You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

自制WordPress前端删除评论插件出现403错误的排查求助

问题分析与修复方案

核心错误原因

403错误的直接原因是AJAX请求的nonce验证失败,同时存在评论永久删除导致撤销功能失效的问题,具体如下:

  • Nonce参数不匹配:PHP默认检查$_POST['_wpnonce'],但JS传递的键名是nonce,导致验证不通过
  • 评论被永久删除:wp_delete_comment第二个参数设为true会直接删除评论,无法通过wp_untrash_comment恢复
  • 多余的未登录权限钩子:添加了wp_ajax_nopriv_*钩子,既多余又存在安全风险

具体修复步骤

1. 修正PHP代码

<?php
/*
Plugin Name: Comment Deleter
Plugin URI: https://example.com/
Description: A plugin for deleting comments with undo function and using AJAX.
Version: 1.0.0
Author: Alexis Grolot
Author URI: https://example.com/
License: GPL2
*/

function comment_deleter_enqueue_scripts() {
    wp_enqueue_script( 'comment-deleter', plugin_dir_url( __FILE__ ) . 'comment-deleter.js', array( 'jquery' ), '1.0.0', true );
    wp_localize_script( 'comment-deleter', 'comment_deleter_ajax', array( 'ajax_url' => admin_url( 'admin-ajax.php' ) ) );
}
add_action( 'wp_enqueue_scripts', 'comment_deleter_enqueue_scripts' );

function comment_deleter_delete_comment() {
    // 显式指定检查$_POST['nonce']字段
    check_ajax_referer( 'comment_deleter_delete_comment', 'nonce' );
    $commentId = isset( $_POST['comment_id'] ) ? intval( $_POST['comment_id'] ) : 0;
    $comment = get_comment( $commentId );
    
    // 验证用户是否有权限删除该评论
    if ( $comment && current_user_can( 'delete_comment', $commentId ) ) {
        // 改为false,将评论移到回收站而非永久删除
        wp_delete_comment( $commentId, false );
        wp_send_json_success();
    } else {
        wp_send_json_error( '无权限删除该评论或评论不存在' );
    }
}
// 只保留登录用户的操作钩子
add_action( 'wp_ajax_comment_deleter_delete_comment', 'comment_deleter_delete_comment' );

function comment_deleter_undo_comment() {
    // 显式指定检查$_POST['nonce']字段
    check_ajax_referer( 'comment_deleter_undo_comment', 'nonce' );
    $commentId = isset( $_POST['comment_id'] ) ? intval( $_POST['comment_id'] ) : 0;
    $comment = get_comment( $commentId );
    
    // 验证用户权限
    if ( $comment && current_user_can( 'delete_comment', $commentId ) ) {
        wp_untrash_comment( $commentId );
        wp_send_json_success();
    } else {
        wp_send_json_error( '无权限恢复该评论或评论不存在' );
    }
}
// 只保留登录用户的操作钩子
add_action( 'wp_ajax_comment_deleter_undo_comment', 'comment_deleter_undo_comment' );

2. 修正JavaScript代码

jQuery( document ).ready( function( $ ) {
    // 删除评论逻辑
    $( '.comment-delete' ).click( function( e ) {
        e.preventDefault();
        var $this = $(this);
        var commentId = $this.data( 'comment-id' );
        var nonce = $this.data( 'nonce' );
        var $comment = $( '#comment-' + commentId );
        var $undoBtn = $comment.find( '.comment-delete-undo' );

        var data = {
            action: 'comment_deleter_delete_comment',
            comment_id: commentId,
            nonce: nonce
        };

        $.post( comment_deleter_ajax.ajax_url, data, function( response ) {
            if ( response.success ) {
                $comment.fadeOut( function() {
                    $undoBtn.show();
                } );
            } else {
                alert( response.data );
            }
        } ).fail(function() {
            alert( '请求失败,请稍后重试' );
        });
    } );

    // 撤销删除逻辑
    $( '.comment-undo' ).click( function( e ) {
        e.preventDefault();
        var $this = $(this);
        var commentId = $this.data( 'comment-id' );
        var nonce = $this.data( 'nonce' );
        var $comment = $( '#comment-' + commentId );
        var $undoBtn = $comment.find( '.comment-delete-undo' );

        var data = {
            action: 'comment_deleter_undo_comment',
            comment_id: commentId,
            nonce: nonce
        };

        $.post( comment_deleter_ajax.ajax_url, data, function( response ) {
            if ( response.success ) {
                $undoBtn.hide();
                $comment.fadeIn();
            } else {
                alert( response.data );
            }
        } ).fail(function() {
            alert( '请求失败,请稍后重试' );
        });
    } );
} );

3. 优化comments.php代码

<?php if ( current_user_can( 'delete_comment', get_comment_ID() ) ) : ?>
    <a href="#" class="comment-delete" data-comment-id="<?php comment_ID(); ?>" data-nonce="<?php echo wp_create_nonce( 'comment_deleter_delete_comment' ); ?>">Delete</a>
    <span class="comment-delete-undo" style="display: none;">
        <a href="#" class="comment-undo" data-comment-id="<?php comment_ID(); ?>" data-nonce="<?php echo wp_create_nonce( 'comment_deleter_undo_comment' ); ?>">Undo</a>
    </span>
<?php endif; ?>

将权限验证改为更精准的current_user_can('delete_comment', get_comment_ID()),确保只有有权限的用户能看到操作按钮。


验证修复效果

  1. 刷新前端页面,登录管理员账号
  2. 点击Delete按钮,评论淡出并显示Undo按钮
  3. 点击Undo按钮,评论重新显示,Undo按钮隐藏
  4. 检查浏览器控制台,不再出现403错误

内容的提问来源于stack exchange,提问作者user21273704

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.30 21:51:48