Open
Description
without private
(in addition to no-cache
in the Cache-Control header for GET requests, server-side caches are allowed to cache responses, creating a large security hole. That is, a server-side cache would happily serve RS content to anyone on the internet, without the authentication of the RS server.
The HTTP spec says HEAD requests MUST send the same headers as GET requests, the spec should probably include HEAD requests in that sentence.
Metadata
Assignees
Labels
No labels