Cloudflare Was Caching an API Response for Logged-in Users
What happened?
Users were seeing outdated account information even after successfully updating their profile.
The update request returned a successful response, and the database contained the new information. However, refreshing the page sometimes showed the old data.
It only happened in production. Everything worked correctly on the local environment.
Environment
Error Message
There was no error message.
The API returned a 200 OK response, but the response body contained stale user data.
What was actually wrong?
Cloudflare was caching the API response.
The API endpoint was returning user-specific data, but it didn't have the appropriate cache-control headers. Cloudflare treated the response as cacheable and served an older response to subsequent requests.
The Fix
I added cache-control headers to prevent private API responses from being cached:
return response()->json($data) ->header('Cache-Control', 'private, no-store, no-cache, must-revalidate');
I also purged the existing Cloudflare cache.
After that, profile updates appeared immediately for the correct user.
What I Learned
Never assume an API response is safe to cache just because the endpoint returns 200 OK.
If an endpoint contains user-specific or sensitive data, explicitly define its caching behavior.
Comments (0)
Please log in to leave a comment.
No comments yet. Be the first to share your thoughts!