diff options
context:
space:
mode:
authorBryce Kwon <bryce@brycekwon.com>
committerBryce Kwon <bryce@brycekwon.com>
commit
parent
tree
download
Mark a page behind an auth filter private
Only the login page carried a Cache-Control, so a page an auth filter had let a visitor see could be kept by a cache shared with the next visitor. The page also varies on the cookie that got them in.
Diffstat (limited to '')
-rw-r--r--source/ui-shared.c5
1 file changed, 5 insertions, 0 deletions
diff --git a/source/ui-shared.c b/source/ui-shared.c
index a112fb2..2c4db2c 100644
--- a/source/ui-shared.c
+++ b/source/ui-shared.c
@@ -1465,8 +1465,13 @@ void cgit_print_http_headers(void)
html("X-Content-Type-Options: nosniff\n");
html("Content-Security-Policy: default-src 'none'\n");
}
+ // A page behind an auth filter is for the visitor who was let in, so a
+ // cache shared with other visitors must not keep it, and it varies on
+ // the cookie that got them in.
if (!ctx.env.authenticated)
html("Cache-Control: no-cache, no-store\n");
+ else if (ctx.cfg.auth_filter)
+ html("Cache-Control: private\nVary: Cookie\n");
html("\n");
// Some pages follow the headers with output written by git itself, not
// through html_raw, so the buffer is emptied to keep the headers first.