Skip to content

Fix REST nonce refresh after guest listing submission - #3027

Closed
the-sohan wants to merge 1 commit into
sovware:developmentfrom
the-sohan:fix/refresh-rest-nonce-after-guest-submission
Closed

the-sohan wants to merge 1 commit into
sovware:developmentfrom
the-sohan:fix/refresh-rest-nonce-after-guest-submission

Conversation

@the-sohan

@the-sohan the-sohan commented Sep 19, 2026 •

Copy link
Copy Markdown
Contributor

PR Type

What kind of change does this PR introduce?

  • Bugfix
  • Security fix
  • Improvement
  • New Feature
  • Refactoring (no functional changes, no api changes)
  • Build related changes
  • Text changes
  • Other... Please describe:

Description

Guest listing submission can create and authenticate a WordPress user before the form finishes validation. The page then keeps the REST nonce generated for the anonymous session. If the user corrects the validation error and submits again, REST-backed media handling sends that stale nonce with the new authentication cookie, causing WordPress to reject the request with rest_cookie_invalid_nonce / “Cookie check failed”.

Issue screenshot:

Guest listing submission displays Cookie check failed

The existing nonce-refresh AJAX handler now returns a fresh wp_rest nonce alongside the Directorist nonce. The add-listing client updates directorist.rest_nonce, wpApiSettings.nonce, and the active wp.apiFetch nonce middleware so both Directorist's direct REST requests and WordPress API clients use the authenticated session's nonce.

How to reproduce the issue or test the changes:

  1. Enable guest listing submission, include an image, and submit as a logged-out visitor with a required field left invalid so the guest account is created before validation returns an error.
  2. Correct the invalid field and submit again without reloading the page.
  3. Verify the REST upload continues successfully and no “Cookie check failed” response is shown.

Local verification:

  • pnpm run build-legacy — completed and generated the production add-listing bundle and installable package.
  • pnpm exec wp-scripts lint-js assets/src/js/global/add-listing.js — passed.
  • php -l includes/classes/class-ajax-handler.php — passed.
  • php -d 'error_reporting=E_ALL & ~E_DEPRECATED' vendor/bin/phpcs --standard=phpcs.xml includes/classes/class-ajax-handler.php — 0 errors; existing file-level alignment warnings remain.
  • Executed a focused client-side nonce propagation check confirming the refreshed nonce reaches all four consumers: Directorist nonce, Directorist REST nonce, wpApiSettings, and wp.apiFetch nonce middleware.
  • Verified the generated ZIP with unzip -tq and inspected both the PHP response field and compiled JavaScript nonce propagation.

Notes:

  • The repository requests Node 24.17.0; the available Node 26.5.0 runtime emitted an engine warning, but the legacy production build completed successfully.
  • The customer production site was inspected read-only and was not modified or submitted to during verification.

Any linked issues

Checklist

@Armanul46 Armanul46 added this to the 8.10 milestone Sep 28, 2026

@RabbiIslamRony RabbiIslamRony left a comment •

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Changes requested — already fixed by merged PR #3006

This issue has already been resolved and merged through:

I reproduced the reported guest-submission flow locally. On the base revision, the stale anonymous REST nonce caused the next image upload to fail with HTTP 403 / Cookie check failed. The refreshed nonce fixes that failure and allows the upload to proceed.

The required production-path fix is already present in development through PR #3006. This older PR now conflicts with later conditional-field changes in add-listing.js. Please close #3027 as superseded. If its broader wpApiSettings or apiFetch propagation is still required for another documented consumer, rebase it while preserving the current conditional-field behavior and request another review.

@Armanul46 Armanul46 removed this from the 8.10 milestone Sep 28, 2026
@Armanul46 Armanul46 closed this Sep 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants