Automattic / Automattic/jetpack

Comments: ampersand triggers "Invalid security token" warning

Open
#2,898 4 comments 0 reactions 0 assignees View on GitHub
[Feature] Comments [Platform] Atomic [Platform] Simple [Plugin] Jetpack [Pri] Normal Bug Triaged
Dominant language
PHP
Stars
1.8k
Forks
898
Avg merge
1d 18h
Merged PRs (30d)
774

Description

Steps to reproduce:
1. Enable Jetpack Comments.
2. Go to a post including a comment form.
3. Enter the following in the comment field: `test & test again`
4. Submit your comment.

https://cloudup.com/clQhQJ61_HB

I couldn't reproduce on WordPress.com.

Reported here:
https://wordpress.org/support/topic/invalid-security-token-when-exists-in-comment?replies=1&view=all

Contributor guide

Open the contributing guide

Research direction

Start by reproducing the warning with Jetpack Comments using the supplied steps and comment text, then trace the comment submission and security-token handling from the comment form. Compare the behavior with WordPress.com if useful; done means the comment submits without the invalid security token warning while preserving normal token validation.

Written by the indexing model from the issue text.

Assessment

Tech stack
php
Domain
backend, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.