WebApp Sec mailing list archives

Cache-Control


From: Pessoft <pessoft () seznam cz>
Date: Mon, 15 Sep 2003 01:37:42 +0200

I need to disable caching my page for maximal security, but i don't know how.
I've tried using http headers Pragme, Expires, Cache-Control without success.
Under Opera page works fine, but IE still caches links and after switching from
one section to another after logoff when i try to return to section one IE reads
cached page and shows, that i'm logged in, but actually i'm not. Also when i run
script which outputs $_SERVER['HTTP_CACHE_CONTROL'] Opera writes "no-cache", but
IE writes ~ undefined variable ~. I've tried IE 5.5 under Win98se and also IE
under WinXP.

Pessoft

PS: Anybody knows how to enable cookies in IE for localhost HTTP server.



Current thread: