Skip to content

skip private and Vary: * responses in HttpCacheInterceptor - #3610

Open
alhudz wants to merge 1 commit into
OpenFeign:masterfrom
alhudz:http-cache-shareable-responses
Open

alhudz wants to merge 1 commit into
OpenFeign:masterfrom
alhudz:http-cache-shareable-responses

Conversation

@alhudz

@alhudz alhudz commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Repro: two callers share one client and both GET /things/42; the origin answers the first with Cache-Control: private, ETag: "v1" and that caller's data, then answers the second caller's revalidation with 304.
Expected: the second caller gets its own data, or the 304 surfaces.
Actual: the second caller is handed the first caller's decoded object.
Cause: maybeStore only refuses no-store, so a private response (RFC 9111 5.2.2.7, a shared cache must not store it) and a Vary: * response (RFC 9111 4.1, * never matches a later request) both land in the HttpCacheStore every caller of the client shares, under a default key of configKey|METHOD url[|body hash] that carries no request header. The stored validator then goes out on the next caller's request as If-None-Match.
Fix: treat both as unstorable alongside no-store. Vary field names other than * are untouched, so Vary: Accept-Encoding and friends still cache as before, and the README caveat about uninterpreted Cache-Control directives is narrowed to freshness, which revalidation already covers.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant