Jake Vanderwerf
2026-02-17 a24a06002081ad71a78ffeff9072725ba39cf121
inc/managers/LoginManager.php
@@ -1,11 +1,9 @@
<?php
namespace JVBase\managers;
use JVBase\blocks\CustomBlocks;
use JVBase\forms\TaxonomySelector;
use JVBase\meta\MetaManager;
use JVBase\meta\MetaForm;
use JVBase\managers\AjaxRateLimiter;
use JVBase\meta\Form;
use JVBase\utility\Features;
use WP_Error;
use WP_User;
@@ -17,8 +15,8 @@
class LoginManager
{
   protected Features $siteFeatures;
   protected ?MetaForm $metaForm = null;
   protected CacheManager $cache;
   protected ?Form $form = null;
   protected Cache $cache;
   protected array $forms =[];
@@ -43,7 +41,7 @@
      $this->siteFeatures = Features::forSite();
      $this->cache = CacheManager::for('login');
      $this->cache = Cache::for('login');
      // Initialize magic link support if enabled
      if ($this->siteFeatures->has('magicLink')) {
@@ -63,6 +61,7 @@
      // Login success handling
      add_action('wp_login', [$this, 'handleSuccessfulLogin'], 10, 2);
      add_filter('lostpassword_url', [$this, 'resetPasswordUrl'], 10, 2);
      add_filter( 'login_url', [$this, 'loginUrl'], 10, 3 );
      add_filter( 'logout_url', [$this, 'logoutUrl'], 10, 2 );
      // Allow other features to register handlers
@@ -227,12 +226,14 @@
                  'type' => 'email',
                  'label' => __('Email Address', 'jvb'),
                  'required' => true,
                  'autocomplete' => 'email',
                  'placeholder' => 'look@me.com',
               ],
               'user_password' => [
                  'type' => 'text',
                  'subtype'=> 'password',
                  'label' => __('Password', 'jvb'),
                  'autocomplete' => 'current-password',
                  'required' => true,
               ],
               'remember_me' => [
@@ -306,20 +307,26 @@
   }
   public function logoutUrl(string $logout_url, string $redirect): string
{
   // Build custom logout URL
   $logout_url = site_url('/login/', 'login');
   $logout_url = add_query_arg('action', 'logout', $logout_url);
   {
      // Build custom logout URL
      $logout_url = site_url('/login/', 'login');
      $logout_url = add_query_arg('action', 'logout', $logout_url);
   if (!empty($redirect)) {
      $logout_url = add_query_arg('redirect_to', urlencode($redirect), $logout_url);
      if (!empty($redirect)) {
         $logout_url = add_query_arg('redirect_to', urlencode($redirect), $logout_url);
      }
      // Add nonce for security
      return wp_nonce_url($logout_url, 'log-out');
   }
   public function resetPasswordUrl(string $url, string $redirect):string
   {
      error_log('reset Password Url:'.print_r($url, true));
      error_log('reset password redirect: '.print_r($redirect, true));
   // Add nonce for security
   $logout_url = wp_nonce_url($logout_url, 'log-out');
      return str_replace('wp_login.php', 'login/', $url);
   return $logout_url;
}
   }
   public function getLoginPage():int|false
   {
      return (int)get_option(BASE.'login_page');
@@ -401,17 +408,11 @@
   protected function setup():void
   {
      $this->action = $this->getAction();
      if (in_array($this->action, ['logout']) || array_key_exists('loggedout', $_GET)) {
      if ($this->action == 'logout' || array_key_exists('loggedout', $_GET)) {
         wp_logout();
         wp_redirect(esc_attr($_GET['redirect_to'] ?? get_home_url()));
         exit;
      }
      if (in_array($this->action, ['rp', 'resetpass']) && !is_user_logged_in()) {
         wp_redirect(wp_login_url());
         exit;
      } elseif (is_user_logged_in()) {
         wp_redirect(get_home_url(null, '/dash/'));
      }
      $this->setupLabels();
      $this->setupFields();
      $this->setupTitle();
@@ -438,11 +439,9 @@
   protected function customStyles():void
   {
      $logo = get_theme_mod('custom_logo');
      $small = $large = '';
      if ($logo) {
         $small = wp_get_attachment_image_src($logo, 'medium')[0];
         $large = wp_get_attachment_image_src($logo, 'large')[0];
         $small = wp_get_attachment_image_src($logo, 'medium')[0]??'';
         $large = wp_get_attachment_image_src($logo, 'large')[0]??'';
      }
      echo '<style>
         .login header,
@@ -533,7 +532,6 @@
   protected function renderForms():void
   {
      $this->metaForm = new MetaForm();
      $form = $this->action.'form';
      ?>
      <section class="login-box col btw">
@@ -552,7 +550,7 @@
            do_action('jvb_add_token_inputs', $this->action);
            foreach ($this->fields as $name => $config) {
               $this->metaForm->render($name, '', $config);
               echo Form::render($name, '', $config);
            }
            $this->maybeTurnstile();
@@ -807,6 +805,7 @@
               'successDescription' => JVB_LOGIN['forgot_password']['success']['description'] ?? ['Check your email for reset instructions'],
            ];
         case 'resetpass':
         case 'rp':
            return [
               'title' => JVB_LOGIN['reset_pass']['title'] ?? 'Reset Your Password',
               'description' => JVB_LOGIN['reset_pass']['description'] ?? [],
@@ -861,115 +860,120 @@
      SCRIPTS
   ************************************************************************/
   public function enqueueScripts(): void
   {
      if (!$this->isLoginPage()) {
         return;
      }
{
    if (!$this->isLoginPage()) {
        return;
    }
      $this->maybeTurnstileScripts();
      wp_enqueue_script('jvb-form');
      $action = $this->getAction();
      ob_start();
      ?>
    $this->maybeTurnstileScripts();
    wp_enqueue_script('jvb-form');
    $action = $this->getAction();
      document.addEventListener('DOMContentLoaded', () => {
         const form = document.querySelector('.login form');
         if (!form) return;
    $redirect_to = isset($_GET['redirect_to']) ? esc_url_raw($_GET['redirect_to']) : '';
    $has_turnstile = Features::hasIntegration('cloudflare');
         if (!window.jvbForm) {
            console.error('jvbForm not loaded');
            return;
         }
    ob_start();
         window.LoginController = new window.jvbForm();
         window.LoginController.registerForm(form, {
            autosave: false,
            endpoint: <?= "'{$action}'" ?>,
            formStatus: false,
            cache: false,
         });
    ?>
         window.LoginController.subscribe((event, data) => {
            if (event === 'form-submit') {
