From 6ead07550059c14306f2c74c564b23793f033bb8 Mon Sep 17 00:00:00 2001 From: Bryce Kwon Date: Fri, 14 Aug 2026 13:06:45 -1000 Subject: Drop the Last-Modified, Expires and ETag headers --- custom/servers/apache.conf | 6 +++++- custom/servers/nginx.conf | 6 ++++++ 2 files changed, 11 insertions(+), 1 deletion(-) (limited to 'custom/servers') diff --git a/custom/servers/apache.conf b/custom/servers/apache.conf index 7ff3bab..4345a9e 100644 --- a/custom/servers/apache.conf +++ b/custom/servers/apache.conf @@ -135,7 +135,11 @@ AddType text/plain .txt AllowOverride None Require all granted - # These assets rarely change, so let browsers cache them. + # These assets rarely change, so let browsers cache them. Keep the + # caching scoped to this directory. cgit sends no caching headers of its + # own, so a server-wide ExpiresDefault would stamp freshness onto its + # pages, fight the no-store cgit puts on the login page, and could let + # one visitor's page be served to another from a shared cache. ExpiresActive On ExpiresDefault "access plus 30 days" diff --git a/custom/servers/nginx.conf b/custom/servers/nginx.conf index 3b0b7ef..12d6888 100644 --- a/custom/servers/nginx.conf +++ b/custom/servers/nginx.conf @@ -234,6 +234,12 @@ http { # can take a while, so give cgit room and stream rather than buffer. fastcgi_read_timeout 300s; fastcgi_buffering off; + + # cgit sends no caching headers of its own, so browsers refetch + # dynamic pages and cgit's internal cache keeps that cheap. Do not + # add a blanket expires or Cache-Control in this location. It + # would fight the no-store cgit puts on the login page and could + # let one visitor's page be served to another from a shared cache. } } } -- cgit v2.8.0