Skip to content

Commit f34a842

Browse files
committed
docs(changelog): add the #296 fragment
1 parent f31d04c commit f34a842

1 file changed

Lines changed: 14 additions & 0 deletions

File tree

‎changelog.d/296.security.md‎

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
**`@cache` no longer stores responses that belong to one caller.** A request
2+
with an `Authorization` header now bypasses the backend like `private=True`
3+
(RFC 9111 §3.5), unless the route is `public=True` or opts in with the new
4+
`cache_authorized=True`, meant for a `key_builder` that includes the verified
5+
caller's identity. A response whose own `Cache-Control` contains `private` or
6+
`no-store`, or that sets a cookie, is served but not stored, and the handler's
7+
`private`/`no-store` header is no longer replaced by the decorator's. A cookie
8+
response and a bypassed `Authorization` response are sent with `private` in
9+
place of `public` (keeping the other directives; `private, no-cache` on
10+
`no_cache` routes), so a CDN or proxy does not store them either;
11+
`must_revalidate=True` does not lift the bypass. Previously all three were
12+
stored and replayed to every caller, so one user's response could reach
13+
another. The per-user example in HTTP_CACHING.md ("Authenticated endpoints")
14+
now passes `cache_authorized=True`.

0 commit comments

Comments
 (0)