CreaCaptcha

password-reset.php

ALTCHA protection for the WordPress password-reset (lost password) form.

Table of Contents

Functions

creationell_captcha_password_reset_enabled()  : bool
Whether password-reset protection is enabled.
creationell_captcha_password_reset_render()  : void
Renders the widget inside the lost-password form.
creationell_captcha_password_reset_exempt_reason()  : string|null
Why the current request is not a public lost-password form submission.
creationell_captcha_password_reset_exempt_label()  : string
Human-readable label for an exemption reason, for the event log.
creationell_captcha_password_reset_verify()  : void
Verifies the captcha during a password-reset request.

Functions

creationell_captcha_password_reset_enabled()

Whether password-reset protection is enabled.

creationell_captcha_password_reset_enabled() : bool
Return values
bool

creationell_captcha_password_reset_render()

Renders the widget inside the lost-password form.

creationell_captcha_password_reset_render() : void

creationell_captcha_password_reset_exempt_reason()

Why the current request is not a public lost-password form submission.

creationell_captcha_password_reset_exempt_reason() : string|null

lostpassword_post is NOT a form hook. WordPress core fires it inside retrieve_password() (wp-includes/user.php), and that function is also the back end of every administrative and programmatic reset: wp_ajax_send_password_reset() behind the "Send reset link" button on user-edit.php, the "Send password reset" bulk action in wp-admin/users.php, and any WP-CLI or third-party plugin call. None of those ever renders our widget, so demanding a solved challenge there rejected the request with "Die Sicherheitsabfrage wurde nicht bestanden" and no mail was ever sent — retrieve_password() bails out before dispatch once $errors is non-empty.

Returns the reason rather than a bare bool for two reasons: the caller logs it on the verified event exactly like a bypass reason, and every branch stays individually observable in the regression test. Under the CLI SAPI a bool predicate could only ever show its CLI branch — which is why the administrative branch is checked FIRST here, before the non-interactive ones. In production the order is immaterial: WP-CLI has neither is_admin() nor a current user, so it can never take the administrative branch.

Return values
string|null —

Exemption reason, or null for a genuine form submission.

creationell_captcha_password_reset_exempt_label()

Human-readable label for an exemption reason, for the event log.

creationell_captcha_password_reset_exempt_label(string $reason) : string
Parameters
$reason : string

Reason key from creationell_captcha_password_reset_exempt_reason().

Return values
string

creationell_captcha_password_reset_verify()

Verifies the captcha during a password-reset request.

creationell_captcha_password_reset_verify(WP_Error $errors) : void
Parameters
$errors : WP_Error

Password-reset errors (passed by WordPress >= 5.4).


        
On this page

Search results