View Issue Details

IDProjectCategoryView StatusLast Update
0019932mantisbtperformancepublic2016-06-05 19:24
Reportervboctor Assigned Tovboctor  
PrioritynormalSeverityminorReproducibilityhave not tried
Status closedResolutionfixed 
Target Version1.3.0-beta.3Fixed in Version1.3.0-beta.3 
Summary0019932: Load jquery from CDN

We should support loading jQuery from CDN by default and provide a configuration option to revert to local version.

See sources at:

This should at least improve first load performance.

TagsNo tags attached.


related to 0013285 closedsyncguru Move script inclusions from HEAD to document footer 




2015-07-14 13:02

developer   ~0051067

Last edited: 2015-08-16 06:05

View 2 revisions


  • performance, especially in a scenario like MantisHub
  • performance in intranet scenario (latency)
  • decreased availability, a fallback should be implemented [1]
  • decreased security

Side notes

  • Don't forget to add the CDN to our CSP header
  • Always use HTTPS to access the CDN

I prefer to have the default setting for CDN usage to OFF.
Setting it to ON will break some existing installations when upgrading.
Setting it to ON will not work for all scenarios of new installations.




2015-08-02 18:05

developer   ~0051181

This sounds like a good idea, but I'm also tempted to say that the default setting should be OFF.

We also need to decide which CDN(s?) we want to use/propose.

Finally, this needs to be carefully integrated and tested with CSP.

Thanks Roland for the research, particularly that interesting article on fallback which is something I definitely think we should do.



2015-08-15 02:14

manager   ~0051259




2015-08-16 14:14

developer   ~0051270

Few years ago, I would have thought OFF is a good choice .. but not anymore.

1- CDNs are very common now due to perf improvement - Popular page speed tools (i.e. YSlow, Google page speed ..etc) strongly recommend using CDNs for few years now. Amazon CloudFront is commonly used to implement very cheap CDNs
2- Public CDNs for popular libraries are not that many - we are talking about Google, Microsoft & MaxCDN (for bootstrap)
3- Practically speaking, we can only use CDNs for JQuery, JQueryUI & Bootstrap - that's it
4- The cons mentioned above serve very special cases while sacrificing the benefits for the most cases. I would argue that 99% will be affected negatively to the benefit of only 1% - If you have better metrics, please share.
5- Environments with no internet access are aware of their limitations ... they are prepared to make config changes.
6- I would challenge 'decreased security' argument.



2015-08-17 03:29

developer   ~0051278

99% will be affected negatively to the benefit of only 1% - If you have better metrics, please share.

82.7% of statistics are made up on the spot ? ;-)

Considering that we have virtually no data on MantisBT usage in the real world, I could challenge where you got your figures from, but I don't think this is worth discussing.

My point for default = OFF is that not using CDN and downloading from MantisBT server is guaranteed to work in every single scenario (even though it may cause degraded performance compared to CDN), whereas using a CDN may not.



2015-08-17 03:42

developer   ~0051279

We might start endless discussions if we want to consider all possible pros/cons, e.g.

I think there is just one solution that would work for all:
Let the user decide when installing/upgrading the system and write the result to config_inc.php.
Default should be OFF, as we should not introduce regressions and we should not introduce access to other servers behind our users back.



2015-08-17 11:37

manager   ~0051282

I've merged the change with default OFF for now. If we agree later to turn it ON, then we can do a follow up checkin. We can also decide to start OFF in 1.3 and turn ON in 2.0.

Feel free to continue the discussion.



2015-08-17 16:22

developer   ~0051287

I am not sure if cdn_enabled should be in list $g_global_settings.
AFAIK we don't have a clear rule for it.



2015-08-18 23:33

manager   ~0051291

Relating to ability to have database overrides, I use the following logic:

Let's assume we have two roles:

  • Sysadmin/Hoster - e.g. MantisHub hosting for users or a sysadmin hosting MantisBT for a team. The sysadmin/hoster have access to the php files, web server, etc. But may not event have a login to MantisBT itself.
  • Administrator This is the MantisBT administrator with full access to do everything within the web app, but not able to change the php scripts, the php config scripts, etc.

In this case, I expect CDN to be an option for the Sysadmin/hoster and not one for the MantisBT administrator, and hence, I would add it to global settings and use config_get_global to get it. Hence, I would make a follow up change for this.

