A passwordless sign-in option. When enabled:
- User enters email on login page and clicks "Email me a sign-in link instead"
- AJAX action
or_send_magic_linkfires - A secure 48-character token is stored in a transient (15-minute expiry)
- Email sent with link:
https://yoursite.com/?or_magic={token} - On click: token validated, user logged in, redirected to dashboard
Security notes:
- Tokens are single-use (deleted immediately on use)
- 15-minute expiry enforced via WordPress transients
- Works via
inithook so no page needed
