| 开发者 |
t2ftech
thaissamendes |
|---|---|
| 更新时间 | 2026年9月15日 06:38 |
| PHP版本: | 7.4 及以上 |
| WordPress版本: | 7.1 |
| 版权: | GPLv2 or later |
| 版权网址: | 版权信息 |
[two_step_login]
How it works
?redirect_to= if present and on-site,
otherwise to the page you configure — the WooCommerce account page by default,
or the site home).admin-ajax.php call. Failed password attempts are rate-limited per IP address
and per email in a short rolling window before WordPress authentication runs,
and an off-screen honeypot field plus a minimum fill-time check drop obvious bot
submissions without the (CPU-heavy) password hash. Together these keep
credential-stuffing traffic from turning the login page into a load problem.
(When Unknown accounts is set to reveal missing accounts, step 1 still needs a
server round trip, since that answer can only come from the database.)
Privacy
By default the two possible step-1 responses are identical whether or not an account
exists, and failed logins return a single generic message — so the form cannot be
used to discover which email addresses have accounts. A setting lets you turn on
explicit "no account found" messages if you prefer Amazon's behaviour.
Settings (Settings → Two-Screen Login)
templates/step-identifier.php, templates/step-password.php)
can be swapped with the tslf_template filter. Style hooks are plain classes
(.tslf, .tslf-form, .tslf-step, .tslf-error, .tslf-submit) and CSS custom
properties (--tslf-accent, --tslf-border, …).
Notes & limitations
wp-login.php or change wp-admin.t2f-two-screen-login.[two_step_login].Yes. If WooCommerce is active and no redirect is configured, users land on the My Account page after logging in. It does not otherwise depend on WooCommerce.
Yes — set First step accepts to "Email address or username".
The stepped experience is JavaScript-driven, but the form also works with JS disabled or blocked: it falls back to a full-page, step-by-step flow instead of the in-browser transition. The bot timing check is skipped for no-JS submissions (the honeypot and rate limiting still apply).
Yes, via a checkbox on the password step.
No. It is sent once, over your site's normal (HTTPS) connection, to WordPress's
standard wp_signon() authentication — the same function core uses.
<form> has no action attribute, so with JavaScript disabled or blocked it silently failed to sign anyone in — there was no server-side handler for that plain POST. A Post/Redirect/Get fallback now handles it and resumes the flow step by step.?redirect_to= was silently dropped on the default sign-in flow, since the request that authenticates carries no query string of its own. It's now carried forward as a hidden field.example.com/blog) by doubling the site's own path prefix.uninstall.php only cleaned up the site it ran on, and missed the non-JS fallback's own transients. It's now multisite-aware and covers both transient prefixes.