fix(evidence): bind HTTP validators to final URL
This commit is contained in:
@@ -54,3 +54,12 @@ Four review findings were closed in a separate follow-up commit:
|
||||
conditional headers; a 304 reuses only previously verified cached bytes and identity. The LRU
|
||||
content cache has an explicit byte bound (`max_cache_bytes`). Validators are not forwarded
|
||||
across redirect origins.
|
||||
|
||||
### Conditional cache binding correction
|
||||
|
||||
The conditional cache now binds bytes and validators to both the canonical provenance key and the
|
||||
exact final effective representation URL. Redirect traversal recomputes request headers per hop:
|
||||
validators are sent only when that exact URL matches the cached final URL, never merely because a
|
||||
redirect retains an origin. A same-origin path change therefore downloads and replaces the body.
|
||||
The adapter accepts 304 only when the exact request carried a bound ETag or Last-Modified validator;
|
||||
unsolicited and cross-origin 304 responses are permanent protocol errors.
|
||||
|
||||
Reference in New Issue
Block a user