-
Notifications
You must be signed in to change notification settings - Fork 3
Open
Labels
enhancementNew feature or requestNew feature or requestplannedSomething is planned and has been added to the backlogsSomething is planned and has been added to the backlogspriority/highSomething is of high prioritySomething is of high priorityscale/smallThis is a small changeThis is a small change
Milestone
Description
Description
Clients can store and cache request URLs,
this can make tokens in the URL vulnerable to leaking via cache.
Generally caching isn't advised for dynamic API, since obviously nothing can be reall reused.
Solution
So to disable or discourage the client from caching add [...] to the response headers.
Cache-Control: no-store, no-cache, must-revalidate, max-age=0, private, proxy-revalidate
Pragma: no-cache
Expires: 0
Vary: *
Referrer-Policy: no-referrer
Metadata
Metadata
Assignees
Labels
enhancementNew feature or requestNew feature or requestplannedSomething is planned and has been added to the backlogsSomething is planned and has been added to the backlogspriority/highSomething is of high prioritySomething is of high priorityscale/smallThis is a small changeThis is a small change