Transform POST param into GET param when redirecting to login page can cause security issues. Now, instead of displaying textarea (even if public user) and the redirect to login page keeping written comment, we display the login button with a redirection to the page to comment.
The redirection happen before commenting, avoiding to remenber param such comment text, rating, ...
To post a comment, the user must:
- be connected
- have a token
- or have a sha_sign