added no-store headers to api responses

Signed-off-by: RonniSkansing <rskansing@gmail.com>
This commit is contained in:
RonniSkansing committed 2026-10-07 21:21:06 +02:00
1 parent 4f7484a8ea
commit e8c0da0160
3 files changed
+17 -2

No files matched your search

+3 -2
View File
@@ -319,8 +319,9 @@ func setupRoutes(
// phishing server (app/server.go AssignRoutes), gated to a single global
// domain, so the admin port does not need public exposure for SCIM.
// all other admin routes are protected by the ip allowlist middleware
admin := r.Group("/", middleware.IPLimiter)
// ip allowlist on all admin routes; NoStore keeps API responses out of the
// browser disk cache. static assets are served off the group and stay cacheable.
admin := r.Group("/", middleware.IPLimiter, middleware.NoStore)
_ = admin
if !build.Flags.Production {
+2
View File
@@ -15,6 +15,7 @@ type Middlewares struct {
LoginRateLimiter gin.HandlerFunc
SessionHandler gin.HandlerFunc
SoftSessionHandler gin.HandlerFunc
NoStore gin.HandlerFunc
}
// NewMiddlewares creates a collection of middlewares
@@ -48,6 +49,7 @@ func NewMiddlewares(
LoginRateLimiter: loginThrottle,
SessionHandler: sessionHandler,
SoftSessionHandler: softSessionHandler,
NoStore: middleware.NoStore(),
}
}
+12
View File
@@ -0,0 +1,12 @@
package middleware
import "github.com/gin-gonic/gin"
// NoStore keeps responses out of the browser disk cache. A handler may set
// its own Cache-Control afterwards to override it.
func NoStore() gin.HandlerFunc {
return func(c *gin.Context) {
c.Header("Cache-Control", "no-store")
c.Next()
}
}