WordPress.org

China 简体中文

  • 主题
  • 插件
  • 新闻
    • 文档
    • 论坛
  • 关于
  • 获取 WordPress
获取 WordPress
WordPress.org

Plugin Directory

Invalidate Logged Out Cookies

  • 提交插件
  • 我的收藏
  • 登录
  • 提交插件
  • 我的收藏
  • 登录

该插件尚未通过WordPress的最新3个主要版本进行测试。 当与较新版本的WordPress一起使用时,可能不再受到维护或支持,并且可能会存在兼容性问题。

Invalidate Logged Out Cookies

作者:laceous
下载
  • 详情
  • 评价
  • 安装
  • 开发进展
支持

描述

Due to lack of interest (both my own and based on the number of downloads) this plugin will not be updated for WP 3.0

WordPress’ auth cookies include a built-in expiration date (either 2 or 14 days depending on if the ‘Remember Me’ option is checked). Even if you remove the client-side cookie (by manually logging out or just closing your browser if ‘Remember Me’ wasn’t checked when logging in) the data that was stored within the cookie is still valid until the expiration date is reached.

This could be an issue if someone managed to “steal” your cookie(s). They would still be able to access your website for some time into the future.

This plugin will immediately invalidate your auth cookies when you manually log out. This, of course, also means that you have to manually click ‘Log out’ for this plugin to work properly (you can’t just close your browser to remove any cookies that expire at the end of the session). This won’t prevent session hijacking, but should limit the amount of time that an attacker can access your website.

安装

  1. Upload the entire invalidate-logged-out-cookies/ directory to the /wp-content/plugins/ directory
  2. Activate the plugin through the ‘Plugins’ menu in WordPress
  • If upgrading manually, make sure to disable and then re-enable the plugin (upgrading through the admin interface will do this automatically)

常见问题

Will this plugin invalidate my cookies if I logged in before the plugin was activated?

No. This plugin will only invalidate cookies that were created after activating the plugin.

Will this plugin work with non-standard auth cookies?

Most likely, no. This plugin is only meant to be used with the standard auth cookies that WordPress uses.

Known conflicts with other plugins

This plugin overrides the core wp_validate_auth_cookie function. This means that you can’t enable this plugin and another that also overrides the same function.

This is a non-comprehensive list of other plugins that also override this function (and should not be used at the same time as this plugin):

  • Safer Cookies
  • Admin SSL
  • WordPress 2.6+ and bbPress 0.9 cookie integration
  • No Login
  • Disclose-Secret
  • PhotoQ Photoblog Plugin

It’s also possible that if another plugin is overriding a related function (e.g. wp_generate_auth_cookie) that this plugin will not work correctly.

How can I know if this plugin is properly overriding the ‘wp_validate_auth_cookie’ function?

Once activated, if this plugin is NOT overriding the function, then a message will be shown to admin users towards the top of every admin page.

What if I can’t log in after activating this plugin?

Simply rename or delete the plugin so WordPress can’t find it. This step requires that you have access to the filesystem where WordPress is installed (via FTP, SFTP, etc).

There’s a small chance that this might happen. It most likely happens because of an incompatibility with another plugin that also overrides one of the core auth_cookie functions.

评价

此插件暂无评价。

贡献者及开发者

「Invalidate Logged Out Cookies」是开源软件。 以下人员对此插件做出了贡献。

贡献者
  • laceous

帮助将「Invalidate Logged Out Cookies」翻译成简体中文。

对开发感兴趣吗?

您可以浏览代码,查看SVN仓库,或通过RSS订阅开发日志。

更新日志

0.1.1

  • Update for WP 2.9 (supports WP 2.9 only)
  • Added the auth_cookie_invalidated_cookie action

0.1

  • Initial version (supports WP 2.8 only)

额外信息

  • 版本 0.1.1
  • 最后更新:16 年前
  • 活跃安装数量 10+
  • WordPress 版本 2.9 或更高版本
  • 已测试的最高版本为 2.9.2
  • 语言
    English (US)
  • 标签
    cookiesloginlogoutsecurity
  • 高级视图

评级

尚未提交反馈。

添加我的评价

查看全部评论

贡献者

  • laceous

支持

有话要说吗?是否需要帮助?

查看支持论坛

  • 关于
  • 新闻
  • 主机
  • 隐私
  • 陈列窗
  • 主题
  • 插件
  • 区块样板
  • 学习
  • 支持
  • 开发者
  • WordPress.tv ↗︎
  • 参与
  • 活动
  • 捐赠 ↗
  • 未来五分计划
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org
WordPress.org

China 简体中文

  • 关注我们的 X(原 Twitter)账号
  • 访问我们的 Bluesky 账号
  • 关注我们的 Mastodon 账号
  • 访问我们的 Threads 账号
  • 访问我们的 Facebook 公共主页
  • 关注我们的 Instagram 账号
  • 关注我们的 LinkedIn 主页
  • 访问我们的 TikTok 账号
  • 访问我们的 YouTube 频道
  • 访问我们的 Tumblr 账号
代码如诗