3 ms·
I don't understand this, the line in the RFC is clear: > Responses to this method are not cacheable, unless the response includes appropriate Cache-Control or
by codeka 14y ago
I don't understand this, the line in the RFC is clear:
> Responses to this method are not cacheable, unless the response includes appropriate Cache-Control or Expires header fields.
That is, if you don't include a Cache-Control header, the response is not cacheable. Why is this even controversial? It's a bug.
- gioele 14y agoCaching without a Cache-Control header is a bug, agreed. The point is that in the original bug report the Cache-Control header was set in a way that implied the resource to be cacheable, but only for 0 seconds. This kind of declarations are perfect "worms' can openers". For a longer, more detailed discussion with references to the RFC, see https://news.ycombinator.com/item?id=4552251 https://news.ycombinator.com/item?id=4552251 .
- codeka 14y agoAs far as I can tell, the original report doesn't actually say whether there's no Cache-Control header at all or whether it set to max-age=0. I would still argue that caching a POST response with max-age=0 (and no max-stale) is a bug because, while the standard technically allows it, it also technically allows the client to immediately invalidate it and immediately invalidating is the saner choice (at least, it's the choice that is going to break fewer websites).