A bad example that we have today is default_timezone. At the moment, administrators are able to set it, but code looks at the global config, hence, it doesn't really work as expected.

Does this make sense as a way to reason about this?



2015-09-13 10:16

developer   ~0051455

Does this make sense as a way to reason about this?
Makes sense

BTW, I just enabled CDN for

Related Changesets

MantisBT: master 5414ba9a

2015-08-15 02:12:41


Details Diff
Load jquery from CDN

This is to improve performance for the following reasons:

- Browser loads more in parallel due to loading from different servers.
- CDN libraries likely to be already cached as it is referenced by other websites / web apps.
- CDN will deliver lower latencies with the possible exception of intranet.

Fixes 0019932
Affected Issues
mod - config_defaults_inc.php Diff File
mod - core/html_api.php Diff File
mod - core/http_api.php Diff File
mod - docbook/Admin_Guide/en-US/config/html.xml Diff File

MantisBT: master 0a45b7b1

2015-08-15 13:01:28


Details Diff
Use protocol-less urls to reference CDN

Fixes 0019932
Affected Issues
mod - core/html_api.php Diff File
mod - core/http_api.php Diff File

MantisBT: master fc9a3320

2015-08-15 13:05:43


Details Diff
Use constants for jQuery and jQueryUI versions

Fixes 0019932
Affected Issues
mod - core/constant_inc.php Diff File
mod - core/html_api.php Diff File

MantisBT: master 958d28bc

2015-08-19 02:43:35


Details Diff
Revert "Use protocol-less urls to reference CDN"

Protocol-less urls were causing the CSP to fail.

This reverts commit 0a45b7b1b375fdc088cdbbc9908928755362c756.

# Conflicts:
# core/html_api.php
Affected Issues
mod - core/html_api.php Diff File
mod - core/http_api.php Diff File

MantisBT: master aa9b4f8a

2015-08-19 03:44:04


Details Diff
Mark cdn_enabled as global setting

Issue 0019932
Affected Issues
mod - config_defaults_inc.php Diff File
mod - core/html_api.php Diff File
mod - core/http_api.php Diff File

MantisBT: master e753cca6

2016-05-23 15:54:11


Details Diff
Use JQUERY_VERSION constant in install.php

Commit fc9a3320815f8341236cb7bf0c41855227a3c8c3 missed one occurence of
jQuery version number.

Issue 0019932
Affected Issues
0019932, 0021059
mod - admin/install.php Diff File

Issue History

Date Modified Username Field Change
2015-07-14 09:46 vboctor New Issue
2015-07-14 09:46 vboctor Status new => assigned
2015-07-14 09:46 vboctor Assigned To => vboctor
2015-07-14 10:12 vboctor Relationship added related to 0013285
2015-07-14 10:12 vboctor Category javascript => performance
2015-07-14 13:02 atrol Note Added: 0051067
2015-08-02 18:05 dregad Note Added: 0051181
2015-08-15 02:14 vboctor Note Added: 0051259
2015-08-16 06:05 atrol Note Edited: 0051067 View Revisions
2015-08-16 14:14 syncguru Note Added: 0051270
2015-08-17 03:29 dregad Note Added: 0051278
2015-08-17 03:42 atrol Note Added: 0051279
2015-08-17 11:36 vboctor Changeset attached => MantisBT master 5414ba9a
2015-08-17 11:36 vboctor Changeset attached => MantisBT master 0a45b7b1
2015-08-17 11:36 vboctor Changeset attached => MantisBT master fc9a3320
2015-08-17 11:36 vboctor Status assigned => resolved
2015-08-17 11:36 vboctor Resolution open => fixed
2015-08-17 11:36 vboctor Fixed in Version => 1.3.0-beta.3
2015-08-17 11:37 vboctor Note Added: 0051282
2015-08-17 12:06 vboctor Target Version => 1.3.0-beta.3
2015-08-17 16:22 atrol Note Added: 0051287
2015-08-18 23:33 vboctor Note Added: 0051291
2015-08-19 03:02 dregad Changeset attached => MantisBT master 958d28bc
2015-08-19 11:08 vboctor Changeset attached => MantisBT master aa9b4f8a
2015-09-06 17:37 vboctoradmin Status resolved => closed
2015-09-13 10:16 atrol Note Added: 0051455
2016-06-05 19:24 dregad Changeset attached => MantisBT master e753cca6