Req #73377 [Com]: Verbose caching instructions by default.
| From: | inforbano at gmail dot com | Date: | Mon, 24 Oct 2016 20:32:17 +0000 |
| Subject: | Req #73377 [Com]: Verbose caching instructions by default. | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-204990@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=73377&edit=1
ID: 73377
Comment by: inforbano at gmail dot com
Reported by: inforbano at gmail dot com
Summary: Verbose caching instructions by default.
Status: Open
Type: Feature/Change Request
Package: PHP options/info functions
PHP Version: Irrelevant
Block user comment: N
Private report: N
New Comment:
"[...]" in your citation is "without a clock". Have you seen many servers with
PHP engine and without a clock? Anyway, this combination is not typical.
A typical server with PHP has clock. And it automatically generates the Date: header with current
time. The Expires: header with time in the past in this situation is spec violation.
The issue is actual, in particular, because it is unclear, how web-crawlers should treat this
situation. Formally, they can treat it as "the page contains outdated content". Therefore,
rating of the page can be suppressed.
Previous Comments:
------------------------------------------------------------------------
[2016-10-24 16:47:09] bwoebi@php.net
You are misreading the RFC, and even RFC 7234 states it's allowed:
https://tools.ietf.org/html/rfc7234#section-5.3
> An origin server [...] MUST NOT generate an Expires field
unless its value represents a fixed time in the past (always expired)
which is exactly what we want.
â¦
Regarding the issue, I doubt it's an actual issue, but I leave that to other people to
determine.
------------------------------------------------------------------------
[2016-10-23 10:48:41] inforbano at gmail dot com
What is even worse, according to RFC-2616
https://tools.ietf.org/html/rfc2616#section-14.21
date in Expires: can not be in the past. So, here PHP just violates web-standards.
------------------------------------------------------------------------
[2016-10-23 10:38:38] inforbano at gmail dot com
Description:
------------
When function session_start(); is used with default options, PHP generates headers like this:
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
This verbose behavior is wrong for the following reasons.
Most PHP-programmers do not need to know anything about caching. Therefore user agents (browsers,
proxies, robots...) MUST have rational behavior (with respect to caching) without any special
instructions from the server. This is only problem of user agents to understand cookies and to
automatically adjust their caching behavior according to their needs.
On the other hand, some meticulous PHP-programmers investigate HTTP-headers of their sites to be
sure that everything is fine. And in this case they just waste their time to study problems, that
are not their.
Test script:
---------------
<?php
session_start();
Expected result:
----------------
No special headers for caching by default.
This is like
session_cache_limiter('');
is set by default.
Actual result:
--------------
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=73377&edit=1