{"id":19016288,"date":"2026-09-10T07:55:37","date_gmt":"2026-09-10T07:55:37","guid":{"rendered":"https:\/\/wordpress.org\/support\/topic\/trailing-whitespace-again-in-comments-module\/"},"modified":"2026-09-10T07:56:41","modified_gmt":"2026-09-10T07:56:41","slug":"trailing-whitespace-again-in-comments-module","status":"publish","type":"topic","link":"https:\/\/wordpress.org\/support\/topic\/trailing-whitespace-again-in-comments-module\/","title":{"rendered":"Trailing whitespace &#8211; again, in comments module"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Hi there,<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">similar to <a href=\"https:\/\/wordpress.org\/support\/topic\/trailing-whitespace-2\/\">https:\/\/wordpress.org\/support\/topic\/trailing-whitespace-2\/<\/a> I&#8217;m having issues with comments not going through if there are trailing whitespaces in the author or comment field (the only fields we use here). <em>[Edit: This is about the WP-Comments, not CF7 as in the linked topic]<\/em><br \/>Apparently this is something that mobile phones tend to do &#8211; adding a whitespace after each word, which is why we&#8217;ve had 7 out of 10 comments fail this morning.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/bastian-boehm.de\/temp\/author-2.jpeg?ssl=1\" alt=\"\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/bastian-boehm.de\/temp\/superzeit.jpeg?ssl=1\" alt=\"\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">I was able to fix it locally with a small mu-plugin that&#8217;s basically using the way the CF7 integration is doing it already:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><code>add_filter('mosparo_integration_comments_form_data', function ($formData) { foreach (['comment', 'author', 'email', 'url'] as $field) { if (isset($_POST[$field]) &amp;&amp; !is_array($_POST[$field])) { $formData[$field] = wp_unslash((string) $_POST[$field]); } } return $formData; }, 20);<\/code><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Here&#8217;s what AI has to say about the problem:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Comments module is the only module that does not verify the raw submitted values. <code>CommentForm::verifyComment()<\/code> runs on the <code>pre_comment_approved<\/code> filter and builds the verification data from <code>$commentData<\/code> (<code>comment_content<\/code>, <code>comment_author<\/code>, \u2026). At that point WordPress has already modified these values:<\/p>\n\n\n\n<ol>\n<li><code>wp_handle_comment_submission()<\/code> applies <code>trim()<\/code> to comment, author, email and url.<\/li>\n\n\n\n<li><code>wp_new_comment()<\/code> calls <code>wp_filter_comment()<\/code> before <code>pre_comment_approved<\/code> fires. That applies the <code>pre_comment_content<\/code> filters (<code>wp_filter_kses<\/code>: &amp; becomes &amp;amp;, &lt;\/&gt; become entities, tags are stripped; <code>wp_rel_ugc<\/code>; <code>wp_encode_emoji<\/code> on non-utf8mb4 databases) and <code>sanitize_text_field()<\/code> \/ <code>sanitize_email()<\/code> \/ <code>esc_url_raw()<\/code> to the author fields \u2013 plus whatever third-party plugins do on <code>preprocess_comment<\/code>.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">The mosparo frontend JS, however, hashed the raw field values at check-form-data time. Any single-character difference makes the verify hash comparison fail, the field is treated as manipulated, and the module returns spam \u2013 regardless of the actual spam rating.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Tech:<br \/>WP 7.1<br \/>mosparo version: 1.5.5<br \/>mosparo Integration: 1.18.2<br \/>Invisible mode<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Think you can fix this in a future update? Or am I doing something wrong?<br \/>Thanks and best Wishes!<br \/>Bastian<\/p>\n","protected":false},"template":"","class_list":["post-19016288","topic","type-topic","status-publish","hentry"],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/19016288","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic"}],"about":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/types\/topic"}],"version-history":[{"count":1,"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/19016288\/revisions"}],"predecessor-version":[{"id":19016289,"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/19016288\/revisions\/19016289"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/media?parent=19016288"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}