Automattic / Automattic/jetpack
Comment form requires WordPress.com login for email address even after account has been closed/purged on simple sites
- Dominant language
- PHP
- Stars
- 1.8k
- Forks
- 898
- Avg merge
- 1d 18h
- Merged PRs (30d)
- 774
Description
### Impacted plugin
Jetpack
### Quick summary
When a user attempts to submit a comment using an email address that is no longer associated with a WordPress.com account, but was previously, they are prompted to log in to WordPress.com rather than have the comment submitted.
### Steps to reproduce
Use an email address that was used for a WordPress.com account that has since been closed and purged from the system. See example in p1736874041061979-slack-C029E4HPT
1. Visit a post on a public simple site with comments enabled (and no requirement to log in prior to commenting in Discussion settings)
2. Use the email address from a closed/purged WordPress.com account in the comment form field
3. Submit the comment
4. Prompt will appear to log in to WordPress.com rather than the comment being submmitted
Reported in 9270987-zd-a8c
### Site owner impact
More than 60% of the total website/platform users
### Severity
Minor
### What other impact(s) does this issue have?
No revenue impact
### If a workaround is available, please outline it here.
Commentor must use a different email to make a comment.
### Platform (Simple and/or Atomic)
Simple
Contributor guide
Research direction
Start at the Jetpack comment form on a public Simple site and reproduce the login prompt with an email address from a closed and purged WordPress.com account. Trace the authentication decision for that email; done means the comment submits without requiring a WordPress.com login when the site does not require login.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- php, wordpress
- Domain
- authentication
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100