wpDiscuz - WordPress Comment Plugin
Share:
Notifications
Clear all

"Nonce Is Invalid" in version 3.7.9


NintendoReporters
Posts: 5
Topic starter
(@nintendoreporters)
Active Member
Joined: 1 year ago

Hi there,

Since the upgrade to 3.7.9 we have been running into nonce errors.
Various browsers, various users etc.

Cleared all possible caches server side, cleared all CDN cache, did testing in browsers which have never ever accessed the website (as in Firefox dev edition, Safari Tech Preview and Chromium)

So I really think this is something that should be looked into.

Hope you can look into this soon, as this is preventing users from commenting all together.
And before you ask, I can not make a mirror / staging of this site. It's way to big for that 😉

Best regards,
Patrick

Topic Tags
3 Replies
NintendoReporters
Posts: 5
Topic starter
(@nintendoreporters)
Active Member
Joined: 1 year ago

Ok this seems to be down to an issue I noted a while back already.
If someone changed there default upload dir in Wordpress it will throw a 500 error.

function wpdiscuz_ABSPATH() {
    $path = join(DIRECTORY_SEPARATOR, ["wp-content", "plugins", "wpdiscuz", "utils", "ajax"]);
    return str_replace($path, "", __DIR__);
}

This is in; wpdiscuz-ajax.php
The wp-content mention here should be gotten dynamically to make sure this can never be an issue.

So yes issue on my end, for customizing things.
But that does not mean leaving it hardcoded to be wp-content is a good option.

Do hope you can look into this in a future release.

Reply
2 Replies
Asti
 Asti
Support
(@asti)
Joined: 4 years ago

Support member
Posts: 4116

@nintendoreporters,

Please let us know when you've updated the plugin? Also, let us know if the issue exists for the registered users or guests. 

Reply
NintendoReporters
(@nintendoreporters)
Joined: 1 year ago

Active Member
Posts: 5
Posted by: @asti

@nintendoreporters,

Please let us know when you've updated the plugin? Also, let us know if the issue exists for the registered users or guests. 

Hi there, we last updated to 3.7.9.
But as explained the issue is due to the hardcoded option of wp-content in wpdiscuz-ajax.php

if that could be replaced to bee dynamic that would bee wondeful.

Reply
Share: