Previously we'd prevent caching of authed responses for security (prevent back cache or proxy caching) but caching could still be an issue in non-auth scenarios due to CSRF (eg. returning to login screen after session expiry). For #4600 |
||
|---|---|---|
| .. | ||
| Middleware | ||
| ApiController.php | ||
| Controller.php | ||
| DownloadResponseFactory.php | ||
| HttpClientHistory.php | ||
| HttpRequestService.php | ||
| Kernel.php | ||
| Request.php | ||