9 ms·
There is in fact some draft language around this kind of a mechanism to update a signature to extend the lifetime of the document by fetching a remote URL. See
by gregable 7y ago
There is in fact some draft language around this kind of a mechanism to update a signature to extend the lifetime of the document by fetching a remote URL. See https://tools.ietf.org/id/draft-yasskin-http-origin-signed-responses-02.html#rfc.section.3.7 https://tools.ietf.org/id/draft-yasskin-http-origin-signed-r... .
Doing this on every page load breaks either user privacy (by making the origin fetch before the user clicks) or the preload performance gain itself (by blocking load while waiting for this round trip).
- e12e 7y agoBut if the signature is expired, preload would fail anyway, which would trigger a regular load "on click" - but that click should maybe result in a head request for possibly just getting an updated signature?
- gregable 7y agoThe intermediary (Google in this case) can choose not to serve an expired exchange.