[ Index ]

PHP Cross Reference of WordPress Trunk (Updated Daily)

Search

title

Body

[close]

/ -> wp-activate.php (source)

   1  <?php
   2  /**
   3   * Confirms that the activation key that is sent in an email after a user signs
   4   * up for a new site matches the key for that user and then displays confirmation.
   5   *
   6   * @package WordPress
   7   */
   8  
   9  define( 'WP_INSTALLING', true );
  10  
  11  /** Sets up the WordPress Environment. */
  12  require  __DIR__ . '/wp-load.php';
  13  
  14  require  __DIR__ . '/wp-blog-header.php';
  15  
  16  if ( ! is_multisite() ) {
  17      wp_redirect( wp_registration_url() );
  18      die();
  19  }
  20  
  21  $valid_error_codes = array( 'already_active', 'blog_taken' );
  22  
  23  list( $activate_path ) = explode( '?', wp_unslash( $_SERVER['REQUEST_URI'] ) );
  24  $activate_cookie       = 'wp-activate-' . COOKIEHASH;
  25  
  26  $key    = '';
  27  $result = null;
  28  
  29  if ( isset( $_GET['key'] ) && isset( $_POST['key'] ) && $_GET['key'] !== $_POST['key'] ) {
  30      wp_die( __( 'A key value mismatch has been detected. Please follow the link provided in your activation email.' ), __( 'An error occurred during the activation' ), 400 );
  31  } elseif ( ! empty( $_GET['key'] ) ) {
  32      $key = sanitize_text_field( $_GET['key'] );
  33  } elseif ( ! empty( $_POST['key'] ) ) {
  34      $key = sanitize_text_field( $_POST['key'] );
  35  }
  36  
  37  if ( $key ) {
  38      $redirect_url = remove_query_arg( 'key' );
  39  
  40      if ( remove_query_arg( false ) !== $redirect_url ) {
  41          setcookie( $activate_cookie, $key, 0, $activate_path, COOKIE_DOMAIN, is_ssl(), true );
  42          wp_safe_redirect( $redirect_url );
  43          exit;
  44      } else {
  45          $result = wpmu_activate_signup( $key );
  46      }
  47  }
  48  
  49  if ( null === $result && isset( $_COOKIE[ $activate_cookie ] ) ) {
  50      $key    = $_COOKIE[ $activate_cookie ];
  51      $result = wpmu_activate_signup( $key );
  52      setcookie( $activate_cookie, ' ', time() - YEAR_IN_SECONDS, $activate_path, COOKIE_DOMAIN, is_ssl(), true );
  53  }
  54  
  55  if ( null === $result || ( is_wp_error( $result ) && 'invalid_key' === $result->get_error_code() ) ) {
  56      status_header( 404 );
  57  } elseif ( is_wp_error( $result ) ) {
  58      $error_code = $result->get_error_code();
  59  
  60      if ( ! in_array( $error_code, $valid_error_codes, true ) ) {
  61          status_header( 400 );
  62      }
  63  }
  64  
  65  nocache_headers();
  66  
  67  /**
  68   * @global WP_Query $wp_query WordPress Query object.
  69   */
  70  global $wp_query;
  71  
  72  // Fix for page title.
  73  $wp_query->is_404 = false;
  74  
  75  /**
  76   * Fires before the Site Activation page is loaded.
  77   *
  78   * @since 3.0.0
  79   */
  80  do_action( 'activate_header' );
  81  
  82  /**
  83   * Adds an action hook specific to this page.
  84   *
  85   * Fires on {@see 'wp_head'}.
  86   *
  87   * @since MU (3.0.0)
  88   */
  89  function do_activate_header() {
  90      /**
  91       * Fires within the `<head>` section of the Site Activation page.
  92       *
  93       * Fires on the {@see 'wp_head'} action.
  94       *
  95       * @since 3.0.0
  96       */
  97      do_action( 'activate_wp_head' );
  98  }
  99  add_action( 'wp_head', 'do_activate_header' );
 100  
 101  /**
 102   * Loads styles specific to this page.
 103   *
 104   * @since MU (3.0.0)
 105   */
 106  function wpmu_activate_stylesheet() {
 107      ?>
 108      <style>
 109          .wp-activate-container { width: 90%; margin: 0 auto; text-align: start; padding: 24px; box-sizing: border-box; }
 110          .wp-activate-container form { margin: 24px 0; }
 111          .wp-activate-container p { font-size: 18px; }
 112          #key, #submit { font-size: 24px; box-sizing: border-box; margin: 5px 0; }
 113          #key { width: 100%; direction: ltr; }
 114          #submit { width: auto; }
 115          span.h3 { font-weight: 600; }
 116      </style>
 117      <?php
 118  }
 119  add_action( 'wp_head', 'wpmu_activate_stylesheet' );
 120  add_action( 'wp_head', 'wp_strict_cross_origin_referrer' );
 121  add_filter( 'wp_robots', 'wp_robots_sensitive_page' );
 122  
 123  get_header( 'wp-activate' );
 124  
 125  /** @var WP_Site $blog_details */
 126  $blog_details = get_site();
 127  ?>
 128  
 129  <div id="signup-content" class="widecolumn">
 130      <div class="wp-activate-container">
 131      <?php if ( ! $key ) { ?>
 132  
 133          <h2><?php _e( 'Activation Key Required' ); ?></h2>
 134          <form name="activateform" id="activateform" method="post" action="<?php echo esc_url( network_site_url( $blog_details->path . 'wp-activate.php' ) ); ?>">
 135              <p>
 136                  <label for="key"><?php _e( 'Activation Key:' ); ?></label>
 137                  <br /><input type="text" name="key" id="key" value="" size="50" autofocus="autofocus" />
 138              </p>
 139              <p class="submit">
 140                  <input id="submit" type="submit" name="Submit" class="submit" value="<?php esc_attr_e( 'Activate' ); ?>" />
