From a24a06002081ad71a78ffeff9072725ba39cf121 Mon Sep 17 00:00:00 2001
From: Jake Vanderwerf <get@jakevanderwerf.ca>
Date: Tue, 17 Feb 2026 20:05:31 +0000
Subject: [PATCH] =minor changes, particularly around the JVB_CHILD_URL pattern
---
inc/rest/routes/LoginRoutes.php | 43 +++++++++++++++----------------------------
1 files changed, 15 insertions(+), 28 deletions(-)
diff --git a/inc/rest/routes/LoginRoutes.php b/inc/rest/routes/LoginRoutes.php
index ef66bb2..8ab30ce 100644
--- a/inc/rest/routes/LoginRoutes.php
+++ b/inc/rest/routes/LoginRoutes.php
@@ -39,7 +39,8 @@
Route::for('auth/status')
->get([$this, 'getAuthStatus'])
->auth('public')
- ->rateLimit(60, 60);
+ ->rateLimit()
+ ->register();
// Standard login
Route::for('auth/login')
@@ -51,7 +52,8 @@
'redirect_to' => 'string',
])
->auth('public')
- ->rateLimit(5, 300);
+ ->rateLimit(5, 300)
+ ->register();
// User registration
Route::for('auth/register')
@@ -64,7 +66,8 @@
'redirect_to' => 'string',
])
->auth('public')
- ->rateLimit(3, 3600);
+ ->rateLimit(3, 3600)
+ ->register();
// Request password reset
Route::for('auth/lostpassword')
@@ -73,7 +76,8 @@
'user_email' => 'email|required',
])
->auth('public')
- ->rateLimit(3, 3600);
+ ->rateLimit(3, 3600)
+ ->register();
// Reset password with token
Route::for('auth/resetpass')
@@ -85,7 +89,8 @@
'pass2' => 'string|required',
])
->auth('public')
- ->rateLimit(5, 300);
+ ->rateLimit(5, 300)
+ ->register();
// Magic link endpoint
if ($this->hasMagicLink) {
@@ -97,14 +102,16 @@
'redirect_to' => 'string',
])
->auth('public')
- ->rateLimit(5, 3600);
+ ->rateLimit(5, 3600)
+ ->register();
}
// Logout endpoint
Route::for('auth/logout')
->post([$this, 'handleLogout'])
->auth('logged_in')
- ->rateLimit(10, 60);
+ ->rateLimit(10)
+ ->register();
}
/**
@@ -333,7 +340,7 @@
'error' => $key->get_error_message(),
]);
} else {
- $this->sendPasswordResetEmail($user, $key);
+ $success = JVB()->email()->sendPasswordResetEmail($user, $key);
}
}
@@ -703,26 +710,6 @@
}
}
- /**
- * Send password reset email (fallback if magic links not available)
- */
- protected function sendPasswordResetEmail(WP_User $user, string $key): bool
- {
- $reset_url = network_site_url(
- "wp-login.php?action=rp&key=$key&login=" . rawurlencode($user->user_login),
- 'login'
- );
-
- $subject = 'Password Reset Request';
- $message = sprintf(
- "Hello %s,\n\nYou requested a password reset. Click the link below to reset your password:\n\n%s\n\nIf you didn't request this, please ignore this email.",
- $user->display_name,
- $reset_url
- );
-
- return wp_mail($user->user_email, $subject, $message);
- }
-
protected function buildAuth(?int $user = null): array
{
if (is_user_logged_in()) {
--
Gitblit v1.10.0