[imp] IE 5 Cache Security Problem

Chuck Hagenbuch chuck@horde.org
Thu, 25 Oct 2001 12:16:40 -0400


Quoting Derek Au <dau@diala.greenpeace.org>:

> HTTPS files delivered by IMP are being cached for 24 hours by IE 5.  I
> couldn't find a conclusive fix in the list archives.  For instance,
> turning on the "do not save encrypted pages to disk" option is IE is not
> recommended in numerous threads (for file downloading, I believe).  And
> I cannot find the default->cache_pages in defaults.php3, but I assume the
> default is not to cache.

We send appropriate caching headers. We also modify the headers when downloading
files so that things work even with "do not save encrypted pages to disk" on, so
I'd reccomend that, since it's the sane way to do things anyway.

-chuck

--
Charles Hagenbuch, <chuck@horde.org>
"What was and what may be, lie, like children whose faces we cannot see, in the
arms of silence. All we ever have is here, now." - Ursula K. Le Guin