• Resolved baboehm

    (@baboehm)


    Hi there,

    similar to https://wordpress.org/support/topic/trailing-whitespace-2/ I’m having issues with comments not going through if there are trailing whitespaces in the author or comment field (the only fields we use here). [Edit: This is about the WP-Comments, not CF7 as in the linked topic]
    Apparently this is something that mobile phones tend to do – adding a whitespace after each word, which is why we’ve had 7 out of 10 comments fail this morning.

    I was able to fix it locally with a small mu-plugin that’s basically using the way the CF7 integration is doing it already:

    add_filter('mosparo_integration_comments_form_data', function ($formData) { foreach (['comment', 'author', 'email', 'url'] as $field) { if (isset($_POST[$field]) && !is_array($_POST[$field])) { $formData[$field] = wp_unslash((string) $_POST[$field]); } } return $formData; }, 20);

    Here’s what AI has to say about the problem:

    The Comments module is the only module that does not verify the raw submitted values. CommentForm::verifyComment() runs on the pre_comment_approved filter and builds the verification data from $commentData (comment_content, comment_author, …). At that point WordPress has already modified these values:

    1. wp_handle_comment_submission() applies trim() to comment, author, email and url.
    2. wp_new_comment() calls wp_filter_comment() before pre_comment_approved fires. That applies the pre_comment_content filters (wp_filter_kses: & becomes &amp;, </> become entities, tags are stripped; wp_rel_ugc; wp_encode_emoji on non-utf8mb4 databases) and sanitize_text_field() / sanitize_email() / esc_url_raw() to the author fields – plus whatever third-party plugins do on preprocess_comment.

    The mosparo frontend JS, however, hashed the raw field values at check-form-data time. Any single-character difference makes the verify hash comparison fail, the field is treated as manipulated, and the module returns spam – regardless of the actual spam rating.

    Tech:
    WP 7.1
    mosparo version: 1.5.5
    mosparo Integration: 1.18.2
    Invisible mode

    Think you can fix this in a future update? Or am I doing something wrong?
    Thanks and best Wishes!
    Bastian

    • This topic was modified 3 weeks, 2 days ago by baboehm.
Viewing 4 replies - 1 through 4 (of 4 total)
  • Plugin Support Matthias Zobrist

    (@zepich)

    Hi @baboehm / Bastian

    Thank you very much for your report and your analysis.

    You are not doing anything wrong, and the solution with the filter is absolutely correct. It doesn’t have to be in a mu-plugin from my perspective, but that doesn’t matter (it could also be a theme or a normal plugin).

    I will look into this issue and release a new version of the plugin as soon as possible. This needs to be fixed in the plugin, of course, and it should not be required for the users to write custom plugins to handle this case.

    I’m not sure why we didn’t add the fix for the comments module when we fixed the other modules. As far as I can remember, I’ve tested all the modules back then.

    I’m sorry for the trouble.

    Kind regards,
    zepich

    Thread Starter baboehm

    (@baboehm)

    Hi zepich,
    good to know, thanks!

    I went the mu-plugin route as that was the fastest at that moment 🙂
    Looking forward to the new version then, in the meantime I’ll keep my fix active.

    Thanks for a great plugin!

    Plugin Support Matthias Zobrist

    (@zepich)

    Hi @baboehm

    Thank you very much for your nice words.

    As you may have seen, we released v1.18.3 yesterday, which fixes the behavior with the comments module. I also found that quotation marks (“) are not working correctly because of the slashes.

    I didn’t see how the wp_filter_kses method is called (as you wrote in your first post). As far as I can tell, it’s only called when the user is logged in, but in that scenario, mosparo is not active for the comments.

    Thank you very much for your help in making mosparo better!

    Kind regards,
    zepich

    Thread Starter baboehm

    (@baboehm)

    Hi zepich,
    Thanks for the quick fix and the great mosparo!

Viewing 4 replies - 1 through 4 (of 4 total)

You must be logged in to reply to this topic.