3 ms·
If the client sends incorrect Authorization you will still serve from the cache. This is insecure.
by krishnasrinivas 10y ago
If the client sends incorrect Authorization you will still serve from the cache. This is insecure.
- mattrobenolt 10y agoThis is a trusted, internal, private network. The only one who could do this is the application itself, or something rogue on our network. If something were running rogue on our network, there'd be worse things it could get access to.
- krishnasrinivas 10y agoI see, if this is private network then this is a nice simple solution for caching. We plan to implement S3-caching in minio [https://minio.io https://minio.io] (i.e it will authenticate the requests and also do caching) in case you'd be interested for public facing caching proxies.
- mattrobenolt 10y agoYep, it's definitely possible to go this route as well. We just didn't have to.