Skip to content

fix(cache): send private to credentialed requests on routes without a positive ttl - #371

Merged
allen0099 merged 1 commit into
masterfrom
fix/362-private-on-bypass
Sep 29, 2026
Merged

allen0099 merged 1 commit into
masterfrom
fix/362-private-on-bypass

Conversation

@allen0099

Copy link
Copy Markdown
Owner

Fixes #362.

A route with ttl=0 or no ttl skips the backend, and the credential check was skipped together with it. Its response to an Authorization or session request therefore kept the decorator's plain Cache-Control. @cache(ttl=0, must_revalidate=True) sent max-age=0, must-revalidate, which RFC 9111 §3.5 lets a shared cache store and reuse for other users after revalidation.

Change

  • The credential check now runs unless the route is private=True (which already sends private), public=True or cache_authorized=True. A credentialed response on a non-positive-ttl route gets the same private header as on any other route, for 200 and 304: private, max-age=0, must-revalidate, private for a plain @cache(), and private, no-cache with no_cache.
  • The once-per-route bypass WARNING is only logged on routes that read the backend. It is about lost cache hits, which these routes never had. Each bypass is still logged at DEBUG.
  • Requests without credentials, and public/cache_authorized/private routes, are unchanged.

Tests

tests/test_cache_bypass_private.py covers:

  • Authorization on the ttl/no-ttl/no_cache variants;
  • the 304;
  • a Starlette session;
  • the unchanged cases;
  • no warning and no backend writes.

On master, 7 of its 12 tests fail. Removing the new warning guard fails only test_backend_stays_untouched_and_nothing_warns.

Docs: the cache_authorized docstring, HTTP_CACHING and CACHE_FLOW (English and zh-TW) no longer say these routes skip the credential check. Changelog: changelog.d/362.security.md.

@allen0099 allen0099 added bug Something isn't working http-cache The @cache decorator, cache keys and Cache-Control handling security Security vulnerability or hardening labels Sep 29, 2026
@allen0099
allen0099 merged commit 09570da into master Sep 29, 2026
12 checks passed
@allen0099
allen0099 deleted the fix/362-private-on-bypass branch September 29, 2026 08:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working http-cache The @cache decorator, cache keys and Cache-Control handling security Security vulnerability or hardening

Projects

None yet

Development

Successfully merging this pull request may close these issues.

@cache: an authorized request on a ttl=0/None route gets Cache-Control without private

1 participant