← Inspection rules

SEC-016 / v1.0.0 / 2026-10-09

Keep personalized responses isolated in caches

Editorial inspection guidance. Start with read-only permissions; fixes, credential revocation, and production changes follow the owner’s authorization.

Applicability

Services that cache responses which vary by login identity, tenant or permissions.

Where to look first

  • CDN and proxy storage conditions, cache keys, Cookie and Authorization handling, authenticated pages and APIs.

Inspection steps

  1. Compare storage conditions and cache keys for personalized responses; verify isolation by identity, tenant and permission.
  2. Review tests in an owner-authorized environment: B visiting a URL after A must not receive A’s data, including anonymous and post-logout access.
  3. Check normal, error, redirect and reauthentication responses, plus behavior after invalidation. Configuration alone without behavioral evidence remains unverified.

Remediation direction

  • Disable shared caching of personalized responses or design adequate identity and permission isolation; invalidate existing cache entries when changing policy.

Evidence required for completion

  • Keep configuration changes and tests that vary user, tenant and anonymous-access order without cross-user data. Verify normal delivery still succeeds.

Limits and unverified scope

  • Cache-Control alone does not prove CDN or custom application storage behavior. Inspect authorization separately with SEC-014.
  • Incident links provide inspection guidance; they do not establish the same defect in every service.