Automattic / Automattic/jetpack
Comments: ampersand triggers "Invalid security token" warning
- Dominant language
- PHP
- Stars
- 1.8k
- Forks
- 898
- Avg merge
- 1d 18h
- Merged PRs (30d)
- 774
Description
Steps to reproduce:
1. Enable Jetpack Comments.
2. Go to a post including a comment form.
3. Enter the following in the comment field: `test & test again`
4. Submit your comment.
https://cloudup.com/clQhQJ61_HB
I couldn't reproduce on WordPress.com.
Reported here:
https://wordpress.org/support/topic/invalid-security-token-when-exists-in-comment?replies=1&view=all
Contributor guide
Research direction
Start by reproducing the warning with Jetpack Comments using the supplied steps and comment text, then trace the comment submission and security-token handling from the comment form. Compare the behavior with WordPress.com if useful; done means the comment submits without the invalid security token warning while preserving normal token validation.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- php
- Domain
- backend, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 30/100