Skip to content

Update our Cache-Control header #58169

@joshbressers

Description

@joshbressers

Today we set the Cache-Control header to no-cache. The current best practice advice we're seeing states

Whenever possible ensure the cache-control HTTP header is set with no-cache, no-store, must-revalidate; and that the pragma HTTP header is set with no-cache.

This is not a security vulnerability to be missing these headers, it is a security hardening measure

Metadata

Metadata

Assignees

Labels

Feature:HardeningHarding of Kibana from a security perspectiveTeam:SecurityPlatform Security: Auth, Users, Roles, Spaces, Audit Logging, etc t//

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions