> Adding the "no-store, no-cache, must-revalidate" etc. headers to the
> Unauthorized page solves the problem.
> Any opinions about that? Is it my mistake, a squid bug, a Z3 bug?

Looks good. I think that we eventually want to review Zope 3 to find all of 
those type of pages. Thanks for digging into this.

