Error with CDN since last version
-
We have identified a reproducible issue with EventPrime 4.3.4.8 when the frontend calendar page is served through full-page CDN caching.
The calendar works correctly for logged-in users, but fails for logged-out/guest visitors.
The failing AJAX request is:
action: ep_get_calendar_event
The request includes a security nonce, for example:
security: 14840fe884
For affected guest users, the AJAX response is:
{
“success”: false,
“data”: {
“message”: “Security check failed. Please refresh the page and try again later.”
}
}The frontend JavaScript then generates a secondary error:
Uncaught TypeError: data.data.map is not a function
at ep-frontend-events.js?ver=4.3.4.8We confirmed the root cause is full-page caching through BunnyCDN.
If the EventPrime/calendar page is excluded from BunnyCDN caching, the issue immediately disappears.
It appears EventPrime is generating the AJAX nonce/security token in the frontend HTML. That HTML is then cached and served to anonymous visitors after the nonce is no longer valid. Logged-in users are unaffected because they bypass the guest page cache and receive a fresh nonce.
There appear to be two issues:
- The EventPrime AJAX nonce is not compatible with long-lived full-page caching for anonymous visitors.
- The frontend JavaScript assumes
data.datais always an array and calls.map()even when the server returns an error object.
Ideally EventPrime should support frontend page caching without requiring the entire calendar page to be excluded from CDN/page caching.
Possible approaches would be to obtain/refresh the nonce dynamically, use an AJAX/REST design that does not rely on a nonce embedded in cached HTML for a public read-only request, or otherwise make the frontend request cache-safe.
The JavaScript should also check
successand verifyArray.isArray(data.data)before calling.map(), so a nonce failure produces a meaningful error instead of a TypeError.Please let me know if you need additional request/response data or testing.
You must be logged in to reply to this topic.