Uploaded image for project: 'Nuxeo Platform'
  1. Nuxeo Platform
  2. NXP-20344

Deactivate no-cache header on resources but only on pages

    XMLWordPrintable

    Details

    • Type: Bug
    • Status: Resolved
    • Priority: Minor
    • Resolution: Fixed
    • Affects Version/s: 7.10-HF07
    • Fix Version/s: 7.10-HF17, 8.10
    • Component/s: Security, Web Common
    • Tags:
    • Backlog priority:
      600
    • Sprint:
      nxNS Sprint 8.4.3
    • Story Points:
      3

      Description

      Since NXP-18651, the no-cache header has been set to avoid XSS threats. But:

      • It's a no-cache for all resources, not just only pages
      • It's a big issue for performances
      • It's not mandatory

      We should find a way to enable it only for pages.

        Attachments

          Issue Links

            Activity

              People

              • Votes:
                0 Vote for this issue
                Watchers:
                3 Start watching this issue

                Dates

                • Created:
                  Updated:
                  Resolved:

                  Time Tracking

                  Estimated:
                  Original Estimate - Not Specified
                  Not Specified
                  Remaining:
                  Remaining Estimate - Not Specified
                  Not Specified
                  Logged:
                  Time Spent - 2 hours
                  2h

                    PagerDuty

                    Error rendering 'com.pagerduty.jira-server-plugin:PagerDuty'. Please contact your Jira administrators.