NOTE
2.9 HTTP Cache
Historical notes on browser HTTP caching, strong cache, negotiated cache, Expires, Cache-Control, Last-Modified, and ETag.
This is a historical learning note and may contain outdated or incomplete understanding.
1. What Is HTTP Cache?
- Browser-side caching.
2. Why Is HTTP Cache Needed?
- HTTP is stateless. The advantage is good scalability; the disadvantage is that repeatedly sending the same data reduces network performance.
3. HTTP Cache Categories
3.1. State Cache
- Does not go through the server; directly determines the state of the target network based on cached information.
3.1.1. 301/302
- Disadvantage: redirecting to HTTPS through 301/302 may cause a downgrade man-in-the-middle attack.
3.1.2. HSTS
3.2. Strong Cache
- Does not send a request to the server, so performance is good but consistency is somewhat worse.
- It can take effect when entering an address in the browser, following page links, opening a new window, going forward, and going back, but should automatically become invalid when the user manually refreshes the page.
3.2.1. Expires
- Header provided by HTTP/1.0:
Expires: Wed, 8 Apr 2020 07:28:00 GMT - Disadvantages:
- Limited by the client’s local time.
- No semantic for “do not cache”.
3.2.2. Cache-Control
- Header provided by HTTP/1.1:
Cache-Control: max-age=600 - If
ExpiresandCache-Controlconflict,Cache-Controltakes precedence.
3.3. Negotiated Cache
- A request needs to be sent to the server, so consistency is better but performance is somewhat lower.
- It takes effect when entering an address in the browser, following page links, opening a new window, going forward, going back, and also when the user manually refreshes the page (F5). It becomes invalid only when the user force-refreshes (Ctrl+F5) or explicitly disables caching (for example, in DevTools). In that case, the client request automatically contains
Cache-Control: no-cache.
3.3.1. Last-Modified and If-Modified-Since
- Tell the client the last modification time of the resource:
HTTP/1.1 304 Not Modified Cache-Control: public, max-age=600 Last-Modified: Wed, 8 Apr 2020 15:31:30 GMT - Disadvantage:
- Last modification time is precise only to the second.
3.3.2. ETag and If-None-Match
- Used to tell the client the unique identifier of the resource:
HTTP/1.1 304 Not Modified Cache-Control: public, max-age=600 ETag: "28c3f612-ceb0-4ddc-ae35-791ca840c5fa" - Disadvantage:
- Lower performance because the server needs to hash the resource each time.
4. When Negotiated Cache and Strong Cache Exist Together
- When strong cache is available, return the resource directly from the strong cache without checking for changes.
- When strong cache expires or is disabled (
no-cache/must-revalidate), negotiated cache can still work normally.

Discussion
Sign in with GitHub to comment. Discussions are stored as GitHub Issues.View on GitHub