From 0f8b7d054e67e7423ea36453ccaa29088d7226d2 Mon Sep 17 00:00:00 2001 From: Daniel Covington Date: Wed, 29 Jul 2026 10:26:41 -0400 Subject: [PATCH] Fix contradictory cache headers on every response in core/mvc.asp Response.ExpiresAbsolute was set to a far-future date at the same time as Cache-Control: no-cache - contradictory directives that could let a cache serve a stale copy of dynamic, session-tied content. Also, Response.AddHeader "cache-control", ... doesn't affect the separate Response.CacheControl intrinsic property (which defaults to "private" and was still being sent regardless of AddHeader); set the property directly so the header is actually correct on the wire. Found while diagnosing a "Your form session expired" report that turned out to be caused by something else (a server-side permissions issue), but this is a real, independent correctness bug worth fixing regardless. --- core/mvc.asp | 17 ++++++++++++----- db/webdata.accdb | Bin 561152 -> 561152 bytes 2 files changed, 12 insertions(+), 5 deletions(-) diff --git a/core/mvc.asp b/core/mvc.asp index 0bbf373..69e81e7 100644 --- a/core/mvc.asp +++ b/core/mvc.asp @@ -1,11 +1,18 @@ <% -' Set cache expiration from configuration -Dim cacheYear : cacheYear = GetAppSetting("CacheExpirationYear") -If cacheYear = "nothing" Then cacheYear = "2030" -Response.ExpiresAbsolute = "01/01/" & cacheYear +' Every response is dynamic and session-sensitive (CSRF tokens, flash messages), so tell +' every cache - browser, proxy, or antivirus web filter - not to store it at all. +' +' Response.CacheControl is ASP's intrinsic property that actually governs the real +' Cache-Control header IIS sends, and it defaults to "private" (which explicitly PERMITS +' browser-local caching) if never set. Response.AddHeader "cache-control", ... does NOT +' touch that property - it adds a second, separate Cache-Control header alongside it, which +' a real proxy/cache can parse unpredictably (confirmed via debug logging: a response still +' reported Response.CacheControl = "private" even after AddHeader was called). Must set the +' CacheControl property directly for this to actually take effect. +Response.ExpiresAbsolute = Now() - 1 +Response.CacheControl = "no-cache" Response.AddHeader "pragma", "no-cache" -Response.AddHeader "cache-control", "private, no-cache, must-revalidate" '======================================================================================================================= ' MVC Dispatcher '======================================================================================================================= diff --git a/db/webdata.accdb b/db/webdata.accdb index f704df07b613fa1b89807d94d74e75afa41e5ad7..43def5cee4f305c2753cbca73d75d2cdc0dae6fb 100644 GIT binary patch delta 1525 zcmZWpO>7%g5T3Pn*J+%!HWB%4LhMvU6bOy$wX?CzX1&>NU1MVhBMv~?Mx^|RintJ! zf)F-U6mp?WNR#D&Adz~isw%0a7*$2-1&9Pfh(nNQB67-s3zZODTFHEGoir)z)7zPS zZ{B?0%$wQbd{=S4YtiL%KjxB3^}av38NaXYf;=H}6S8YUb}!4kd`ggssMT)F^G{2y zPMC&aVD%~D`eq+krtQD_!qAH}JMx+zF1^->s`;^=W`Dw)`~poO6g zz-|B@daLxCi~zWLABe~g}Ooz zsJ-Bzz(+59F|05}94y98akM^gj61s_?DarXAPt9$0U4s}^x7_dGw>Tf|8}DZcu<{( zegE^>mOe(O>0KHl9r8TcSJs5KLNys-IA(!|;V=%DD#%0}DnV!pz=95iIOqm3*jfZu zM{&Z!o6!&9t|~RhWC+JtZBRUTB_aFE*5p7j15OalgIE ziFrR54mB2vM9AAv6H{=3L(NPWwK$;JIQg&Ue_)TylHtL$a8)`(?3XrqjP~ zX)(?P3K3J+Q^}ZR7&%qTsL|x0s%nNcsOJXFXw0;1u0d?!n(WPb@my!p9Mp6(YUxH! zOKZ7AEE$a%k*H>*GU-$*R<&&|ztA9hUH()ql~yxWMmHk5rlk^zbjs3_re@~S8uqlR zb)$Xa5iuGlqz7ZUbRrp1EmPN2D`{mCIX#n(q@!lSibnLRb<5I1v3A)n%6^WYt>;_p zL%P@|d2v}gkGGuF#T%XO`_c%~#=H0$d1>J`XKxORO}<*9$$czCI5AmU=3Lx;X*n;t zBS5E0S4!E z_YO%%&Q{C(_S~*KfQ{AddHC8#Tdeg=+jFs|v+y3hfgT(qKRVzX<~t~_AZ9n}x6diA zUexgs6jzo;on9HH*I}2Tx9JSMPtT&vj-wn|S+bu<81FD-2vwiO9EDvTUPsZAZvy9e z2ko@8^Bb)V(=Ga%uF@6y^1+zIffHyM9~Fv~3Kt-x*ZGUE@YV(PCfdAQ4exq?ofVkdB4(@RdXtrQ~8`KR8&!&liC1irj`=>WQ}Okv?5DiRY1QARlL_Ur)^mUGS zzk?9YQ)CLKF^ZY(_#p06))0CjAhS~?-wu_m#m~~p0pX=Qw!GSH?XL>&IrBTm;tDk| z+m$h3cQV^m?l|#GmPBsBOL;wJKxG&5KEJ0_yu_J%J6YO#*U3D*DQj$S=E_mB8T7PfD4NxIwp(!n4_$UgbyC)se#w;-klJ0P;&YMdb}g8CMDS57rY5!@lQNu=tk&Js^h+}0Vx?QN9