← Inspection rules
SEC-016 / v1.0.0 / 2026-10-09
Keep personalized responses isolated in caches
Editorial inspection guidance. Start with read-only permissions; fixes, credential revocation, and production changes follow the owner’s authorization.
Applicability
Services that cache responses which vary by login identity, tenant or permissions.
Where to look first
- CDN and proxy storage conditions, cache keys, Cookie and Authorization handling, authenticated pages and APIs.
Inspection steps
- Compare storage conditions and cache keys for personalized responses; verify isolation by identity, tenant and permission.
- Review tests in an owner-authorized environment: B visiting a URL after A must not receive A’s data, including anonymous and post-logout access.
- Check normal, error, redirect and reauthentication responses, plus behavior after invalidation. Configuration alone without behavioral evidence remains unverified.
Remediation direction
- Disable shared caching of personalized responses or design adequate identity and permission isolation; invalidate existing cache entries when changing policy.
Evidence required for completion
- Keep configuration changes and tests that vary user, tenant and anonymous-access order without cross-user data. Verify normal delivery still succeeds.
Limits and unverified scope
- Cache-Control alone does not prove CDN or custom application storage behavior. Inspect authorization separately with SEC-014.
- Incident links provide inspection guidance; they do not establish the same defect in every service.