diff options
context:
space:
mode:
authorBryce Kwon <bryce@brycekwon.com>
committerBryce Kwon <bryce@brycekwon.com>
commit
parent
tree
download
Drop the Last-Modified, Expires and ETag headers
Diffstat (limited to 'custom')
-rw-r--r--custom/servers/apache.conf6
-rw-r--r--custom/servers/nginx.conf6
2 files changed, 11 insertions, 1 deletion
diff --git a/custom/servers/apache.conf b/custom/servers/apache.conf
index 7ff3bab..4345a9e 100644
--- a/custom/servers/apache.conf
+++ b/custom/servers/apache.conf
@@ -135,7 +135,11 @@ AddType text/plain .txt
AllowOverride None
Require all granted
- # These assets rarely change, so let browsers cache them.
+ # These assets rarely change, so let browsers cache them. Keep the
+ # caching scoped to this directory. cgit sends no caching headers of its
+ # own, so a server-wide ExpiresDefault would stamp freshness onto its
+ # pages, fight the no-store cgit puts on the login page, and could let
+ # one visitor's page be served to another from a shared cache.
<IfModule mod_expires.c>
ExpiresActive On
ExpiresDefault "access plus 30 days"
diff --git a/custom/servers/nginx.conf b/custom/servers/nginx.conf
index 3b0b7ef..12d6888 100644
--- a/custom/servers/nginx.conf
+++ b/custom/servers/nginx.conf
@@ -234,6 +234,12 @@ http {
# can take a while, so give cgit room and stream rather than buffer.
fastcgi_read_timeout 300s;
fastcgi_buffering off;
+
+ # cgit sends no caching headers of its own, so browsers refetch
+ # dynamic pages and cgit's internal cache keeps that cheap. Do not
+ # add a blanket expires or Cache-Control in this location. It
+ # would fight the no-store cgit puts on the login page and could
+ # let one visitor's page be served to another from a shared cache.
}
}
}