Prevent profile form submission when required fields are empty - #11511
Prevent profile form submission when required fields are empty#11511vijendrajat wants to merge 3 commits into
Conversation
On the user profile screen, required fields (Email and Nickname) are validated server-side. If a user spends time filling out many fields but leaves a required field empty and submits, WordPress returns a server-side error and all unsaved field values are lost. This fix adds client-side validation to the profile form using the existing validateForm() function already available in common.js. The form-required class is added to the Nickname and Email rows in user-edit.php, and a submit event handler is added to #your-profile in user-profile.js that calls window.validateForm() to block submission and highlight the empty fields. Server-side validation is unchanged and remains the security boundary. Only the #your-profile update form is targeted, matching the server-side behavior where Nickname is only required on update.
|
The following accounts have interacted with this PR and/or linked issues. I will continue to update these lists as activity occurs. You can also manually ask me to refresh this list by adding the Unlinked AccountsThe following contributors have not linked their GitHub and WordPress.org accounts: @softglazee. Contributors, please read how to link your accounts to ensure your work is properly credited in WordPress releases. Core Committers: Use this line as a base for the props when committing in SVN: To understand the WordPress project's expectations around crediting contributors, please review the Contributor Attribution page in the Core Handbook. |
Test using WordPress PlaygroundThe changes in this pull request can previewed and tested using a WordPress Playground instance. WordPress Playground is an experimental project that creates a full WordPress instance entirely within the browser. Some things to be aware of
For more details about these limitations and more, check out the Limitations page in the WordPress Playground documentation. |
|
Tested locally on Windows (Docker, Chrome, 7.1-alpha trunk) after a clean npm ci + npm run build:dev — the fix works as intended: submission with empty Nickname/Email is blocked client-side, both fields get the error highlight, and unsaved values in other fields are preserved. Valid data saves normally in a single click. One minor issue: each blocked submit activates the spinner next to the Update Profile button and it's never reset, so spinners accumulate on repeated attempts (screenshot attached). Since the button is at the bottom and the highlighted fields are at the top, there's no feedback near the button about why nothing happened. Suggest resetting the spinner in the handler when validation fails, and possibly moving focus/scrolling to the first invalid field. Full test notes on the Trac ticket: https://core.trac.wordpress.org/ticket/41314#comment:17
|


On the user profile screen, required fields (Email and Nickname) are validated server-side. If a user spends time filling out many fields but leaves a required field empty and submits, WordPress returns a server-side error and all unsaved field values are lost.
This fix adds client-side validation to the profile form using the existing validateForm() function already available in common.js. The form-required class is added to the Nickname and Email rows in user-edit.php, and a submit event handler is added to #your-profile in user-profile.js that calls window.validateForm() to block submission and highlight the empty fields. Server-side validation is unchanged and remains the security boundary. Only the #your-profile update form is targeted, matching the server-side behavior where Nickname is only required on update.
Trac ticket: https://core.trac.wordpress.org/ticket/41314
Use of AI Tools
This Pull Request is for code review only. Please keep all other discussion in the Trac ticket. Do not merge this Pull Request. See GitHub Pull Requests for Code Review in the Core Handbook for more details.