View Issue Details

IDProjectCategoryView StatusLast Update
0009723Talerexchangepublic2025-04-10 19:02
ReporterChristian Grothoff Assigned To 
PrioritynormalSeverityminorReproducibilityN/A
Status confirmedResolutionopen 
Platformi7OSDebian GNU/LinuxOS Versionsqueeze
Product Versiongit (master) 
Target Versionpost-1.0 
Summary0009723: exchange should set cache-control headers on GET requests to 'no-store' disable caching in some cases
DescriptionSome GET APIs return somewhat private data, we should explicitly tell HTTP caches to not store those.
This might have prevented a (minor) security issue found by RoS where i-Things cached possibly sensitive data on exposed local storage.
TagsNo tags attached.

Activities

There are no notes attached to this issue.

Issue History

Date Modified Username Field Change
2025-04-10 18:46 Christian Grothoff New Issue
2025-04-10 18:46 Christian Grothoff Status new => assigned
2025-04-10 18:46 Christian Grothoff Assigned To => Christian Grothoff
2025-04-10 18:46 Christian Grothoff Assigned To Christian Grothoff =>
2025-04-10 18:46 Christian Grothoff Status assigned => confirmed