You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
fix(cache): percent-encode | and % in cache-key host and path
The default key builder joined the raw Host header and decoded path with
|||, so a Host of 'example.com|||/p' on GET /x stored the response under
the key of GET /p%7C%7C%7C/x. Encode | and % in both components with
escape_key_component; clear_path encodes its argument the same way and
the monitoring routes decode for display. Recommend TrustedHostMiddleware
in the HTTP caching guide.
Closes#230
- Fails open by default (`fail_open=True`): a backend error on `get` is logged and treated as a miss, one on `set` is logged and the response served unstored. `fail_open=False` propagates the error.
55
55
- Only GET requests are cached; other methods bypass the cache entirely.
56
-
- Cache keys follow the format `method|||host|||path|||query_params` (separator defined in `types.py`).
56
+
- Cache keys follow the format `method|||host|||path|||query_params` (separator defined in `types.py`). Host and path go through `escape_key_component` (`|` → `%7C`, `%` → `%25`) so client input cannot inject the separator; `clear_path` encodes its argument and `routes.py` decodes for display.
57
57
-`BackendProxy` is a non-instantiable class-level singleton (via `ProxyMeta`). Call `BackendProxy.set(backend)` at app startup; `BackendProxy.get()` raises `BackendNotFoundError` if unset. Falls back to `MemoryBackend` automatically inside `@cache` if no backend is set.
58
58
- Cache values are stored as `CacheEntry(fingerprint, content, media_type)` dataclass (defined in `types.py`).
0 commit comments