Repository navigation
Conversation
There was a problem hiding this comment.
Changes requested — already fixed by merged PR #3006
This issue has already been resolved and merged through:
I reproduced the reported guest-submission flow locally. On the base revision, the stale anonymous REST nonce caused the next image upload to fail with HTTP 403 / Cookie check failed. The refreshed nonce fixes that failure and allows the upload to proceed.
The required production-path fix is already present in development through PR #3006. This older PR now conflicts with later conditional-field changes in add-listing.js. Please close #3027 as superseded. If its broader wpApiSettings or apiFetch propagation is still required for another documented consumer, rebase it while preserving the current conditional-field behavior and request another review.
PR Type
What kind of change does this PR introduce?
Description
Guest listing submission can create and authenticate a WordPress user before the form finishes validation. The page then keeps the REST nonce generated for the anonymous session. If the user corrects the validation error and submits again, REST-backed media handling sends that stale nonce with the new authentication cookie, causing WordPress to reject the request with
rest_cookie_invalid_nonce/ “Cookie check failed”.Issue screenshot:
The existing nonce-refresh AJAX handler now returns a fresh
wp_restnonce alongside the Directorist nonce. The add-listing client updatesdirectorist.rest_nonce,wpApiSettings.nonce, and the activewp.apiFetchnonce middleware so both Directorist's direct REST requests and WordPress API clients use the authenticated session's nonce.How to reproduce the issue or test the changes:
Local verification:
pnpm run build-legacy— completed and generated the production add-listing bundle and installable package.pnpm exec wp-scripts lint-js assets/src/js/global/add-listing.js— passed.php -l includes/classes/class-ajax-handler.php— passed.php -d 'error_reporting=E_ALL & ~E_DEPRECATED' vendor/bin/phpcs --standard=phpcs.xml includes/classes/class-ajax-handler.php— 0 errors; existing file-level alignment warnings remain.wpApiSettings, andwp.apiFetchnonce middleware.unzip -tqand inspected both the PHP response field and compiled JavaScript nonce propagation.Notes:
Any linked issues
Checklist