You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
mastodon/app/controllers/auth
Daniel Axtens 4d85c27d1a
Add 'private' to Cache-Control, match Rails expectations (#20608)
Several controlers set quite intricate Cache-Control headers in order to
hopefully not be cached by any intermediate proxies or local caches. Unfortunately,
these headers are processed by ActionDispatch::HTTP::Cache in a way that squashes
and discards any values set alongside no-store other than private:
8015c2c2cf/actionpack/lib/action_dispatch/http/cache.rb (L207-L209)

We want to preserve no-store on these responses, but we might as well remove
parts that are going to be dropped anyway. As many of the endpoints in these
controllers are private to a particular user, we should also add "private",
which will be preserved alongside no-store.
2 years ago
..
challenges_controller.rb Add password challenge to 2FA settings, e-mail notifications (#11878) 6 years ago
confirmations_controller.rb Fix confirmation redirect to app without `Location` header (#18523) 3 years ago
omniauth_callbacks_controller.rb Fix crash when external auth provider has no display_name set (#19962) 3 years ago
passwords_controller.rb Fix reviving revoked sessions and invalidating login (#16943) 4 years ago
registrations_controller.rb Add 'private' to Cache-Control, match Rails expectations (#20608) 2 years ago
sessions_controller.rb Fix suspicious sign-in mails never being sent (#18599) 3 years ago
setup_controller.rb Change unconfirmed user login behaviour (#11375) 6 years ago