Skip to content

Users: Treat email addresses that differ only in letter case as the s… - #14053

Open
rvpatel wants to merge 2 commits into
WordPress:trunkfrom
rvpatel:trac-66238
Open

rvpatel wants to merge 2 commits into
WordPress:trunkfrom
rvpatel:trac-66238

Conversation

@rvpatel

@rvpatel rvpatel commented Oct 6, 2026

Copy link
Copy Markdown

Trac ticket: https://core.trac.wordpress.org/ticket/66238

What

email_exists() now matches emails case-insensitively regardless of the DB collation, so ABc@example.com can't be registered when abc@example.com exists. The Users list table flags existing case-variant duplicates so they can be cleaned up.

Index tradeoff (from Trac feedback)

The LOWER(user_email) lookup now only runs when the user_email column has a case-sensitive collation (*_bin, *_cs) or the collation can't be determined. With the default *_ci collation, the existing indexed lookup already ignores case, so no extra query is made.

The list table check only queries the email addresses on the current page, using user_email IN (...) on *_ci collations so the index is used.

Collation detection is cached per request in the private _wp_is_user_email_case_sensitive() and can be overridden with the wp_is_user_email_case_sensitive filter.

Testing

  1. npm run test:php -- --group 66238 (covers both the case-insensitive and case-sensitive paths).
  2. Create a user abc@example.com, then try to add ABc@example.com: it should be rejected with "This email address is already registered".

…ame.

`email_exists()` now matches email addresses case-insensitively regardless of
the database collation, so a second account cannot be created with an address
that only differs in letter case (for example `abc@example.com` and
`ABc@example.com`).

With the default case-insensitive collation of the users table, the existing
lookup already ignores letter case and uses the `user_email` index, so no extra
query is made. The `LOWER()` fallback, which cannot use the index, only runs
when the `user_email` column has a case-sensitive collation or the collation
cannot be determined. This is detected once per request by the new private
`_wp_is_user_email_case_sensitive()` function, and can be overridden with the
`wp_is_user_email_case_sensitive` filter.

The Users list table also flags users on the current page whose email address
is shared with another account, ignoring letter case, so that existing
duplicates can be found and cleaned up. The lookup only uses the addresses on
the current page and is index-friendly on case-insensitive collations.

See #66238.
@github-actions

github-actions Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

The following accounts have interacted with this PR and/or linked issues. I will continue to update these lists as activity occurs. You can also manually ask me to refresh this list by adding the props-bot label.

Core Committers: Use this line as a base for the props when committing in SVN:

Props ravipatel, westonruter.

To understand the WordPress project's expectations around crediting contributors, please review the Contributor Attribution page in the Core Handbook.

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown

Test using WordPress Playground

The changes in this pull request can previewed and tested using a WordPress Playground instance.

WordPress Playground is an experimental project that creates a full WordPress instance entirely within the browser.

Some things to be aware of

  • All changes will be lost when closing a tab with a Playground instance.
  • All changes will be lost when refreshing the page.
  • A fresh instance is created each time the link below is clicked.
  • Every time this pull request is updated, a new ZIP file containing all changes is created. If changes are not reflected in the Playground instance,
    it's possible that the most recent build failed, or has not completed. Check the list of workflow runs to be sure.

For more details about these limitations and more, check out the Limitations page in the WordPress Playground documentation.

Test this pull request with WordPress Playground.

@westonruter

Copy link
Copy Markdown
Member

Please add the AI disclosure to the PR description:

## Use of AI Tools
<!--
You are free to use artificial intelligence (AI) tooling to contribute, but you must disclose what tooling you are using and to what extent a pull request has been authored by AI. It is your responsibility to review and take responsibility for what AI generates. See the WordPress AI Guidelines: <https://make.wordpress.org/ai/handbook/ai-guidelines/>.
Example disclosure:
AI assistance: Yes
Tool(s): GitHub Copilot, ChatGPT
Model(s): GPT-5.1
Used for: Initial code skeleton and test suggestions; final implementation and tests were reviewed and edited by me.
-->

* user, ignoring letter case. Keys are user IDs.
*
* @since 7.2.0
* @var true[]

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
* @var true[]
* @var array<int, true>

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This being said, I'm not sure an associative array is needed here. It could just be list<int>, without any mapping.

* @global wpdb $wpdb WordPress database abstraction object.
*
* @param int[] $user_ids IDs of the users to check.
* @return true[] Array keyed by the IDs of users whose email address is shared.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
* @return true[] Array keyed by the IDs of users whose email address is shared.
* @return array<int, true> Array keyed by the IDs of users whose email address is shared.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

But note above, how this could just return list<int>. An associative array seems unnecessary.

* @param int[] $user_ids IDs of the users to check.
* @return true[] Array keyed by the IDs of users whose email address is shared.
*/
protected function get_duplicate_email_user_ids( $user_ids ) {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
protected function get_duplicate_email_user_ids( $user_ids ) {
protected function get_duplicate_email_user_ids( array $user_ids ): array {

Comment thread src/wp-includes/user.php
function _wp_is_user_email_case_sensitive() {
global $wpdb;

static $is_case_sensitive = array();

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why is this an array when it only ever has one item in it?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants