Fix #26962: Retaining user info in user edit after submit#11491
Fix #26962: Retaining user info in user edit after submit#11491yashyadav-mo wants to merge 6 commits intoWordPress:trunkfrom
Conversation
|
The following accounts have interacted with this PR and/or linked issues. I will continue to update these lists as activity occurs. You can also manually ask me to refresh this list by adding the Unlinked AccountsThe following contributors have not linked their GitHub and WordPress.org accounts: @root@MO-LT-0519.localdomain. Contributors, please read how to link your accounts to ensure your work is properly credited in WordPress releases. Core Committers: Use this line as a base for the props when committing in SVN: To understand the WordPress project's expectations around crediting contributors, please review the Contributor Attribution page in the Core Handbook. |
|
Hi @yashyadav-mo! 👋 Thank you for your contribution to WordPress! 💖 It looks like this is your first pull request to No one monitors this repository for new pull requests. Pull requests must be attached to a Trac ticket to be considered for inclusion in WordPress Core. To attach a pull request to a Trac ticket, please include the ticket's full URL in your pull request description. Pull requests are never merged on GitHub. The WordPress codebase continues to be managed through the SVN repository that this GitHub repository mirrors. Please feel free to open pull requests to work on any contribution you are making. More information about how GitHub pull requests can be used to contribute to WordPress can be found in the Core Handbook. Please include automated tests. Including tests in your pull request is one way to help your patch be considered faster. To learn about WordPress' test suites, visit the Automated Testing page in the handbook. If you have not had a chance, please review the Contribute with Code page in the WordPress Core Handbook. The Developer Hub also documents the various coding standards that are followed:
Thank you, |
Test using WordPress PlaygroundThe changes in this pull request can previewed and tested using a WordPress Playground instance. WordPress Playground is an experimental project that creates a full WordPress instance entirely within the browser. Some things to be aware of
For more details about these limitations and more, check out the Limitations page in the WordPress Playground documentation. |
e45c5e2 to
5a9766f
Compare
09a37b2 to
5ef2943
Compare
4c530d4 to
b3537ae
Compare
Core Track Ticket: https://core.trac.wordpress.org/ticket/26962
Problem
When updating a user on wp-admin/profile.php or wp-admin/user-edit.php, any validation error causes the form to be rebuilt from stored database values. As a result, valid changes entered in other fields are lost from the screen after reload, forcing the user to re-enter them.
This is inconsistent with the Add New User flow in wp-admin/user-new.php, which preserves submitted values after an error.
Root Cause
wp-admin/user-edit.php calls edit_user( $user_id ) on submit. If that returns WP_Error, the page falls through to rendering and rebuilds form state with get_user_to_edit( $user_id ).
get_user_to_edit() only loads persisted user data from the database, so it has no knowledge of the submitted $_POST values from the failed request. That means the form loses the user's unsaved but valid input.
An earlier approach tried to partially save valid fields even when validation failed, but that changes database state during an error path and conflicts with existing edit_user() behavior and PHPUnit expectations.
Solution
This PR keeps edit_user() non-persisting on validation failure and fixes the problem at the form-rendering layer instead.
It introduces a helper in wp-admin/includes/user.php that:
Starts from get_user_to_edit( $user_id )
Overlays safe submitted values from $_POST onto the returned WP_User object
Excludes fields that failed validation based on WP_Error metadata and known username/password-related error codes
Never repopulates password fields
wp-admin/user-edit.php now uses that helper when rerendering the form after a failed update, so valid submitted values remain visible without being written to the database.
The implementation also handles option-backed controls used by the profile form, such as:
administration color scheme
toolbar preference
other personal option toggles
This preserves the user’s submitted state on error while keeping database data unchanged until validation succeeds.