File tree Expand file tree Collapse file tree
crates/gitlawb-node/src/api Expand file tree Collapse file tree Original file line number Diff line number Diff line change @@ -343,6 +343,7 @@ POST /{owner}/{repo}/git-upload-pack
343343REST blob reads serve file content only; directory and gitlink paths return 404.
344344Body delivery has its own allowance equal to ` GITLAWB_GIT_SERVICE_TIMEOUT_SECS ` .
345345If delivery exceeds it, the response is interrupted and its admission slots are released.
346+ Blob responses use ` Cache-Control: no-store ` because they may contain private content.
346347
347348Signed write routes include:
348349
Original file line number Diff line number Diff line change @@ -624,6 +624,10 @@ pub async fn get_blob(
624624 std:: time:: Duration :: from_secs ( state. config . git_service_timeout_secs ) ,
625625 ) ;
626626 let mut response = Response :: new ( axum:: body:: Body :: from_stream ( stream) ) ;
627+ response. headers_mut ( ) . insert (
628+ header:: CACHE_CONTROL ,
629+ axum:: http:: HeaderValue :: from_static ( "no-store" ) ,
630+ ) ;
627631 response. headers_mut ( ) . insert (
628632 header:: CONTENT_TYPE ,
629633 axum:: http:: HeaderValue :: from_static ( mime) ,
@@ -4069,6 +4073,7 @@ mod tests {
40694073 "application/json; charset=utf-8"
40704074 ) ;
40714075 assert_eq ! ( response. headers( ) [ header:: CONTENT_LENGTH ] , "13" ) ;
4076+ assert_eq ! ( response. headers( ) [ header:: CACHE_CONTROL ] , "no-store" ) ;
40724077 let bytes = response. into_body ( ) . collect ( ) . await . unwrap ( ) . to_bytes ( ) ;
40734078 assert_eq ! ( & bytes[ ..] , b"{\" hello\" :123}" ) ;
40744079 }
You can’t perform that action at this time.
0 commit comments