Skip to content

[Backport 21.2.X] fix(http): prevent caching of responses with Set-Cookie headers - #69449

Merged
leonsenft merged 1 commit into
angular:21.2.xfrom
SkyZeroZx:backport/69385-to-21.2.x
Jul 7, 2026
Merged

[Backport 21.2.X] fix(http): prevent caching of responses with Set-Cookie headers#69449
leonsenft merged 1 commit into
angular:21.2.xfrom
SkyZeroZx:backport/69385-to-21.2.x

Conversation

@SkyZeroZx

Copy link
Copy Markdown
Contributor

Backport of #69385

Skip HttpTransferCache serialization for HTTP responses that contain a
Set-Cookie header.

Cookie-setting responses commonly represent session-specific,
user-specific, or security-sensitive state. Serializing their bodies into
SSR TransferState can embed sensitive data into the generated HTML, where
it may be reused during hydration or replayed by a shared cache/CDN.

(cherry picked from commit 80795de)
@pullapprove
pullapprove Bot requested a review from crisbeto June 19, 2026 15:15
@angular-robot angular-robot Bot added the area: common/http Issues related to HTTP and HTTP Client label Jun 19, 2026
@ngbot ngbot Bot added this to the Backlog milestone Jun 19, 2026
@JeanMeche
JeanMeche removed the request for review from crisbeto June 19, 2026 15:17
@JeanMeche JeanMeche added action: merge The PR is ready for merge by the caretaker target: lts This PR is targeting a version currently in long-term support labels Jun 19, 2026
@leonsenft
leonsenft merged commit 91df739 into angular:21.2.x Jul 7, 2026
28 of 29 checks passed
@leonsenft

Copy link
Copy Markdown
Contributor

This PR was merged into the repository. The changes were merged into the following branches:

@angular-automatic-lock-bot

Copy link
Copy Markdown

This pull request has been automatically locked due to inactivity.
Please file a new issue if you are encountering a similar or related problem.

Read more about our automatic conversation locking policy.

This action has been performed automatically by a bot.

@angular-automatic-lock-bot angular-automatic-lock-bot Bot locked and limited conversation to collaborators Aug 7, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

action: merge The PR is ready for merge by the caretaker area: common/http Issues related to HTTP and HTTP Client target: lts This PR is targeting a version currently in long-term support

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants