activemq
activemq copied to clipboard
[AMQ-9545] Set cache-control to no-store by default for stronger security
Unspecified Cache-Control HTTP header is vulnerable. Set it to no-store to avoid caching sensitive data for stronger security. It should be the default unless users override it.
Reference: https://www.virtuesecurity.com/kb/cache-controls-explained/
Note: this PR was approved at https://github.com/apache/activemq/pull/1238 However, the branch history for that PR was messed up due to wrong operation with git. I closed that one and opened a new one (this one). Please approve again, thank you so much.