Skip to content

Commit dfbde56

Browse files
committed
Update only the expiration field of the token
Because WP_Session_Tokens::update() overwrites the entire session object in its datastore, the previous code was wiping out fields like IP address and original login date as well as any custom data attached to the token. This reads the original token data array so that only the exp field is updated.
1 parent dcc7258 commit dfbde56

1 file changed

Lines changed: 11 additions & 5 deletions

File tree

‎src/Actions/Authentication.php‎

Lines changed: 11 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -601,11 +601,17 @@ public function onShutdown(): void
601601
/** This filter is documented in wp-includes/pluggable.php */
602602
$expiration = apply_filters('auth_cookie_expiration', 14 * DAY_IN_SECONDS, $userId, true);
603603

604-
// Update the server-side session record (wp_set_auth_cookie does not do this
605-
// when a token is supplied).
606-
\WP_Session_Tokens::get_instance($userId)->update($token, [
607-
'expiration' => time() + $expiration,
608-
]);
604+
// Update the expiration date in the server-side session record
605+
// (wp_set_auth_cookie does not do this when a token is supplied).
606+
$manager = \WP_Session_Tokens::get_instance( $userId );
607+
$session = $manager->get( $token );
608+
609+
if ( ! is_array( $session ) ) {
610+
return;
611+
}
612+
613+
$session['expiration'] = time() + $expiration;
614+
$manager->update( $token, $session );
609615

610616
// Reissue the browser cookies with the same token and new expiration.
611617
wp_set_auth_cookie($userId, true, '', $token);

0 commit comments

Comments
 (0)