Skip to content

fix: Plugin "Check it!" button fails silently with nonce error #893 - #1418

Open
kmfoysal06 wants to merge 4 commits into
WordPress:trunkfrom
kmfoysal06:nonce-failed-error
Open

fix: Plugin "Check it!" button fails silently with nonce error #893#1418
kmfoysal06 wants to merge 4 commits into
WordPress:trunkfrom
kmfoysal06:nonce-failed-error

Conversation

@kmfoysal06

@kmfoysal06 kmfoysal06 commented Jul 26, 2026

Copy link
Copy Markdown
Contributor

What?

Closes #893

The changes in this PR are to add a custom error notice in the UI instead of showing the error in the console when an error occurs in the catch block.

Why?

The issue mentioned above shows how, after some time, when the nonce gets expired, the check plugin button does not work and shows an invalid nonce message in the console. So, the solution is either to tell the user about the nonce expiration on the client side visually or reload the page automatically. As reloading the page won't be a consistent solution, I decided to show an admin error notice informing the user that the nonce has expired.

How?

My suggested solution is to show the error message from the server side directly as an admin error notice so the user can understand why the plugin check is failing.

Testing Instructions

  1. Open 'Plugin Check' from Dashboard > Tools.
  2. Open Browser DevTools and paste PLUGIN_CHECK.nonce = 'gg' and press Enter to make the nonce invalid.
  3. Select any plugin and click the "Check It!" button to check the plugin.
  4. The admin error notice will be visible with the error message from the server side.

AI Usage Disclosure

  • This PR was created without the help of AI tools
  • This PR includes AI-assisted code or content

If AI tools were used, please describe how they were used:
AI tools used in this PR only to modify the PR message to ensure no grammar mistake included in the message.

Before After
image image
Open WordPress Playground Preview

Unlinked contributors: tamimhasan19702, rtpHarry.

Co-authored-by: kmfoysal06 kmfoysal06@git.wordpress.org
Co-authored-by: iyut aralle@git.wordpress.org

@github-actions

github-actions Bot commented Jul 26, 2026

Copy link
Copy Markdown

The following accounts have interacted with this PR and/or linked issues. I will continue to update these lists as activity occurs. You can also manually ask me to refresh this list by adding the props-bot label.

Unlinked Accounts

The following contributors have not linked their GitHub and WordPress.org accounts: @sajjadfaraj-dev, @tamimhasan19702, @rtpHarry.

Contributors, please read how to link your accounts to ensure your work is properly credited in WordPress releases.

If you're merging code through a pull request on GitHub, copy and paste the following into the bottom of the merge commit message.

Unlinked contributors: sajjadfaraj-dev, tamimhasan19702, rtpHarry.

Co-authored-by: kmfoysal06 <kmfoysal06@git.wordpress.org>
Co-authored-by: iyut <aralle@git.wordpress.org>

To understand the WordPress project's expectations around crediting contributors, please review the Contributor Attribution page in the Core Handbook.

@sajjadfaraj-dev sajjadfaraj-dev left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I tested this PR locally against the current branch on Fedora.

Validation passed for me:

  • npm run lint-js
  • composer lint

The fix also looks nicely scoped to the reported failure.

One accessibility question: since #plugin-check__client-error becomes visible asynchronously after the request fails, would it be worth giving the notice alert/live-region semantics (for example role="alert"), so the new error is announced to screen-reader users without requiring focus to move to it?

Otherwise the visible error handling is a clear improvement over the current silent failure.

@kmfoysal06

Copy link
Copy Markdown
Contributor Author

Hello @sajjadfaraj-dev
Thank you for your time reviewing this PR. I agree with you and I will let you know when I update the code to add the mentioned accessibility improvement.

@kmfoysal06

Copy link
Copy Markdown
Contributor Author

Hello @sajjadfaraj-dev I just updated the alert. can you please review it again.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Plugin "Check it!" button fails silently with nonce error

2 participants