418   <body>
419      <table class="header">
420         <tbody>
421            <tr>
422               <td class="left">HTTPbis Working Group</td>
423               <td class="right">R. Fielding, Editor</td>
424            </tr>
425            <tr>
426               <td class="left">Internet-Draft</td>
427               <td class="right">Adobe</td>
428            </tr>
429            <tr>
430               <td class="left">Obsoletes: <a href="">2616</a> (if approved)
431               </td>
432               <td class="right">J. Gettys</td>
433            </tr>
434            <tr>
435               <td class="left">Intended status: Standards Track</td>
436               <td class="right">Alcatel-Lucent</td>
437            </tr>
438            <tr>
439               <td class="left">Expires: October 20, 2011</td>
440               <td class="right">J. Mogul</td>
441            </tr>
442            <tr>
443               <td class="left"></td>
444               <td class="right">HP</td>
445            </tr>
446            <tr>
447               <td class="left"></td>
448               <td class="right">H. Frystyk</td>
449            </tr>
450            <tr>
451               <td class="left"></td>
452               <td class="right">Microsoft</td>
453            </tr>
454            <tr>
455               <td class="left"></td>
456               <td class="right">L. Masinter</td>
457            </tr>
458            <tr>
459               <td class="left"></td>
460               <td class="right">Adobe</td>
461            </tr>
462            <tr>
463               <td class="left"></td>
464               <td class="right">P. Leach</td>
465            </tr>
466            <tr>
467               <td class="left"></td>
468               <td class="right">Microsoft</td>
469            </tr>
470            <tr>
471               <td class="left"></td>
472               <td class="right">T. Berners-Lee</td>
473            </tr>
474            <tr>
475               <td class="left"></td>
476               <td class="right">W3C/MIT</td>
477            </tr>
478            <tr>
479               <td class="left"></td>
480               <td class="right">Y. Lafon, Editor</td>
481            </tr>
482            <tr>
483               <td class="left"></td>
484               <td class="right">W3C</td>
485            </tr>
486            <tr>
487               <td class="left"></td>
488               <td class="right">M. Nottingham, Editor</td>
489            </tr>
490            <tr>
491               <td class="left"></td>
492               <td class="right">J. Reschke, Editor</td>
493            </tr>
494            <tr>
495               <td class="left"></td>
496               <td class="right">greenbytes</td>
497            </tr>
498            <tr>
499               <td class="left"></td>
500               <td class="right">April 18, 2011</td>
501            </tr>
502         </tbody>
503      </table>
HTTP/1.1, part 6: Caching
draft-ietf-httpbis-p6-cache-14
Abstract
506      <p>The Hypertext Transfer Protocol (HTTP) is an application-level protocol for distributed, collaborative, hypermedia information
507         systems. This document is Part 6 of the seven-part specification that defines the protocol referred to as "HTTP/1.1" and,
508         taken together, obsoletes RFC 2616. Part 6 defines requirements on HTTP caches and the associated header fields that control
509         cache behavior or indicate cacheable response messages.
510      </p>
511      <h1 id="rfc.note.1"><a href="#rfc.note.1">Editorial Note (To be removed by RFC Editor)</a></h1>
512      <p>Discussion of this draft should take place on the HTTPBIS working group mailing list (, which is archived
513         at &lt;<a href=""></a>&gt;.
514      </p>
515      <p>The current issues list is at &lt;<a href=""></a>&gt; and related documents (including fancy diffs) can be found at &lt;<a href=""></a>&gt;.
516      </p>
517      <p>The changes in this draft are summarized in <a href="#changes.since.13" title="Since draft-ietf-httpbis-p6-cache-13">Appendix&nbsp;C.15</a>.
518      </p>
Status of This Memo
520         <h1><a href="#rfc.status">Status of This Memo</a></h1>
521         <p>This Internet-Draft is submitted in full conformance with the provisions of BCP 78 and BCP 79.</p>
522         <p>Internet-Drafts are working documents of the Internet Engineering Task Force (IETF). Note that other groups may also distribute
523            working documents as Internet-Drafts. The list of current Internet-Drafts is at <a href=""></a>.
524         </p>
525         <p>Internet-Drafts are draft documents valid for a maximum of six months and may be updated, replaced, or obsoleted by other
526            documents at any time. It is inappropriate to use Internet-Drafts as reference material or to cite them other than as “work
527            in progress”.
528         </p>
529         <p>This Internet-Draft will expire on October 20, 2011.</p>
530      </div>
Copyright Notice
532         <h1><a href="#rfc.copyrightnotice">Copyright Notice</a></h1>
533         <p>Copyright © 2011 IETF Trust and the persons identified as the document authors. All rights reserved.</p>
534         <p>This document is subject to BCP 78 and the IETF Trust's Legal Provisions Relating to IETF Documents (<a href=""></a>) in effect on the date of publication of this document. Please review these documents carefully, as they describe your rights
535            and restrictions with respect to this document. Code Components extracted from this document must include Simplified BSD License
536            text as described in Section 4.e of the Trust Legal Provisions and are provided without warranty as described in the Simplified
537            BSD License.
538         </p>
539         <p>This document may contain material from IETF Documents or IETF Contributions published or made publicly available before November
540            10, 2008. The person(s) controlling the copyright in some of this material may not have granted the IETF Trust the right to
541            allow modifications of such material outside the IETF Standards Process. Without obtaining an adequate license from the person(s)
542            controlling the copyright in such materials, this document may not be modified outside the IETF Standards Process, and derivative
543            works of it may not be created outside the IETF Standards Process, except to format it for publication as an RFC or to translate
544            it into languages other than English.
545         </p>
546      </div>
Table of Contents
549      <ul class="toc">
550         <li><a href="#rfc.section.1">1.</a>&nbsp;&nbsp;&nbsp;<a href="#caching">Introduction</a><ul>
551               <li><a href="#rfc.section.1.1">1.1</a>&nbsp;&nbsp;&nbsp;<a href="#intro.purpose">Purpose</a></li>
552               <li><a href="#rfc.section.1.2">1.2</a>&nbsp;&nbsp;&nbsp;<a href="#intro.terminology">Terminology</a></li>
553               <li><a href="#rfc.section.1.3">1.3</a>&nbsp;&nbsp;&nbsp;<a href="#intro.requirements">Requirements</a></li>
554               <li><a href="#rfc.section.1.4">1.4</a>&nbsp;&nbsp;&nbsp;<a href="#notation">Syntax Notation</a><ul>
555                     <li><a href="#rfc.section.1.4.1">1.4.1</a>&nbsp;&nbsp;&nbsp;<a href="#core.rules">Core Rules</a></li>
556                     <li><a href="#rfc.section.1.4.2">1.4.2</a>&nbsp;&nbsp;&nbsp;<a href="#abnf.dependencies">ABNF Rules defined in other Parts of the Specification</a></li>
557                  </ul>
558               </li>
559            </ul>
560         </li>
561         <li><a href="#rfc.section.2">2.</a>&nbsp;&nbsp;&nbsp;<a href="#caching.overview">Cache Operation</a><ul>
562               <li><a href="#rfc.section.2.1">2.1</a>&nbsp;&nbsp;&nbsp;<a href="#response.cacheability">Response Cacheability</a><ul>
563                     <li><a href="#rfc.section.2.1.1">2.1.1</a>&nbsp;&nbsp;&nbsp;<a href="#errors.or.incomplete.response.cache.behavior">Storing Partial and Incomplete Responses</a></li>
564                  </ul>
565               </li>
