From a8f7e4639b79718b06b958bb3c06c82e97bfe31b Mon Sep 17 00:00:00 2001 From: Bryce Kwon Date: Thu, 1 Oct 2026 20:13:25 -1000 Subject: Mark a page behind an auth filter private Only the login page carried a Cache-Control, so a page an auth filter had let a visitor see could be kept by a cache shared with the next visitor. The page also varies on the cookie that got them in. --- custom/servers/apache.conf | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) (limited to 'custom/servers/apache.conf') diff --git a/custom/servers/apache.conf b/custom/servers/apache.conf index f25c444..d95d76f 100644 --- a/custom/servers/apache.conf +++ b/custom/servers/apache.conf @@ -204,11 +204,11 @@ AddType text/plain .txt # Site-wide security headers are set here so they also cover the static # assets Apache serves. cgit itself sends only the headers the proxy # cannot supply. Those are Status, Content-Type, Content-Length and - # Content-Disposition on downloads, Location on redirects, a no-store - # Cache-Control on unauthenticated responses, the auth filter's Set-Cookie, - # and on raw repository bytes a nosniff of its own next to the stricter - # policy "default-src 'none'". Everything else, this policy included, is - # the proxy's job. + # Content-Disposition on downloads, Location on redirects, a Cache-Control + # marking the login page no-store and a page behind an auth filter private, + # the auth filter's Set-Cookie, and on raw repository bytes a nosniff of + # its own next to the stricter policy "default-src 'none'". Everything + # else, this policy included, is the proxy's job. # # The word setifempty is load bearing on the two headers cgit can also # emit. "Header always set" replaces a same-named header even when the -- cgit v2.8.0