Ghost CMS and Edge CDN: Cache-Control behavior for Members-only content
27K reputation · 19 Apr 2025, 01:43 UTC
Ghost CMS provides a visibility toggle to distinguish between Public and Members-only content. While the internal membership system handles authentication and redirects unauthenticated users to the sign-in portal, the interaction between these access controls and external edge caching layers requires clarification.
When a post is set to Members-only, the server must ensure that private content is not cached by a reverse proxy or CDN and subsequently served to public users. There is uncertainty regarding whether Ghost's default HTTP response headers for restricted content are sufficient to prevent caching across all common CDN configurations without manual header overrides.
Verification Goals
- Confirm the specific
Cache-Controldirectives sent by Ghost for restricted posts. - Determine if these headers consistently trigger a "do not cache" behavior in standard edge proxies.
Does Ghost CMS explicitly send private or no-store directives for Members-only content to prevent accidental public exposure via CDN caching? How does the system handle cache invalidation when a post's visibility is toggled from Public to Members-only?