566               <li><a href="#rfc.section.2.2">2.2</a>&nbsp;&nbsp;&nbsp;<a href="#constructing.responses.from.caches">Constructing Responses from Caches</a></li>
567               <li><a href="#rfc.section.2.3">2.3</a>&nbsp;&nbsp;&nbsp;<a href="#expiration.model">Freshness Model</a><ul>
568                     <li><a href="#rfc.section.2.3.1">2.3.1</a>&nbsp;&nbsp;&nbsp;<a href="#calculating.freshness.lifetime">Calculating Freshness Lifetime</a></li>
569                     <li><a href="#rfc.section.2.3.2">2.3.2</a>&nbsp;&nbsp;&nbsp;<a href="#age.calculations">Calculating Age</a></li>
570                     <li><a href="#rfc.section.2.3.3">2.3.3</a>&nbsp;&nbsp;&nbsp;<a href="#serving.stale.responses">Serving Stale Responses</a></li>
571                  </ul>
572               </li>
573               <li><a href="#rfc.section.2.4">2.4</a>&nbsp;&nbsp;&nbsp;<a href="#validation.model">Validation Model</a></li>
574               <li><a href="#rfc.section.2.5">2.5</a>&nbsp;&nbsp;&nbsp;<a href="#invalidation.after.updates.or.deletions">Request Methods that Invalidate</a></li>
575               <li><a href="#rfc.section.2.6">2.6</a>&nbsp;&nbsp;&nbsp;<a href="#caching.authenticated.responses">Shared Caching of Authenticated Responses</a></li>
576               <li><a href="#rfc.section.2.7">2.7</a>&nbsp;&nbsp;&nbsp;<a href="#caching.negotiated.responses">Caching Negotiated Responses</a></li>
577               <li><a href="#rfc.section.2.8">2.8</a>&nbsp;&nbsp;&nbsp;<a href="#combining.responses">Combining Responses</a></li>
578            </ul>
579         </li>
580         <li><a href="#rfc.section.3">3.</a>&nbsp;&nbsp;&nbsp;<a href="#header.fields">Header Field Definitions</a><ul>
581               <li><a href="#rfc.section.3.1">3.1</a>&nbsp;&nbsp;&nbsp;<a href="#header.age">Age</a></li>
582               <li><a href="#rfc.section.3.2">3.2</a>&nbsp;&nbsp;&nbsp;<a href="#header.cache-control">Cache-Control</a><ul>
583                     <li><a href="#rfc.section.3.2.1">3.2.1</a>&nbsp;&nbsp;&nbsp;<a href="#cache-request-directive">Request Cache-Control Directives</a></li>
584                     <li><a href="#rfc.section.3.2.2">3.2.2</a>&nbsp;&nbsp;&nbsp;<a href="#cache-response-directive">Response Cache-Control Directives</a></li>
585                     <li><a href="#rfc.section.3.2.3">3.2.3</a>&nbsp;&nbsp;&nbsp;<a href="#cache.control.extensions">Cache Control Extensions</a></li>
586                  </ul>
587               </li>
588               <li><a href="#rfc.section.3.3">3.3</a>&nbsp;&nbsp;&nbsp;<a href="#header.expires">Expires</a></li>
589               <li><a href="#rfc.section.3.4">3.4</a>&nbsp;&nbsp;&nbsp;<a href="#header.pragma">Pragma</a></li>
590               <li><a href="#rfc.section.3.5">3.5</a>&nbsp;&nbsp;&nbsp;<a href="#header.vary">Vary</a></li>
591               <li><a href="#rfc.section.3.6">3.6</a>&nbsp;&nbsp;&nbsp;<a href="#header.warning">Warning</a></li>
592            </ul>
593         </li>
594         <li><a href="#rfc.section.4">4.</a>&nbsp;&nbsp;&nbsp;<a href="#history.lists">History Lists</a></li>
595         <li><a href="#rfc.section.5">5.</a>&nbsp;&nbsp;&nbsp;<a href="#IANA.considerations">IANA Considerations</a><ul>
596               <li><a href="#rfc.section.5.1">5.1</a>&nbsp;&nbsp;&nbsp;<a href="#cache.directive.registration">Cache Directive Registry</a></li>
597               <li><a href="#rfc.section.5.2">5.2</a>&nbsp;&nbsp;&nbsp;<a href="#header.field.registration">Header Field Registration</a></li>
598            </ul>
599         </li>
600         <li><a href="#rfc.section.6">6.</a>&nbsp;&nbsp;&nbsp;<a href="#security.considerations">Security Considerations</a></li>
