rest_cookie_check_errors( WP_Error|mixed $result ): WP_Error|mixed|bool
- Since
- 4.4.0
- Source
wp-includes/rest-api.php:1130
Checks for errors when using cookie-based authentication.
Description
WordPress' built-in cookie authentication is always active for logged in users. However, the API has to check nonces for each request to ensure users are not vulnerable to CSRF.
Parameters
$resultWP_Error|mixed- Error from another authentication handler, null if we should handle it, or another value if not.
Return
WP_Error|mixed|bool- WP_Error if the cookie is invalid, the $result, otherwise true.
Uses · 9
- is_user_logged_in()Determines whether the current visitor is a logged in user.
- wp_set_current_user()Changes the current user by ID or name.
- wp_verify_nonce()Verifies that a correct security nonce was used with time limit.
- add_filter()Adds a callback function to a filter hook.
- __()Retrieves the translation of $text.
- rest_get_server()Retrieves the current REST server instance.
- wp_create_nonce()Creates a cryptographic token tied to a specific action, user, user session, and window of time.
- WP_Error::__construct()Initializes the error.
- rest_get_server()::send_header()
Source
function rest_cookie_check_errors( $result ) { if ( ! empty( $result ) ) { return $result; } global $wp_rest_auth_cookie; /* * Is cookie authentication being used? (If we get an auth * error, but we're still logged in, another authentication * must have been used). */ if ( true !== $wp_rest_auth_cookie && is_user_logged_in() ) { return $result; } // Determine if there is a nonce. $nonce = null; if ( isset( $_REQUEST['_wpnonce'] ) ) { $nonce = $_REQUEST['_wpnonce']; } elseif ( isset( $_SERVER['HTTP_X_WP_NONCE'] ) ) { $nonce = $_SERVER['HTTP_X_WP_NONCE']; } if ( null === $nonce ) { // No nonce at all, so act as if it's an unauthenticated request. wp_set_current_user( 0 ); return true; } // Check the nonce. $result = wp_verify_nonce( $nonce, 'wp_rest' ); if ( ! $result ) { add_filter( 'rest_send_nocache_headers', '__return_true', 20 ); return new WP_Error( 'rest_cookie_invalid_nonce', __( 'Cookie check failed' ), array( 'status' => 403 ) ); } // Send a refreshed nonce in header. rest_get_server()->send_header( 'X-WP-Nonce', wp_create_nonce( 'wp_rest' ) ); return true;}History
Introduced in 4.4.0. Unchanged from 6.7.7 through 7.1.0.
Signature, return type and hooks compared across 5 parsed releases.
About this page
- Parsed data
- Generated from the wordpress-develop 7.1.0 tag, from
src/wp-includes/rest-api.php, and regenerated for each WordPress release so it tracks the code rather than a snapshot of it. - Corrections
- Something wrong on this page? Report it and it gets fixed in the next regeneration.