Skip to content

Commit 49aebb2

Browse files
committed
fix(node): prevent caching of authorized blob content
Set Cache-Control to no-store so private content is not reused after an identity change, and assert the response header. Fixup for fc2d043. Refs #407
1 parent 4344b77 commit 49aebb2

2 files changed

Lines changed: 6 additions & 0 deletions

File tree

‎README.md‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -343,6 +343,7 @@ POST /{owner}/{repo}/git-upload-pack
343343
REST blob reads serve file content only; directory and gitlink paths return 404.
344344
Body delivery has its own allowance equal to `GITLAWB_GIT_SERVICE_TIMEOUT_SECS`.
345345
If delivery exceeds it, the response is interrupted and its admission slots are released.
346+
Blob responses use `Cache-Control: no-store` because they may contain private content.
346347

347348
Signed write routes include:
348349

‎crates/gitlawb-node/src/api/repos.rs‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -624,6 +624,10 @@ pub async fn get_blob(
624624
std::time::Duration::from_secs(state.config.git_service_timeout_secs),
625625
);
626626
let mut response = Response::new(axum::body::Body::from_stream(stream));
627+
response.headers_mut().insert(
628+
header::CACHE_CONTROL,
629+
axum::http::HeaderValue::from_static("no-store"),
630+
);
627631
response.headers_mut().insert(
628632
header::CONTENT_TYPE,
629633
axum::http::HeaderValue::from_static(mime),
@@ -4069,6 +4073,7 @@ mod tests {
40694073
"application/json; charset=utf-8"
40704074
);
40714075
assert_eq!(response.headers()[header::CONTENT_LENGTH], "13");
4076+
assert_eq!(response.headers()[header::CACHE_CONTROL], "no-store");
40724077
let bytes = response.into_body().collect().await.unwrap().to_bytes();
40734078
assert_eq!(&bytes[..], b"{\"hello\":123}");
40744079
}

0 commit comments

Comments
 (0)