601         <li><a href="#rfc.section.7">7.</a>&nbsp;&nbsp;&nbsp;<a href="#ack">Acknowledgments</a></li>
602         <li><a href="#rfc.section.8">8.</a>&nbsp;&nbsp;&nbsp;<a href="#rfc.references">References</a><ul>
603               <li><a href="#rfc.section.8.1">8.1</a>&nbsp;&nbsp;&nbsp;<a href="#rfc.references.1">Normative References</a></li>
604               <li><a href="#rfc.section.8.2">8.2</a>&nbsp;&nbsp;&nbsp;<a href="#rfc.references.2">Informative References</a></li>
605            </ul>
606         </li>
607         <li><a href="#rfc.section.A">A.</a>&nbsp;&nbsp;&nbsp;<a href="#changes.from.rfc.2616">Changes from RFC 2616</a></li>
608         <li><a href="#rfc.section.B">B.</a>&nbsp;&nbsp;&nbsp;<a href="#collected.abnf">Collected ABNF</a></li>
609         <li><a href="#rfc.section.C">C.</a>&nbsp;&nbsp;&nbsp;<a href="#change.log">Change Log (to be removed by RFC Editor before publication)</a><ul>
610               <li><a href="#rfc.section.C.1">C.1</a>&nbsp;&nbsp;&nbsp;<a href="#rfc.section.C.1">Since RFC 2616</a></li>
611               <li><a href="#rfc.section.C.2">C.2</a>&nbsp;&nbsp;&nbsp;<a href="#rfc.section.C.2">Since draft-ietf-httpbis-p6-cache-00</a></li>
612               <li><a href="#rfc.section.C.3">C.3</a>&nbsp;&nbsp;&nbsp;<a href="#rfc.section.C.3">Since draft-ietf-httpbis-p6-cache-01</a></li>
613               <li><a href="#rfc.section.C.4">C.4</a>&nbsp;&nbsp;&nbsp;<a href="#changes.since.02">Since draft-ietf-httpbis-p6-cache-02</a></li>
614               <li><a href="#rfc.section.C.5">C.5</a>&nbsp;&nbsp;&nbsp;<a href="#changes.since.03">Since draft-ietf-httpbis-p6-cache-03</a></li>
615               <li><a href="#rfc.section.C.6">C.6</a>&nbsp;&nbsp;&nbsp;<a href="#changes.since.04">Since draft-ietf-httpbis-p6-cache-04</a></li>
616               <li><a href="#rfc.section.C.7">C.7</a>&nbsp;&nbsp;&nbsp;<a href="#changes.since.05">Since draft-ietf-httpbis-p6-cache-05</a></li>
617               <li><a href="#rfc.section.C.8">C.8</a>&nbsp;&nbsp;&nbsp;<a href="#changes.since.06">Since draft-ietf-httpbis-p6-cache-06</a></li>
618               <li><a href="#rfc.section.C.9">C.9</a>&nbsp;&nbsp;&nbsp;<a href="#changes.since.07">Since draft-ietf-httpbis-p6-cache-07</a></li>
619               <li><a href="#rfc.section.C.10">C.10</a>&nbsp;&nbsp;&nbsp;<a href="#changes.since.08">Since draft-ietf-httpbis-p6-cache-08</a></li>
620               <li><a href="#rfc.section.C.11">C.11</a>&nbsp;&nbsp;&nbsp;<a href="#changes.since.09">Since draft-ietf-httpbis-p6-cache-09</a></li>
621               <li><a href="#rfc.section.C.12">C.12</a>&nbsp;&nbsp;&nbsp;<a href="#changes.since.10">Since draft-ietf-httpbis-p6-cache-10</a></li>
622               <li><a href="#rfc.section.C.13">C.13</a>&nbsp;&nbsp;&nbsp;<a href="#changes.since.11">Since draft-ietf-httpbis-p6-cache-11</a></li>
623               <li><a href="#rfc.section.C.14">C.14</a>&nbsp;&nbsp;&nbsp;<a href="#changes.since.12">Since draft-ietf-httpbis-p6-cache-12</a></li>
624               <li><a href="#rfc.section.C.15">C.15</a>&nbsp;&nbsp;&nbsp;<a href="#changes.since.13">Since draft-ietf-httpbis-p6-cache-13</a></li>
625            </ul>
626         </li>
627         <li><a href="#rfc.index">Index</a></li>
628         <li><a href="#rfc.authors">Authors' Addresses</a></li>
629      </ul>
630      <div id="caching">
631         <h1 id="rfc.section.1" class="np"><a href="#rfc.section.1">1.</a>&nbsp;<a href="#caching">Introduction</a></h1>
632         <p id="rfc.section.1.p.1">HTTP is typically used for distributed information systems, where performance can be improved by the use of response caches.
633            This document defines aspects of HTTP/1.1 related to caching and reusing response messages.
634         </p>
635         <div id="intro.purpose">
636            <div id="rfc.iref.c.1"></div>
637            <h2 id="rfc.section.1.1"><a href="#rfc.section.1.1">1.1</a>&nbsp;<a href="#intro.purpose">Purpose</a></h2>
638            <p id="rfc.section.1.1.p.1">An HTTP <dfn>cache</dfn> is a local store of response messages and the subsystem that controls its message storage, retrieval, and deletion. A cache
639               stores cacheable responses in order to reduce the response time and network bandwidth consumption on future, equivalent requests.
640               Any client or server <em class="bcp14">MAY</em> employ a cache, though a cache cannot be used by a server that is acting as a tunnel.
641            </p>
642            <p id="rfc.section.1.1.p.2">Caching would be useless if it did not significantly improve performance. The goal of caching in HTTP/1.1 is to reuse a prior
643               response message to satisfy a current request. In some cases, a stored response can be reused without the need for a network
644               request, reducing latency and network round-trips; a "freshness" mechanism is used for this purpose (see <a href="#expiration.model" title="Freshness Model">Section&nbsp;2.3</a>). Even when a new request is required, it is often possible to reuse all or parts of the payload of a prior response to satisfy
645               the request, thereby reducing network bandwidth usage; a "validation" mechanism is used for this purpose (see <a href="#validation.model" title="Validation Model">Section&nbsp;2.4</a>).
646            </p>
647         </div>
648         <div id="intro.terminology">
649            <h2 id="rfc.section.1.2"><a href="#rfc.section.1.2">1.2</a>&nbsp;<a href="#intro.terminology">Terminology</a></h2>
650            <p id="rfc.section.1.2.p.1">This specification uses a number of terms to refer to the roles played by participants in, and objects of, HTTP caching.</p>
651            <p id="rfc.section.1.2.p.2"><span id="rfc.iref.c.2"></span> <dfn>cache</dfn>
652            </p>
653            <ul class="empty">
654               <li>A conformant implementation of a HTTP cache. Note that this implies an HTTP/1.1 cache; this specification does not define
655                  conformance for HTTP/1.0 caches.
656               </li>
657            </ul>
658            <div id="shared.and.non-shared.caches">
659               <p id="rfc.section.1.2.p.3"><span id="rfc.iref.s.1"></span> <dfn>shared cache</dfn>
660               </p>
661               <ul class="empty">
662                  <li>A cache that is accessible to more than one user; usually (but not always) deployed as part of an intermediary.</li>
663               </ul>
664            </div>
665            <p id="rfc.section.1.2.p.4"><span id="rfc.iref.p.1"></span> <dfn>private cache</dfn>
666            </p>
667            <ul class="empty">
668               <li>A cache that is dedicated to a single user.</li>
669            </ul>
670            <p id="rfc.section.1.2.p.5"><span id="rfc.iref.c.3"></span> <dfn>cacheable</dfn>
671            </p>
672            <ul class="empty">
673               <li>A response is cacheable if a cache is allowed to store a copy of the response message for use in answering subsequent requests.
674                  Even when a response is cacheable, there might be additional constraints on whether a cache can use the stored copy to satisfy
675                  a particular request.