 141              </p>
 142          </form>
 143  
 144          <?php
 145      } else {
 146          if ( is_wp_error( $result ) && in_array( $result->get_error_code(), $valid_error_codes, true ) ) {
 147              /** @var object{ signup_id: string, domain: string, path: string, title: string, user_login: string, user_email: string, registered: string, activated: string, active: string, activation_key: string, meta: string|null } $signup */
 148              $signup = $result->get_error_data();
 149              ?>
 150              <h2><?php _e( 'Your account is now active!' ); ?></h2>
 151              <?php
 152              echo '<p class="lead-in">';
 153              if ( '' === $signup->domain . $signup->path ) {
 154                  printf(
 155                      /* translators: 1: Login URL, 2: Username, 3: User email address, 4: Lost password URL. */
 156                      __( 'Your account has been activated. You may now <a href="%1$s">log in</a> to the site using your chosen username of &#8220;%2$s&#8221;. Please check your email inbox at %3$s for your password and login instructions. If you do not receive an email, please check your junk or spam folder. If you still do not receive an email within an hour, you can <a href="%4$s">reset your password</a>.' ),
 157                      esc_url( network_site_url( $blog_details->path . 'wp-login.php', 'login' ) ),
 158                      esc_html( $signup->user_login ),
 159                      esc_html( $signup->user_email ),
 160                      esc_url( wp_lostpassword_url() )
 161                  );
 162              } else {
 163                  $url = ( is_ssl() ? 'https://' : 'http://' ) . $signup->domain . $blog_details->path;
 164  
 165                  printf(
 166                      /* translators: 1: Site URL, 2: Username, 3: User email address, 4: Lost password URL. */
 167                      __( 'Your site at %1$s is active. You may now log in to your site using your chosen username of &#8220;%2$s&#8221;. Please check your email inbox at %3$s for your password and login instructions. If you do not receive an email, please check your junk or spam folder. If you still do not receive an email within an hour, you can <a href="%4$s">reset your password</a>.' ),
 168                      sprintf( '<a href="%1$s">%1$s</a>', esc_url( $url ) ),
 169                      esc_html( $signup->user_login ),
 170                      esc_html( $signup->user_email ),
 171                      esc_url( wp_lostpassword_url() )
 172                  );
 173              }
 174              echo '</p>';
 175          } elseif ( null === $result || is_wp_error( $result ) ) {
 176              ?>
 177              <h2><?php _e( 'An error occurred during the activation' ); ?></h2>
 178              <?php if ( is_wp_error( $result ) ) : ?>
 179                  <p><?php echo esc_html( $result->get_error_message() ); ?></p>
 180              <?php endif; ?>
 181              <?php
 182          } else {
 183              $url = isset( $result['blog_id'] ) ? esc_url( get_home_url( (int) $result['blog_id'] ) ) : '';
 184              /** @var WP_User $user */
 185              $user = get_userdata( (int) $result['user_id'] );
 186              ?>
 187              <h2><?php _e( 'Your account is now active!' ); ?></h2>
 188  
 189              <div id="signup-welcome">
 190              <p><span class="h3"><?php _e( 'Username:' ); ?></span> <?php echo esc_html( $user->user_login ); ?></p>
 191              <p><span class="h3"><?php _e( 'Password:' ); ?></span> <?php echo esc_html( $result['password'] ); ?></p>
 192              </div>
 193  
 194              <?php
 195              if ( $url && network_home_url( '', 'http' ) !== $url ) :
 196                  switch_to_blog( (int) $result['blog_id'] );
 197                  $login_url = wp_login_url();
 198                  restore_current_blog();
 199                  ?>
 200                  <p class="view">
 201                  <?php
 202                      /* translators: 1: Site URL, 2: Login URL. */
 203                      printf( __( 'Your account is now activated. <a href="%1$s">View your site</a> or <a href="%2$s">Log in</a>' ), esc_url( $url ), esc_url( $login_url ) );
 204                  ?>
 205                  </p>
 206              <?php else : ?>
 207                  <p class="view">
 208                  <?php
 209                      printf(
 210                          /* translators: 1: Login URL, 2: Network home URL. */
 211                          __( 'Your account is now activated. <a href="%1$s">Log in</a> or go back to the <a href="%2$s">homepage</a>.' ),
 212                          esc_url( network_site_url( $blog_details->path . 'wp-login.php', 'login' ) ),
 213                          esc_url( network_home_url( $blog_details->path ) )
 214                      );
 215                  ?>
 216                  </p>
 217                  <?php
 218                  endif;
 219          }
 220      }
 221      ?>
 222      </div>
 223  </div>
 224  <?php
 225  get_footer( 'wp-activate' );


Generated : Sat Oct 3 08:20:34 2026 Cross-referenced by PHPXref