Actions
Story #33
openEpic #32: Weak Authentication Controls
Implement Secure Cache-Control Headers( no-cache, no-store, max-age=0)
Start date:
01/05/2026
Due date:
% Done:
0%
Estimated time:
Acceptance Criteria:
1. No Cache directive instructs the browser or proxy to not cache the response. However, it may store a copy for validating subsequent requests, ensuring that the cached content is still valid
2. No Store directive tells the browser or proxy not to store any part of the response, including the headers and the body. It forces every request to be forwarded to the server for a fresh response.
3. Max age directive specifies the maximum amount of time (in seconds) for which a cached response can be considered fresh before it needs to be revalidated with the server.
DOR:
No
Story Points:
Work Type:
Feature
User Impact:
Technical Area:
Release Narrative:
Planned Sprint:
Completed In Sprint:
Spillover Reason:
Deployment Reference URL:
Description
As a system, I want to prevent sensitive pages from being cached.
Actions