676               </li>
677            </ul>
678            <p id="rfc.section.1.2.p.6"><span id="rfc.iref.e.1"></span> <dfn>explicit expiration time</dfn>
679            </p>
680            <ul class="empty">
681               <li>The time at which the origin server intends that a representation no longer be returned by a cache without further validation.</li>
682            </ul>
683            <p id="rfc.section.1.2.p.7"><span id="rfc.iref.h.1"></span> <dfn>heuristic expiration time</dfn>
684            </p>
685            <ul class="empty">
686               <li>An expiration time assigned by a cache when no explicit expiration time is available.</li>
687            </ul>
688            <p id="rfc.section.1.2.p.8"><span id="rfc.iref.a.1"></span> <dfn>age</dfn>
689            </p>
690            <ul class="empty">
691               <li>The age of a response is the time since it was sent by, or successfully validated with, the origin server.</li>
692            </ul>
693            <p id="rfc.section.1.2.p.9"><span id="rfc.iref.f.1"></span> <dfn>first-hand</dfn>
694            </p>
695            <ul class="empty">
696               <li>A response is first-hand if the freshness model is not in use; i.e., its age is 0.</li>
697            </ul>
698            <p id="rfc.section.1.2.p.10"><span id="rfc.iref.f.2"></span> <dfn>freshness lifetime</dfn>
699            </p>
700            <ul class="empty">
701               <li>The length of time between the generation of a response and its expiration time.</li>
702            </ul>
703            <p id="rfc.section.1.2.p.11"><span id="rfc.iref.f.3"></span> <dfn>fresh</dfn>
704            </p>
705            <ul class="empty">
706               <li>A response is fresh if its age has not yet exceeded its freshness lifetime.</li>
707            </ul>
708            <p id="rfc.section.1.2.p.12"><span id="rfc.iref.s.2"></span> <dfn>stale</dfn>
709            </p>
710            <ul class="empty">
711               <li>A response is stale if its age has passed its freshness lifetime (either explicit or heuristic).</li>
712            </ul>
713            <p id="rfc.section.1.2.p.13"><span id="rfc.iref.v.1"></span> <dfn>validator</dfn>
714            </p>
715            <ul class="empty">
716               <li>A protocol element (e.g., an entity-tag or a Last-Modified time) that is used to find out whether a stored response is an
717                  equivalent copy of a representation.
718               </li>
719            </ul>
720         </div>
721         <div id="intro.requirements">
722            <h2 id="rfc.section.1.3"><a href="#rfc.section.1.3">1.3</a>&nbsp;<a href="#intro.requirements">Requirements</a></h2>
723            <p id="rfc.section.1.3.p.1">The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "MAY", and "OPTIONAL"
724               in this document are to be interpreted as described in <a href="#RFC2119" id="rfc.xref.RFC2119.1"><cite title="Key words for use in RFCs to Indicate Requirement Levels">[RFC2119]</cite></a>.
725            </p>
726            <p id="rfc.section.1.3.p.2">An implementation is not compliant if it fails to satisfy one or more of the "MUST" or "REQUIRED" level requirements for the
727               protocols it implements. An implementation that satisfies all the "MUST" or "REQUIRED" level and all the "SHOULD" level requirements
728               for its protocols is said to be "unconditionally compliant"; one that satisfies all the "MUST" level requirements but not
729               all the "SHOULD" level requirements for its protocols is said to be "conditionally compliant".
730            </p>
731         </div>
732         <div id="notation">
733            <h2 id="rfc.section.1.4"><a href="#rfc.section.1.4">1.4</a>&nbsp;<a href="#notation">Syntax Notation</a></h2>
734            <p id="rfc.section.1.4.p.1">This specification uses the ABNF syntax defined in <a href="p1-messaging.html#notation" title="Syntax Notation">Section 1.2</a> of <a href="#Part1" id="rfc.xref.Part1.1"><cite title="HTTP/1.1, part 1: URIs, Connections, and Message Parsing">[Part1]</cite></a> (which extends the syntax defined in <a href="#RFC5234" id="rfc.xref.RFC5234.1"><cite title="Augmented BNF for Syntax Specifications: ABNF">[RFC5234]</cite></a> with a list rule). <a href="#collected.abnf" title="Collected ABNF">Appendix&nbsp;B</a> shows the collected ABNF, with the list rule expanded.
735            </p>
736            <p id="rfc.section.1.4.p.2">The following core rules are included by reference, as defined in <a href="#RFC5234" id="rfc.xref.RFC5234.2"><cite title="Augmented BNF for Syntax Specifications: ABNF">[RFC5234]</cite></a>, <a href="">Appendix B.1</a>: ALPHA (letters), CR (carriage return), CRLF (CR LF), CTL (controls), DIGIT (decimal 0-9), DQUOTE (double quote), HEXDIG
737               (hexadecimal 0-9/A-F/a-f), LF (line feed), OCTET (any 8-bit sequence of data), SP (space), VCHAR (any visible USASCII character),
738               and WSP (whitespace).
