• Resolved Tech Dragon

    (@thetechdragon)


    We have identified a reproducible issue with EventPrime 4.3.4.8 when the frontend calendar page is served through full-page CDN caching.

    The calendar works correctly for logged-in users, but fails for logged-out/guest visitors.

    The failing AJAX request is:

    action: ep_get_calendar_event

    The request includes a security nonce, for example:

    security: 14840fe884

    For affected guest users, the AJAX response is:

    {
    “success”: false,
    “data”: {
    “message”: “Security check failed. Please refresh the page and try again later.”
    }
    }

    The frontend JavaScript then generates a secondary error:

    Uncaught TypeError: data.data.map is not a function
    at ep-frontend-events.js?ver=4.3.4.8

    We confirmed the root cause is full-page caching through BunnyCDN.

    If the EventPrime/calendar page is excluded from BunnyCDN caching, the issue immediately disappears.

    It appears EventPrime is generating the AJAX nonce/security token in the frontend HTML. That HTML is then cached and served to anonymous visitors after the nonce is no longer valid. Logged-in users are unaffected because they bypass the guest page cache and receive a fresh nonce.

    There appear to be two issues:

    1. The EventPrime AJAX nonce is not compatible with long-lived full-page caching for anonymous visitors.
    2. The frontend JavaScript assumes data.data is always an array and calls .map() even when the server returns an error object.

    Ideally EventPrime should support frontend page caching without requiring the entire calendar page to be excluded from CDN/page caching.

    Possible approaches would be to obtain/refresh the nonce dynamically, use an AJAX/REST design that does not rely on a nonce embedded in cached HTML for a public read-only request, or otherwise make the frontend request cache-safe.

    The JavaScript should also check success and verify Array.isArray(data.data) before calling .map(), so a nonce failure produces a meaningful error instead of a TypeError.

    Please let me know if you need additional request/response data or testing.

Viewing 3 replies - 1 through 3 (of 3 total)
  • Plugin Support epsupport1

    (@epsupport1)

    Hi @thetechdragon,

    Thank you for reporting this and providing the details.

    We have taken note of the issue, and our team will address it in one of our upcoming releases.

    If you have any further questions or concerns, please feel free to reach out.
    We’re always happy to assist.

    Thread Starter Tech Dragon

    (@thetechdragon)

    More details on the issue:
    The EventPrime calendar has a bug where its AJAX handler doesn’t properly handle a rejected nonce. When that happens, it tries to run .map() on the error response, which causes the TypeError I was seeing.

    Plugin Support epsupport1

    (@epsupport1)

    Hi @thetechdragon,

    Thank you for your response.

    Yes, we took note of this in your initial message and will ensure that this is addressed as well.

Viewing 3 replies - 1 through 3 (of 3 total)

You must be logged in to reply to this topic.