Rails ( set_no_cache method) Cannot disable browser caching in Safari and Opera

后端 未结 3 496
后悔当初
后悔当初 2021-01-02 03:28

After using Devise for my authentication, I found that there was a security hole in that, after the user logs out, the session variables are preserved. This allows anyone to

3条回答
  •  佛祖请我去吃肉
    2021-01-02 04:12

    First of all, for any issues with cache, use Mark Nottingham's guide on HTTP caching

    Cache-Control: no-cache, no-store, must-revalidate
    Pragma: no-cache
    Expires: 0
    

    Try this.

提交回复
热议问题