activemq icon indicating copy to clipboard operation
activemq copied to clipboard

[AMQ-9545] Set cache-control to no-store by default for stronger security

Open kenliao94 opened this issue 1 year ago • 0 comments

Unspecified Cache-Control HTTP header is vulnerable. Set it to no-store to avoid caching sensitive data for stronger security. It should be the default unless users override it.

Reference: https://www.virtuesecurity.com/kb/cache-controls-explained/

Note: this PR was approved at https://github.com/apache/activemq/pull/1238 However, the branch history for that PR was messed up due to wrong operation with git. I closed that one and opened a new one (this one). Please approve again, thank you so much.

kenliao94 avatar Aug 23 '24 05:08 kenliao94