apache / apache/trafficserver

Cache needs invalidated for PATCH and unknown methods

Open
#8,006 6 comments 0 reactions 1 assignee Claimed by @JosiahWI View on GitHub
Bug HTTP
Dominant language
C++
Stars
2k
Forks
874
Avg merge
6d 15h
Merged PRs (30d)
46

Description

This is strictly violating the RFC.

`does_method_require_cache_copy_deletion` needs to return true for PATCH and unknown methods

https://datatracker.ietf.org/doc/html/rfc7234#section-4.4

> A cache MUST invalidate the effective request URI (Section 5.5 of
> [RFC7230]) when it receives a non-error response to a request with a
> method whose safety is unknown.

And

https://datatracker.ietf.org/doc/html/rfc5789

> PATCH is neither safe nor idempotent

The code is https://github.com/apache/trafficserver/blob/b3ef5a04/proxy/http/HttpTransact.cc#L750

```
does_method_require_cache_copy_deletion(const HttpConfigParams *http_config_param, const int method)
{
return ((method != HTTP_WKSIDX_GET) &&
(method == HTTP_WKSIDX_DELETE || method == HTTP_WKSIDX_PURGE || method == HTTP_WKSIDX_PUT ||
(http_config_param->cache_post_method != 1 && method == HTTP_WKSIDX_POST)));
```

So it's only returning true specifically for DELETE,PURGE,PUT,(maybe)POST.

It needs changed to return `true`, causing ATS to delete (invalidate) cached objects, for unknown methods and `PATCH`.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.