Skip to content

Users: Preserve early-authenticated user ID in determine_current_user filter chain - #12789

Draft
himanshupathak95 wants to merge 5 commits into
WordPress:trunkfrom
himanshupathak95:fix/28212
Draft

Users: Preserve early-authenticated user ID in determine_current_user filter chain#12789
himanshupathak95 wants to merge 5 commits into
WordPress:trunkfrom
himanshupathak95:fix/28212

Conversation

@himanshupathak95

@himanshupathak95 himanshupathak95 commented Jul 31, 2026

Copy link
Copy Markdown

Trac ticket: https://core.trac.wordpress.org/ticket/28212

When a callback registered on the determine_current_user filter at a priority lower than 10 authenticates a user and returns a user ID, wp_validate_auth_cookie (hooked directly at priority 10) receives that user ID as its $cookie argument.

Because wp_validate_auth_cookie expected a cookie string, it failed parsing and returned false, overriding the user ID determined by the earlier filter callback.

Since we cannot wrap wp_validate_auth_cookie in a new filter callback function (like wp_validate_logged_in_cookie) because changing the hook name in default-filters.php would break backward compatibility for countless stateless API plugins that rely on remove_filter( 'determine_current_user', 'wp_validate_auth_cookie' ).

Instead, this PR adds a safeguard inside wp_validate_auth_cookie() in pluggable.php. If a user ID (non-string or numeric value) is passed, it returns it immediately. If no user ID is passed, it falls through to wp_parse_auth_cookie(), preserving the existing is_ssl() auto-detection logic perfectly.

@github-actions

Copy link
Copy Markdown

Test using WordPress Playground

The changes in this pull request can previewed and tested using a WordPress Playground instance.

WordPress Playground is an experimental project that creates a full WordPress instance entirely within the browser.

Some things to be aware of

  • All changes will be lost when closing a tab with a Playground instance.
  • All changes will be lost when refreshing the page.
  • A fresh instance is created each time the link below is clicked.
  • Every time this pull request is updated, a new ZIP file containing all changes is created. If changes are not reflected in the Playground instance,
    it's possible that the most recent build failed, or has not completed. Check the list of workflow runs to be sure.

For more details about these limitations and more, check out the Limitations page in the WordPress Playground documentation.

Test this pull request with WordPress Playground.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant