# WordPress DiscourseConnect client - expired nonce

**URL:** <https://meta.discourse.org/t/wordpress-discourseconnect-client-expired-nonce/285374>\
**Category:** WordPress\
**Created:** [November 13, 2023, 7:09pm UTC](https://meta.discourse.org/t/wordpress-discourseconnect-client-expired-nonce/285374 "2023-11-13T19:09:59Z")\
**Posts on this page:** 1\
**Showing post:** 14

<div class="post-metadata">

**Author:** ![simon](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/simon/32/339122_2.png) [@simon](https://meta.discourse.org/u/simon)\
**Post date:** [December 11, 2023, 10:02am UTC](https://meta.discourse.org/t/wordpress-discourseconnect-client-expired-nonce/285374/14 "2023-12-11T10:02:14Z")

</div>

> [@Petr\_Mišák](#):
>
> I checked the status of our Nginx Microcache at [Přihlásit se ‹ Svět Androida — WordPress](https://www.svetandroida.cz/wp-login.php), but it seems that Nginx Microcache is not used there at all.

I’m fairly sure the issue with logging into [https://www.svetandroida.cz/](https://www.svetandroida.cz/) through Discourse is related to the nonce being cached. The way I tested this was by clicking the “Log in with Discourse” link ([https://www.svetandroida.cz/?discourse\_sso=1&redirect\_to=https%3A%2F%2Fwww.svetandroida.cz%2F](https://www.svetandroida.cz/?discourse_sso=1&redirect_to=https%3A%2F%2Fwww.svetandroida.cz%2F)).

The first time I did that I was redirected to [https://komunita.svetandroida.cz/](https://komunita.svetandroida.cz/), created an account on the Discourse site with Gmail, then redirected back to your WordPress site as a logged in user.

I then logged out of your WordPress site and tried logging back in by clicking the “Login with Discourse” link again. This time I got the “expired nonce” error.

I then generated a login link with a random value for the `discourse_sso` URL parameter, for example [https://www.svetandroida.cz/?discourse\_sso=181253058&redirect\_to=https%3A%2F%2Fwww.svetandroida.cz%2F](https://www.svetandroida.cz/?discourse_sso=181253058&redirect_to=https%3A%2F%2Fwww.svetandroida.cz%2F) and was able to login to your WordPress site through Discourse without any issues.

I’ve tried this a few times, both with the login link that’s generated by the plugin (`https://www.svetandroida.cz/?discourse_sso=1&redirect_to=https%3A%2F%2Fwww.svetandroida.cz%2F`) and with login links that have a random value set for the `discourse_sso` parameter. It seems that the nonce that’s being returned is being cached for at least a few minutes.

Without fully debugging the issue, I’m fairly sure you can get things to work just by adding the following to your theme’s `functions.php` file (it will set a random string to the `discourse_sso` URL parameter. This should work as long as there isn’t also “page caching” enabled on your login page.)

```php
add_filter('wpdc_sso_client_query', 'wpdc_custom_sso_client_query' );
function wpdc_custom_sso_client_query() {
    return wp_generate_password( 12, false );
}

```

If you do want to debug the issue, here’s what I’m seeing for a successful request. Note the `Cache-Svetzitrka: STALE` line. This might indicate that there’s a custom caching layer in place and that the cache was `STALE` for the successful request (so a fresh nonce was generated.)

> **Summary**
>
> ```plaintext
> Request URL:
> https://www.svetandroida.cz/?discourse_sso=1&redirect_to=https%3A%2F%2Fwww.svetandroida.cz%2F
> Request Method:
> GET
> Status Code:
> 302 Found
> Remote Address:
> 93.185.102.156:443
> Referrer Policy:
> strict-origin-when-cross-origin
> Cache-Control:
> max-age=0
> Cache-Svetzitrka:
> STALE
> Content-Length:
> 0
> Content-Type:
> text/html; charset=UTF-8
> Date:
> Mon, 11 Dec 2023 09:38:05 GMT
> Expires:
> Mon, 11 Dec 2023 09:21:47 GMT
> Location:
> https://komunita.svetandroida.cz/session/sso_provider?sso=bm9uY2U9MGU3NTNjYWNhNjMwNmMzNzM5M2MyODk4MjZlYzMxMjQmcmV0dXJuX3Nzb191cmw9aHR0cHMlM0ElMkYlMkZ3d3cuc3ZldGFuZHJvaWRhLmN6JTJG&sig=32ddcc85bd2dd7175f963e791cc9ac734a607355d773422d3abec6173c9f656b
> Server:
> nginx
> Strict-Transport-Security:
> max-age=10886400; includeSubdomains; preload
> X-Content-Type-Options:
> nosniff
> X-Frame-Options:
> SAMEORIGIN
> X-Redirect-By:
> WordPress
> 
> ```

Here’s what I’m seeing for a failed request. The `Cache-Control: no-cache, no-store` line seems to indicate that the response _shouldn’t_ be cached, but the `from service worker` entry in the response indicates that the response could be coming from a service worker’s cache.

> **Summary**
>
> ```plaintext
> Request URL:
> https://www.svetandroida.cz/?discourse_sso=1&redirect_to=https%3A%2F%2Fwww.svetandroida.cz%2F
> Request Method:
> GET
> Status Code:
> 302 Found (from service worker)
> Referrer Policy:
> strict-origin-when-cross-origin
> Cache-Control:
> no-cache, no-store
> Content-Security-Policy:
> upgrade-insecure-requests; base-uri 'self'; object-src 'none'; script-src https://komunita.svetandroida.cz/logs/ https://komunita.svetandroida.cz/sidekiq/ https://komunita.svetandroida.cz/mini-profiler-resources/ https://komunita.svetandroida.cz/assets/ https://komunita.svetandroida.cz/extra-locales/ https://komunita.svetandroida.cz/highlight-js/ https://komunita.svetandroida.cz/javascripts/ https://komunita.svetandroida.cz/plugins/ https://komunita.svetandroida.cz/theme-javascripts/ https://komunita.svetandroida.cz/svg-sprite/ https://www.google-analytics.com/analytics.js https://www.googletagmanager.com/gtag/js 'sha256-8uAKDaK4QxxCeYZl0Wxad2Nnj2tgKyA14hYBh66pnn0='; worker-src 'self' https://komunita.svetandroida.cz/assets/ https://komunita.svetandroida.cz/javascripts/ https://komunita.svetandroida.cz/plugins/; frame-ancestors 'self'; manifest-src 'self'
> Content-Type:
> text/html; charset=utf-8
> Date:
> Mon, 11 Dec 2023 09:38:05 GMT
> Discourse-Logged-Out:
> 1
> Location:
> https://komunita.svetandroida.cz/login
> Referrer-Policy:
> strict-origin-when-cross-origin
> Server:
> nginx
> Set-Cookie:
> sso_payload=sso%3Dbm9uY2U9MGU3NTNjYWNhNjMwNmMzNzM5M2MyODk4MjZlYzMxMjQmcmV0dXJuX3Nzb191cmw9aHR0cHMlM0ElMkYlMkZ3d3cuc3ZldGFuZHJvaWRhLmN6JTJG%26sig%3D32ddcc85bd2dd7175f963e791cc9ac734a607355d773422d3abec6173c9f656b; path=/; SameSite=Lax
> Set-Cookie:
> _forum_session=kGW2K6gafsjS90qQMEmxzjggEYo4tZPZe76XZNVro34ilyuuHsaYt2nEzC9h6tfiSBmY9XoDdxh1SV3S8n%2BwqrbsD58UvJBz6khjm%2Fty83ufkgry8daHDdyoTfFwQOjAbXrWeGIwkS4edGY1XetNwXhu%2FNJUghqmq8BEUycBt7098KUO%2BmRYDl5iSL0FNhUzo5Hc7xwRg0tfxuxmb%2FIyVLnbFz6IJuGB3Y95PRcU5DYIwAAny1GQbKQ23kSjgALxAThG7aA%2B7LCI9cJNWV1JRSy%2FTElDN3iugKuVpaQcrSPhV3SvQaiNH3MCfLwu6yxlp%2BZ%2BwTyw22czX8bb197z36WhlbghYtxvKYGRjONJQUagisjPpMrCAcGeTKsGB4JgnUKCtlrwIoFvaDxjec7hMo3aCnibbbkmcxWc6LvD6G2xaxkDgebe7RpvfTYdG8cn8j6rNwX3hM8la4RqZnmma0%2FQlSrfj0BjfY7lnan6TYm28vLwH%2FFfdZoRbo6JdTs5AFjCJvx9UXSjFmoXHH1R1yfAizPeKDFnpiuUs4a%2FBzWafQ%3D%3D--8PEvbWwpqBuJMSRJ--CzzhBea4mmv58a7KLEnukw%3D%3D; path=/; secure; HttpOnly; SameSite=Lax
> Set-Cookie:
> _t=; path=/; max-age=0; expires=Thu, 01 Jan 1970 00:00:00 GMT; SameSite=Lax
> Strict-Transport-Security:
> max-age=31536000
> Vary:
> Accept
> X-Content-Type-Options:
> nosniff
> X-Discourse-Route:
> session/sso_provider
> X-Download-Options:
> noopen
> X-Frame-Options:
> SAMEORIGIN
> X-Permitted-Cross-Domain-Policies:
> none
> X-Request-Id:
> 001750b9-94f2-4bf0-8503-9d673463b91e
> X-Runtime:
> 0.012335
> X-Xss-Protection:
> 0
> 
> ```

---

_[View the full topic](https://meta.discourse.org/t/wordpress-discourseconnect-client-expired-nonce/285374)._
