> > > > The point is that a browser can act as if every single server response
> > > > included "Vary: User-Agent".  And perhaps should.  Intermediary caches
> > > > _certainly_ should.
> > 
> > 
> > 
> > Good suggestion.
> 
> 

> But my concern was even if browser acts as such, intermediary caches would 
> still return forged content


I guess UAs *could* add a Cache-control: no-cache request header when getting a 
resource that was previously retrieved with a different UA string - this is 
getting very "fiddly" though.

-- 
Hallvord R. M. Steen
Core tester, Opera Software






Reply via email to