httpd-bugs mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From bugzi...@apache.org
Subject [Bug 55896] Secure page can be cached in browser. Cache control is not set in HTTP header nor HTML header.
Date Tue, 17 Dec 2013 14:16:20 GMT
https://issues.apache.org/bugzilla/show_bug.cgi?id=55896

Eric Covener <covener@gmail.com> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
             Status|NEW                         |NEEDINFO
                 OS|                            |All

--- Comment #1 from Eric Covener <covener@gmail.com> ---
Does it happen on a contemporary maintenance level?

 A response received with any other status code (e.g. status codes 302 and 307)
MUST NOT be returned in a reply to a subsequent request unless there are
cache-control directives or another header(s) that explicitly allow it. For
example, these include the following: an Expires header (section 14.21); a
"max-age", "s-maxage", "must- revalidate", "proxy-revalidate", "public" or
"private" cache-control directive (section 14.9).

-- 
You are receiving this mail because:
You are the assignee for the bug.

---------------------------------------------------------------------
To unsubscribe, e-mail: bugs-unsubscribe@httpd.apache.org
For additional commands, e-mail: bugs-help@httpd.apache.org


Mime
View raw message