# give/4.18.0/src/DonationForms/Routes/AuthenticationRoute.php

GiveWP – Donation Plugin and Fundraising Platform, version 4.18.0. 76 lines.

- Page: https://pluginprobe.com/plugins/give/4.18.0/code/src/DonationForms/Routes/AuthenticationRoute.php
- Raw: https://pluginprobe.com/plugins/give/4.18.0/raw/src/DonationForms/Routes/AuthenticationRoute.php
- Modified: 2026-09-23T17:56:52+00:00

Line numbers below start at 1. Link to a line or a range by appending a fragment to the
page URL, for example `https://pluginprobe.com/plugins/give/4.18.0/code/src/DonationForms/Routes/AuthenticationRoute.php#L10-L20`.

```php
<?php

namespace Give\DonationForms\Routes;

use Give\DonationForms\Actions\AuthenticateFormRequestWithToken;
use Give\DonationForms\DataTransferObjects\AuthenticationData;
use Give\DonationForms\DataTransferObjects\DonateRouteData;
use Give\DonationForms\DataTransferObjects\UserData;
use Give\Framework\PaymentGateways\Traits\HandleHttpResponses;
use WP_User;

/**
 * @since 3.0.0
 */
class AuthenticationRoute
{
    use HandleHttpResponses;

    /**
     * @since 4.17.0 Return an auth token so embedded forms can authenticate without cookies.
     * @since 3.0.0
     *
     * @return void
     */
    public function __invoke(array $request)
    {
        $routeData = DonateRouteData::fromRequest(give_clean($_GET));

        $routeData->validateSignature();

        $user = $this->authenticate(AuthenticationData::fromRequest($request));

        wp_send_json_success(
            get_object_vars(UserData::fromUser($user)) + [
                AuthenticateFormRequestWithToken::TOKEN_KEY => $this->generateAuthToken($user),
            ]
        );

        exit;
    }

    /**
     * The token is built like an auth cookie: signed by core, session backed,
     * and revoked with the session. It carries the login where the cookie
     * cannot, which is inside a cross-site iframe. Its own salt scheme means
     * it is not usable as a login cookie.
     *
     * @since 4.17.0
     */
    protected function generateAuthToken(WP_User $user): string
    {
        return wp_generate_auth_cookie($user->ID, time() + HOUR_IN_SECONDS, AuthenticateFormRequestWithToken::SCHEME);
    }

    /**
     * @since 3.0.0
     */
    protected function authenticate(AuthenticationData $auth): WP_User
    {
        $userOrError = wp_signon([
            'user_login' => $auth->login,
            'user_password' => $auth->password,
        ]);

        if (is_wp_error($userOrError)) {
            wp_send_json_error([
                'type' => 'authentication_error',
                'message' => __('The login/password does not match or is incorrect.', 'give'),
            ], 401);
            exit;
        }

        return $userOrError;
    }
}

```
