SSO: Getting rid of the user token. #16915
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Changes proposed in this Pull Request:
The SSO login process performs an API request to WP.com (
jetpack.sso.validateResultendpoint) to validate the authentication the results and get user information.Jetpack tries to use
user_tokenfor that request, but at that point the user is not authenticated in WP, souser_idequals0, thusblog_tokenis used for authorization anyway.That makes the commit janitorial with no functional changes.
Jetpack product discussion
Part of the issue #16709.
Related to #16830.
Does this pull request change what data or activity we track or use?
No.
Testing instructions:
Proposed changelog entry for your changes:
n/a.