validateSignature(); $user = $this->authenticate(AuthenticationData::fromRequest($request)); wp_send_json_success( get_object_vars(UserData::fromUser($user)) + [ AuthenticateFormRequestWithToken::TOKEN_KEY => $this->generateAuthToken($user), ] ); exit; } /** * The token is built like an auth cookie: signed by core, session backed, * and revoked with the session. It carries the login where the cookie * cannot, which is inside a cross-site iframe. Its own salt scheme means * it is not usable as a login cookie. * * @since 4.17.0 */ protected function generateAuthToken(WP_User $user): string { return wp_generate_auth_cookie($user->ID, time() + HOUR_IN_SECONDS, AuthenticateFormRequestWithToken::SCHEME); } /** * @since 3.0.0 */ protected function authenticate(AuthenticationData $auth): WP_User { $userOrError = wp_signon([ 'user_login' => $auth->login, 'user_password' => $auth->password, ]); if (is_wp_error($userOrError)) { wp_send_json_error([ 'type' => 'authentication_error', 'message' => __('The login/password does not match or is incorrect.', 'give'), ], 401); exit; } return $userOrError; } }