WordPress Core Authentication + Password Expiration Plugin: Least‑Privilege Interaction on Expired Credentials
0 reputation · 18 Mar 2021, 10:41 UTC
The goal is to understand whether WordPress core treats a plugin‑enforced credential expiration as a least‑privilege state before any capability checks are performed, and whether this behavior is consistent across different expiration‑enforcing plugins and WordPress versions.
Because core lacks a native password‑expiration mechanism, plugins must implement their own logic (e.g., clearing auth cookies or setting expiration timestamps). This creates uncertainty about when authentication fails, whether current_user_can() is ever invoked, and if the redirect to wp-login.php occurs before any privileged content is rendered.
Does WordPress core execute any capability checks after a plugin‑initiated authentication failure due to expired credentials?
Is the redirect to wp-login.php guaranteed to happen before any capability‑based content is loaded for all expiration‑enforcing plugins?
Are there hooks that allow a plugin to alter the least‑privilege state after authentication fails but before the login redirect?