• highlyresponsivetech

    (@highlyresponsivetech)


    I am having an issue with several client sites (since the major 2.0 overhaul) where sometimes comments won’t load when scrolling to that section of the post. It works most of the time, but sometimes there is an error. Clearing the cache on the site+Cloudflare always seems to fix the issue, but obviously that’s not something that can be expected to constantly be done on large, heavy traffic sites. I can’t cross check this against any other hosting companies, but all the clients experiencing this are using BigScoots and their tightly integrated Cloudflare caching plugin. They are also all on the Astra theme with Astra Pro plugin, but they have been running this plugin for a long time without any issues until the 2.0 overhaul.

    Based on debugging, it seems like a caching conflict of some kind is causing the issue (since clearig the cache fixes the issue every time) although there are specific rules in Cloudflare to bypass cache there for any /wp-json/ request.

    I did notice that wp_create_nonce( ‘wp_rest’ ) runs whether the user is logged in or out in includes/front/class-assets.php and typically that is something not needed for read-only requests from logged out users. It may be completely appropriate, but it was the only thing I flagged as a possible cause to this weird behavior.

Viewing 1 replies (of 1 total)
  • Plugin Author Joel James

    (@joelcj91)

    Hi @highlyresponsivetech

    Thanks for reporting this, and you were spot on about the nonce.

    That nonce was being added to the page even for logged out visitors. It only
    stays valid for 12 to 24 hours, but your cached pages get served for much
    longer than that. So the nonce expires while the page is still being served,
    and WordPress blocks the request with a 403 before it gets to the plugin.
    The plugin’s endpoint is public and doesn’t need a nonce in the first place.
    That’s why clearing the cache fixed it every time, and why it came back later.

    I’ve fixed it in 2.1.0. Logged out visitors don’t get a nonce anymore, and if
    an old one does show up the request just retries without it.

    One thing to note: WordPress.org now holds new plugin updates for up to 6 hours
    before they show up, so you may not see the update straight away.

    Once you do update, please clear the site cache and Cloudflare one more time.
    The pages sitting in your cache right now still have the old nonce in them, so
    they need to be flushed once to pick up the fix.

    Let me know if it still happens after that and I’ll take another look.

Viewing 1 replies (of 1 total)

You must be logged in to reply to this topic.