3 ms·
Apparently it's a caching bug - if you add some random query parameters like ?r=123456789 to the url you get the correct page.
by Santzes 11y ago
Apparently it's a caching bug - if you add some random query parameters like ?r=123456789 to the url you get the correct page.
- benwilber0 11y agoyeah pretty obvious caching bug. im sure they accidentally told their cache to ignore cookies or something stupid.
- geofft 11y agoAmazon CloudFront all but encourages you to ignore cookies and query strings in caching. This is exactly what you want in some cases, like images or CSS, but it seems like a very dangerous option, and there's no scary text around the option.
- ChipWolf 11y agoValve would have to entirely rewrite their current caching system in order to repair this which they've avoided for so long.
- bottled_poe 11y agoEw, cookies? I thought those days were behind us..
- gizmo385 11y agoAs someone who really doesn't do that much web programming, what is the modern way to handle the kinds of information that cookies are/were used for?
- bottled_poe 11y agoSession variables are awful, which is the main selling point for cookies. I prefer basic auth with server-side user settings. This is how I implement stateless web apps and services, which greatly simplifies application architecture and makes it easy to implement automated atomic web testing.
- tom9729 11y agoIt's unfortunate that people are down-voting instead of responding to you. I'm far from an expert but it would be interesting to see what other people think here... Basic auth is insecure (i.e. sending credentials in plaintext) and poorly supported by browsers. For example how would you handle these scenarios: - Force users to reauthenticate after a certain period of time. - Allow user to logout without closing their browser. I think Basic auth is more reasonable for server-server communications, combined with HTTPS and client-certs. The best setup IMO is to have an HTTPS login page (form auth, hopefully with MFA) and use a session cookie. You can do server-side settings with this setup, you minimize the time when credentials are being sent (basically just once on login), and you can force your users to occasionally reauthenticate (either session timeout or manual logout) just in case they forgot to logout of a public computer. For testing you could allow basic auth (make it configurable, or use user-agent sniffing to force browsers to use form auth). Edit: formatting
- bottled_poe 11y ago> Basic auth is insecure When used over HTTPS it is about as secure as any other web auth method. > Force users to reauthenticate after a certain period of time. With basic auth, there is no session. Authentication credentials are sent with each request. > Allow user to logout without closing their browser. There is no session. Only authenticated requests. It's not for everyone, but I find that stateless APIs are much easier to work with.
- chei0aiV 11y agoBest practice authentication is client-side SSL certificates.
- cheald 11y agoCookies.
- blibble 11y agoI'd put my money on someone bringing up some new varnish servers to handle the xmas day load with default config... or the backend service, and not setting the Vary header correctly