Req #40686 [Opn]: Overly restrictive/invalid headers sent as session cache limiters
| From: | cmb@php.net | Date: | Thu, 12 Sep 2019 10:37:49 +0000 |
| Subject: | Req #40686 [Opn]: Overly restrictive/invalid headers sent as session cache limiters | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-222703@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=40686&edit=1
ID: 40686
Updated by: cmb@php.net
Reported by: spam02 at pornel dot net
Summary: Overly restrictive/invalid headers sent as session
cache limiters
Status: Open
Type: Feature/Change Request
-Package: Feature/Change Request
+Package: *General Issues
Operating System: *
PHP Version: 4CVS-2007-03-01 (snap)
Block user comment: N
Private report: N
New Comment:
JFTR: the IE specific directives are removed as of PHP 7.0.0.
Previous Comments:
------------------------------------------------------------------------
[2007-03-01 22:52:30] spam02 at pornel dot net
Description:
------------
Currently, *by default*, PHP sends *the most restrictive* anti-caching directives possible.
* no-store is intended as a security measure, not regular cache-control
* must-revalidate alone doesn't prevent caching, just requires browser to revalidate it after
it expires. This however, with no-cache prevents use of "offline browsing" feature.
* pre-check and post-check are non-standard directives that let Internet Explorer revalidate cached
objects less frequently and/or asynchronously.
Please don't use these directives in the default configuration (called "nocache"
cache_limiter), as their use in majority of cases is either unjustified or invalid and causes
performance and usability problems (for example: https://bugzilla.mozilla.org/show_bug.cgi?id=261312).
BTW: it turns out that Opera (and most likely other browser vendors) do not fully support these
directives *because* PHP abuses them
(http://my.opera.com/yngve/blog/2007/02/27/introducing-cache-contexts-or-why-the "This abuse is
the reason why must-revalidate is only obeyed for secure sites.")
Reproduce code:
---------------
<?php session_start();
Expected result:
----------------
Cache-control: no-cache
Actual result:
--------------
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=40686&edit=1