cross-site iframe response.
 * The authentication route therefore also returns a token built with the same
 * core functions as the auth cookie, which WordPress signs, expires, and backs
 * with a session token, under a plugin-specific scheme. The form sends it back
 * with the donation and the route validates it the same way core validates
 * the cookie.
 *
 * This runs from the two form routes rather than on determine_current_user so
 * it works even when another plugin resolves the current user before this
 * plugin has loaded, and so the token is never accepted anywhere else.
 *
 * @since 4.17.0
 */
class AuthenticateFormRequestWithToken
{
    /**
     * The request key the form sends the token under. The authentication
     * route returns it under the same key.
     *
     * @since 4.17.0
     */
    public const TOKEN_KEY = 'authToken';

    /**
     * A plugin-specific salt scheme. WordPress derives the salt from the scheme
     * name, so the token verifies only here and is never a valid login cookie
     * if it leaks.
     *
     * @since 4.17.0
     */
    public const SCHEME = 'givewp_embedded_form';

    /**
     * @since 4.17.0
     */
    public function __invoke(array $request): void
    {
        if (is_user_logged_in()) {
            return;
        }

        $token = $request[self::TOKEN_KEY] ?? '';

        if (!is_string($token) || $token === '') {
            return;
        }

        /*
         * Core extends the expiry by an hour for POST requests, which is meant
         * for a form that sat open in a browser. This token is a short-lived
         * credential, so its own expiry is the limit.
         */
        $parts = wp_parse_auth_cookie($token);

        if (!$parts || (int)$parts['expiration'] < time()) {
            return;
        }

        $userId = wp_validate_auth_cookie($token, self::SCHEME);

        if ($userId) {
            wp_set_current_user($userId);
        }
    }
}

```
