wp_get_current_commenter() の使い方|説明・引数・注意点

説明

wp_get_current_commenter() は、コメントフォームの入力情報を保持している、現在のコメント投稿者の情報を返す関数です。

基本構文

wp_get_current_commenter(): array

引数

引数はありません。

戻り値

comment_author、comment_author_email、comment_author_url を含む配列。

使い方(サンプル)

$commenter = wp_get_current_commenter();

注意点

  • Cookieに保存された情報を元にしています。

実務での使いどころ

  • コメントフォームに、以前に入力した、名前やメールアドレスを、あらかじめ入れるとき。

よくあるミスと対処

  • ログインしていない訪問者の、Cookieの値であることを、考えていない。信頼できない入力として扱う。
  • コメントしたことがない訪問者では、値が空になる。
  • 出力時に、エスケープしていない。

NG例

$commenter = wp_get_current_commenter();
echo '<input value="' . $commenter['comment_author'] . '">'; // 出力時のエスケープが、省かれている

OK例

$commenter = wp_get_current_commenter();
echo '<input name="author" value="' . esc_attr( $commenter['comment_author'] ) . '">';

使い分け早見表

関数 取得するもの
wp_get_current_commenter() Cookieに保存された、コメント投稿者の情報
wp_get_current_user() ログイン中のユーザーの情報
get_comments() コメントの一覧

関連項目

comments_template()、wp_insert_comment()、get_comments()

公式リファレンス:wp_get_current_commenter() | Function | WordPress Developer Resources

コメント

タイトルとURLをコピーしました