FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

[Backport 20.3.X] fix(http): prevent caching of responses with Set-Cookie headers by SkyZeroZx · Pull Request #69448 · angular/angular · GitHub

[Backport 20.3.X] fix(http): prevent caching of responses with Set-Cookie headers - #69448

Merged
leonsenft merged 1 commit into
angular:20.3.xfrom
SkyZeroZx:backport/69385-to-20.3.x
Jul 7, 2026
Merged

[Backport 20.3.X] fix(http): prevent caching of responses with Set-Cookie headers#69448
leonsenft merged 1 commit into
angular:20.3.xfrom
SkyZeroZx:backport/69385-to-20.3.x

Conversation

Copy link
Copy Markdown
Contributor

Backport of #69385

Skip HttpTransferCache serialization for HTTP responses that contain a
Set-Cookie header.

Cookie-setting responses commonly represent session-specific,
user-specific, or security-sensitive state. Serializing their bodies into
SSR TransferState can embed sensitive data into the generated HTML, where
it may be reused during hydration or replayed by a shared cache/CDN.

(cherry picked from commit 80795de)
pullapprove Bot requested a review from crisbeto June 19, 2026 15:13
angular-robot Bot added the area: common/http Issues related to HTTP and HTTP Client label Jun 19, 2026
ngbot Bot added this to the Backlog milestone Jun 19, 2026
JeanMeche removed the request for review from crisbeto June 19, 2026 15:17
JeanMeche added action: merge The PR is ready for merge by the caretaker target: lts This PR is targeting a version currently in long-term support labels Jun 19, 2026
leonsenft merged commit b963f61 into angular:20.3.x Jul 7, 2026
32 of 34 checks passed

Copy link
Copy Markdown
Contributor

This PR was merged into the repository. The changes were merged into the following branches:

Copy link
Copy Markdown

This pull request has been automatically locked due to inactivity.
Please file a new issue if you are encountering a similar or related problem.

Read more about our automatic conversation locking policy.

This action has been performed automatically by a bot.

angular-automatic-lock-bot Bot locked and limited conversation to collaborators Aug 7, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

action: merge The PR is ready for merge by the caretaker area: common/http Issues related to HTTP and HTTP Client target: lts This PR is targeting a version currently in long-term support

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants


Back | FazBrowse Home | New Git URL