New issue
Advanced search Search tips

Issue 829100 link

Starred by 3 users

Issue metadata

Status: WontFix
Owner:
Closed: Aug 16
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 3
Type: Bug



Sign in to add a comment

Token Binding and Vary header

Project Member Reported by nhar...@chromium.org, Apr 4 2018

Issue description

The Token Binding HTTP spec (https://datatracker.ietf.org/doc/draft-ietf-tokbind-https/) says that the Sec-Token-Binding header may be included in the Vary header. Actually implementing this is somewhat ridiculous, as checking whether the Sec-Token-Binding header for a request matches a cached entry first requires binding the request to a connection.

To stay compliant with the HTTPSTB spec, another option is to treat "Vary: Sec-Token-Binding" as "Cache-Control: no-cache". This bug is to track progress on either bringing the Token Binding implementation in line with HTTPSTB w.r.t. Vary (likely by not caching any response that includes Sec-Token-Binding in the Vary header), or to document how our implementation deviates from the spec.
 
Status: WontFix (was: Assigned)
Token Binding is being removed. See crbug.com/875046

Sign in to add a comment