password-reset.php
ALTCHA protection for the WordPress password-reset (lost password) form.
Table of Contents
Functions
- creationell_captcha_password_reset_enabled() : bool
- Whether password-reset protection is enabled.
- creationell_captcha_password_reset_render() : void
- Renders the widget inside the lost-password form.
- creationell_captcha_password_reset_exempt_reason() : string|null
- Why the current request is not a public lost-password form submission.
- creationell_captcha_password_reset_exempt_label() : string
- Human-readable label for an exemption reason, for the event log.
- creationell_captcha_password_reset_verify() : void
- Verifies the captcha during a password-reset request.
Functions
creationell_captcha_password_reset_enabled()
Whether password-reset protection is enabled.
creationell_captcha_password_reset_enabled() : bool
Return values
boolcreationell_captcha_password_reset_render()
Renders the widget inside the lost-password form.
creationell_captcha_password_reset_render() : void
creationell_captcha_password_reset_exempt_reason()
Why the current request is not a public lost-password form submission.
creationell_captcha_password_reset_exempt_reason() : string|null
lostpassword_post is NOT a form hook. WordPress core fires it inside
retrieve_password() (wp-includes/user.php), and that function is also the
back end of every administrative and programmatic reset:
wp_ajax_send_password_reset() behind the "Send reset link" button on
user-edit.php, the "Send password reset" bulk action in wp-admin/users.php,
and any WP-CLI or third-party plugin call. None of those ever renders our
widget, so demanding a solved challenge there rejected the request with
"Die Sicherheitsabfrage wurde nicht bestanden" and no mail was ever sent —
retrieve_password() bails out before dispatch once $errors is non-empty.
Returns the reason rather than a bare bool for two reasons: the caller logs
it on the verified event exactly like a bypass reason, and every branch
stays individually observable in the regression test. Under the CLI SAPI a
bool predicate could only ever show its CLI branch — which is why the
administrative branch is checked FIRST here, before the non-interactive
ones. In production the order is immaterial: WP-CLI has neither is_admin()
nor a current user, so it can never take the administrative branch.
Return values
string|null —Exemption reason, or null for a genuine form submission.
creationell_captcha_password_reset_exempt_label()
Human-readable label for an exemption reason, for the event log.
creationell_captcha_password_reset_exempt_label(string $reason) : string
Parameters
- $reason : string
-
Reason key from creationell_captcha_password_reset_exempt_reason().
Return values
stringcreationell_captcha_password_reset_verify()
Verifies the captcha during a password-reset request.
creationell_captcha_password_reset_verify(WP_Error $errors) : void
Parameters
- $errors : WP_Error
-
Password-reset errors (passed by WordPress >= 5.4).