Project

General

Profile

Actions

Story #33

open

Epic #32: Weak Authentication Controls

Implement Secure Cache-Control Headers( no-cache, no-store, max-age=0)

Added by rashmita rout about 2 months ago. Updated about 2 months ago.

Status:
New
Priority:
High
Assignee:
Target version:
-
Start date:
01/05/2026
Due date:
% Done:

0%

Estimated time:
Acceptance Criteria:

1. No Cache directive instructs the browser or proxy to not cache the response. However, it may store a copy for validating subsequent requests, ensuring that the cached content is still valid
2. No Store directive tells the browser or proxy not to store any part of the response, including the headers and the body. It forces every request to be forwarded to the server for a fresh response.
3. Max age directive specifies the maximum amount of time (in seconds) for which a cached response can be considered fresh before it needs to be revalidated with the server.

DOR:
No
Story Points:
Work Type:
Feature
User Impact:
Technical Area:
Release Narrative:
Planned Sprint:
Completed In Sprint:
Spillover Reason:

Description

As a system, I want to prevent sensitive pages from being cached.

Actions #1

Updated by rashmita rout about 2 months ago

  • Assignee set to Tingg BE
Actions

Also available in: Atom PDF