Skip to content

block(news): API requests need to include a header to avoid bot protection challenges #137

Description

@knice

CampusPress site pages with the News Block are seeing intermittent failures and inconsistent behavior in the block editor. We attempted to fix this (issue #135 and PR #136), but testing those fixes on CampusPress servers is still showing errors.

We asked CampusPress to ensure that their servers are not rate-limiting outbound requests from their sites. Instead, they indicated that requests from their servers to news.ucsc.edu are failing.

HTTP/2 429
date: Thu, 17 Sep 2026 19:55:17 GMT
content-type: text/html
content-length: 805
accept-ch: Sec-CH-UA-Bitness, Sec-CH-UA-Arch, Sec-CH-UA-Full-Version, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Platform, Sec-CH-UA, UA-Bitness, UA-Arch, UA-Full-Version, UA-Mobile, UA-Model, UA-Platform-Version, UA-Platform, UA
cf-mitigated: challenge
x-frame-options: SAMEORIGIN
server: cloudflare

As indicated by the cf-mitigated: challenge in the response, Cloudflare is presenting this request with a bot challenge, which an API request from a block cannot complete. The result is a failed request, and the news block does not work.

If this hypothesis is correct, we may need to implement a bot bypass token in this plugin so the news block doesn't face Cloudflare challenges. That would require updating the token in an environment variable every 6 months.

For the time being, we will explore other options, namely, making certain CampusPress servers are sending appropriate headers in their requests to avoid appearing like bots to CloudFlare.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

securitySecurity hardening

Type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions