Files
changedetection.io/changedetectionio/tests
Dennis Gaidaanddgtlmoon b91082b38a Set Cache-Control: no-store on dynamic responses by default (#4319)
* Set Cache-Control: no-store on dynamic responses by default

Pages with per-session content (settings, CSRF-token-bearing forms,
watch data) had no Cache-Control header, so a misconfigured CDN or
reverse proxy sitting in front of the app could cache and replay them
across requests/sessions — most commonly surfacing as "CSRF tokens do
not match" after the edge served a stale cached page. Routes that
already set their own Cache-Control (static assets, screenshots,
favicons) are left untouched.

* Adding tests and moving function

---------

Co-authored-by: dgtlmoon <dgtlmoon@gmail.com>
2026-09-17 11:20:31 +02:00
..
2021-08-16 15:24:37 +02:00