4 ms·
Isn't that part of the point of etag headers?
by chrisacky 6y ago
Isn't that part of the point of etag headers?
- Scoundreller 6y agoWouldn’t that create a giant mess if someone forged the header etag to match something else?
- chrisacky 6y agoI haven't got enough skin in this to read any RFCs but my assumption had been it's not intended to act as a point of truth or verify contents and was always only to be used in an advisory capacity. So yeah, it would cause a mess.
- Waterluvian 6y agoYeah I think it's meant to be used in a context of mutual trust.
- Waterluvian 6y agoThanks for the name. I looked it up and it seems close. But I think it's up to the client to provide an etag and the server to respond with the same etag and a 304. What I'm thinking is a server blind way for the client to say: "give me th resource at address X. ... Oh you know what i think I already have this one. Let's abort the transfer." I guess what I'm thinking is a way for th client to decide it's a 304, not the server.
- bbatha 6y agoThe If-Match and If-None-Match headers makes the request conditional. You can also of course store the etag with the file or calculate the checksum and do a HEAD conditionally followed by a GET. But there isn’t any advantage to that over If-Match