I fully support this proposal. In addition to APIs, I'd like to propose 
prohibiting caching any resources loaded over insecure HTTP, regardless of 
Cache-Control header, in Phase 2.N. The reasons are:
1) MITM can pollute users' HTTP cache, by modifying some JavaScript files with 
a long time cache control max-age.
2) It won't break any websites, just some performance penalty for them.
3) Many website operators and users avoid using HTTPS, since they believe HTTPS 
is much slower than plaintext HTTP. After deprecating HTTP cache, this argument 
will be more wrong.
_______________________________________________
dev-platform mailing list
dev-platform@lists.mozilla.org
https://lists.mozilla.org/listinfo/dev-platform

Reply via email to