wppaste
WordPress

wp_authenticate( string $username, string $password ): WP_User|WP_Error

Since
2.5.0, 4.5.0
Source
wp-includes/pluggable.php:680
Authenticates a user, confirming the login credentials are valid.

Parameters

$usernamestring
User's username or email address.
$passwordstring
User's password.

Return

WP_User|WP_Error
WP_User object if the credentials are valid, otherwise WP_Error.

Hooks fired · 2

2 hooks fire while wp_authenticate() runs, in this order:

  1. apply_filters( authenticate )filterline 702 (+22 into the body)

    Filters whether a set of user login credentials are valid.

  2. do_action( wp_login_failed )actionline 727 (+47 into the body)

    Fires after a user login has failed.

Uses · 6

Used by · 4

Source

	function wp_authenticate(		$username,		#[\SensitiveParameter]		$password	) {		$username = sanitize_user( $username );		$password = trim( $password ); 		/**		 * Filters whether a set of user login credentials are valid.		 *		 * A WP_User object is returned if the credentials authenticate a user.		 * WP_Error or null otherwise.		 *		 * @since 2.8.0		 * @since 4.5.0 `$username` now accepts an email address.		 *		 * @param null|WP_User|WP_Error $user     WP_User if the user is authenticated.		 *                                        WP_Error or null otherwise.		 * @param string                $username Username or email address.		 * @param string                $password User password.		 */		$user = apply_filters( 'authenticate', null, $username, $password ); 		if ( null === $user || false === $user ) {			/*			 * TODO: What should the error message be? (Or would these even happen?)			 * Only needed if all authentication handlers fail to return anything.			 */			$user = new WP_Error( 'authentication_failed', __( '<strong>Error:</strong> Invalid username, email address or incorrect password.' ) );		} 		$ignore_codes = array( 'empty_username', 'empty_password' ); 		if ( is_wp_error( $user ) && ! in_array( $user->get_error_code(), $ignore_codes, true ) ) {			$error = $user; 			/**			 * Fires after a user login has failed.			 *			 * @since 2.5.0			 * @since 4.5.0 The value of `$username` can now be an email address.			 * @since 5.4.0 The `$error` parameter was added.			 *			 * @param string   $username Username or email address.			 * @param WP_Error $error    A WP_Error object with the authentication failure details.			 */			do_action( 'wp_login_failed', $username, $error );		} 		return $user;	}

History

Introduced in 2.5.0. Unchanged from 6.7.7 through 7.1.0.

  1. 6.7.7
  2. 6.8.8
  3. 6.9.7
  4. 7.0.4
  5. 7.1.0

Signature, return type and hooks compared across 5 parsed releases.

4.5.0
$username now accepts an email address.from the docblock
2.5.0
Introduced.from the docblock

About this page

Parsed data
Generated from the wordpress-develop 6.9.7 tag, from src/wp-includes/pluggable.php, and regenerated for each WordPress release so it tracks the code rather than a snapshot of it.
Corrections
Something wrong on this page? Report it and it gets fixed in the next regeneration.