Squid does not cache pages that are HTTP authenticated, unless a Cache-Control: public header is returned with the response (the web site would have to do this specifically). If they're using another authentication mechanism, it's perfectly possible the pages are being cached, albiet unlikely (they'd have to generate validators, Expires times or similar for the objects as they're served). This assumes Squid 2.x; Squid 1.x behaves in a similar manner, AFAIK, except I don't know offhand whether it will honor a Cache-Control: public directive. A much more likely explanation is that someone had used the browser to access the site in the same session. Regards, > I works for a small IT news service. A large portion of our > articles are in > directories protected using basic authentication. Recently, one of our > sales people was demoing our service and found that the > person to whom they > were demoing could read the articles within the protected > directories - > without having to enter a password. > > After I checked and could find no accesses from the company > (and indeed the > continent in question) during the time when the demo was > taking place, I > asked if there was a cache in use. They told me that SQUID > was being used. > > Am I correct in thinking that SQUID has cached the page from > an earlier > access by someone who does have a password, or am I barking > up the wrong > tree here? > > - Si >
RE: Small question about the caching of password protected pages
Nottingham, Mark (Australia) Wed, 10 Feb 1999 18:02:02 -0500
- Small question about the caching of password ... Simon Austin
- Re: Small question about the caching of ... Robert Olsson
- RE: Small question about the caching of ... Nottingham, Mark (Australia)
- RE: Small question about the caching... Simon Austin
- RE: Small question about the caching of ... Nottingham, Mark (Australia)
- RE: Small question about the caching of ... Williams Jon
- Re: Proxy authentication and caching Henrik Nordstrom
- RE: Small question about the caching of ... Nottingham, Mark (Australia)
