-
Notifications
You must be signed in to change notification settings - Fork 4
Closed
Labels
choreSomething doesn't envolve new features and instead focuses on the devex and codebaseSomething doesn't envolve new features and instead focuses on the devex and codebasepriority/highSomething is of high prioritySomething is of high priorityscale/smallThis is a small changeThis is a small change
Milestone
Description
Description
Clients can store and cache request URLs,
this can make tokens in the URL vulnerable to leaking via cache.
Generally caching isn't advised for dynamic API, since obviously nothing can be reall reused.
Solution
So to disable or discourage the client from caching add [...] to the response headers.
Cache-Control: no-store, no-cache, must-revalidate, max-age=0, private, proxy-revalidate
Pragma: no-cache
Expires: 0
Vary: *
Referrer-Policy: no-referrer
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
choreSomething doesn't envolve new features and instead focuses on the devex and codebaseSomething doesn't envolve new features and instead focuses on the devex and codebasepriority/highSomething is of high prioritySomething is of high priorityscale/smallThis is a small changeThis is a small change