               handleFormSubmission(data);
            }
         });
   document.addEventListener('DOMContentLoaded', async function () {
      const hasTurnstile = <?= json_encode($has_turnstile) ?>;
      const redirectTo = <?= json_encode($redirect_to) ?>;
      window.auth.subscribe(event => {
         if (event === 'auth-loaded') {
            const form = document.querySelector('.login form');
            if (!form || !window.jvbForm) return;
         async function handleFormSubmission(data) {
         let realFormData = data.fullData;
         const { formId, config, data: formData } = data;
         const form = config.element;
         const submit = form.querySelector('[type=submit]');
         let oldText = submit.textContent;
         window.LoginController.showFormStatus(formId, 'uploading');
         try {
            submit.disabled = true;
            submit.textContent = 'Loading...';
            const response = await fetch(`${jvbSettings.api}<?=($action === 'magic') ? $action : 'auth/'.$action?>`, {
               method: 'POST',
               headers: {
                     'Content-Type': 'application/json',
                  'X-WP-Nonce': window.auth.getNonce()
               },
               body: JSON.stringify(realFormData)
            window.jvbForm.registerForm(form, {
               autosave: false,
               endpoint: '<?= $action ?>',
               formStatus: false,
               cache: false,
            });
               const result = await response.json();
            window.jvbForm.subscribe((event, data) => {
               if (event === 'form-submit') {
                  const { config } = data;
                  const formElement = config.element;
               // Handle errors
               if (!response.ok) {
                  window.LoginController.showFormStatus(formId, 'error');
                  window.LoginController.handleFormError(form, result);
                  return;
                  // Collect current form data
                  const formData = new FormData(formElement);
                  const formObject = Object.fromEntries(formData.entries());
                  let params = new URLSearchParams(window.location.search);
                  if (params.has('key')) {
                     formObject['key'] = params.get('key');
                  }
                  if (params.has('login')) {
                     formObject['login'] = params.get('login');
                  }
                  // Add redirect_to from URL
                  if (redirectTo) {
                     formObject.redirect_to = redirectTo;
                  }
                  const submit = formElement.querySelector('[type=submit]');
                  const oldText = submit.textContent;
                  window.jvbForm.showFormStatus(config.id, 'uploading');
                  submit.disabled = true;
                  submit.textContent = 'Loading...';
                  window.auth.fetch(`${jvbSettings.api}auth/<?= $action ?>`, {
                     method: 'POST',
                     body: JSON.stringify(formObject)
                  })
                  .then(response => response.json().then(result => ({ response, result })))
                  .then(({ response, result }) => {
                     if (!response.ok) {
                        window.jvbForm.showFormStatus(config.id, 'error');
                        window.jvbForm.handleFormError(formElement, result);
                        return;
                     }
                     window.jvbForm.showFormStatus(config.id, 'submitted');
                     if (result.message) {
                        window.jvbForm.handleFormSuccess(formElement, result);
                     }
                     if (window.auth?.handleLogin && result.auth) {
                        return window.auth.handleLogin(result.auth).then(() => {
                           if (result.redirect) {
                              setTimeout(() => {
                                 window.location.href = result.redirect;
                              }, 100);
                           }
                        });
                     } else if (result.redirect) {
                        setTimeout(() => {
                           window.location.href = result.redirect;
                        }, 100);
                     }
                  })
                  .catch(error => {
                     console.error('Form submission error:', error);
                     window.jvbForm.showFormStatus(config.id, 'error');
                     window.jvbForm.handleFormError(formElement, {
                        message: 'Network error. Please check your connection and try again.',
                        code: 'network_error'
                     });
                  })
                  .finally(() => {
                     submit.textContent = oldText;
                     submit.disabled = false;
                  });
               }
               // Handle success
               window.LoginController.showFormStatus(formId, 'submitted');
               // Show success message briefly before redirect
               if (result.message) {
                  window.LoginController.handleFormSuccess(form, result);
               }
               if (window.auth && typeof window.auth.handleLogin === 'function' && Object.hasOwn(result, 'auth')) {
                  console.log('Awaiting Auth...');
                  await window.auth.handleLogin(result.auth); // Pass the full result
               }
               // Handle redirect
               if (result.redirect) {
                  setTimeout(() => {
                     window.location.href = result.redirect;
                  }, 200); // Brief delay to show success message
               }
            } catch (error) {
               console.error('Form submission error:', error);
               window.LoginController.showFormStatus(formId, 'error');
               window.LoginController.handleFormError(form, {
                  message: 'Network error. Please check your connection and try again.',
                  code: 'network_error'
               });
            } finally {
               submit.textContent = oldText;
               submit.disabled = false;
            }
            });
         }
      });
   });
      <?php
   <?php
      $script = ob_get_clean();
      wp_add_inline_script('jvb-form', $script);
   }