739            </p>
740            <div id="core.rules">
741               <h3 id="rfc.section.1.4.1"><a href="#rfc.section.1.4.1">1.4.1</a>&nbsp;<a href="#core.rules">Core Rules</a></h3>
742               <p id="rfc.section.1.4.1.p.1">The core rules below are defined in <a href="p1-messaging.html#basic.rules" title="Basic Rules">Section 1.2.2</a> of <a href="#Part1" id="rfc.xref.Part1.2"><cite title="HTTP/1.1, part 1: URIs, Connections, and Message Parsing">[Part1]</cite></a>:
743               </p>
744               <div id="rfc.figure.u.1"></div><pre class="inline">  <a href="#core.rules" class="smpl">quoted-string</a> = &lt;quoted-string, defined in <a href="#Part1" id="rfc.xref.Part1.3"><cite title="HTTP/1.1, part 1: URIs, Connections, and Message Parsing">[Part1]</cite></a>, <a href="p1-messaging.html#basic.rules" title="Basic Rules">Section 1.2.2</a>&gt;
745  <a href="#core.rules" class="smpl">token</a>         = &lt;token, defined in <a href="#Part1" id="rfc.xref.Part1.4"><cite title="HTTP/1.1, part 1: URIs, Connections, and Message Parsing">[Part1]</cite></a>, <a href="p1-messaging.html#basic.rules" title="Basic Rules">Section 1.2.2</a>&gt;
746  <a href="#core.rules" class="smpl">OWS</a>           = &lt;OWS, defined in <a href="#Part1" id="rfc.xref.Part1.5"><cite title="HTTP/1.1, part 1: URIs, Connections, and Message Parsing">[Part1]</cite></a>, <a href="p1-messaging.html#basic.rules" title="Basic Rules">Section 1.2.2</a>&gt;
748            <div id="abnf.dependencies">
749               <h3 id="rfc.section.1.4.2"><a href="#rfc.section.1.4.2">1.4.2</a>&nbsp;<a href="#abnf.dependencies">ABNF Rules defined in other Parts of the Specification</a></h3>
750               <p id="rfc.section.1.4.2.p.1">The ABNF rules below are defined in other parts:</p>
751               <div id="rfc.figure.u.2"></div><pre class="inline">  <a href="#abnf.dependencies" class="smpl">field-name</a>    = &lt;field-name, defined in <a href="#Part1" id="rfc.xref.Part1.6"><cite title="HTTP/1.1, part 1: URIs, Connections, and Message Parsing">[Part1]</cite></a>, <a href="p1-messaging.html#header.fields" title="Header Fields">Section 3.2</a>&gt;
752  <a href="#abnf.dependencies" class="smpl">HTTP-date</a>     = &lt;HTTP-date, defined in <a href="#Part1" id="rfc.xref.Part1.7"><cite title="HTTP/1.1, part 1: URIs, Connections, and Message Parsing">[Part1]</cite></a>, <a href="" title="Date/Time Formats: Full Date">Section 6.1</a>&gt;
753  <a href="#abnf.dependencies" class="smpl">port</a>          = &lt;port, defined in <a href="#Part1" id="rfc.xref.Part1.8"><cite title="HTTP/1.1, part 1: URIs, Connections, and Message Parsing">[Part1]</cite></a>, <a href="p1-messaging.html#uri" title="Uniform Resource Identifiers">Section 2.6</a>&gt;
754  <a href="#abnf.dependencies" class="smpl">pseudonym</a>     = &lt;pseudonym, defined in <a href="#Part1" id="rfc.xref.Part1.9"><cite title="HTTP/1.1, part 1: URIs, Connections, and Message Parsing">[Part1]</cite></a>, <a href="p1-messaging.html#header.via" title="Via">Section 9.9</a>&gt;
755  <a href="#abnf.dependencies" class="smpl">uri-host</a>      = &lt;uri-host, defined in <a href="#Part1" id="rfc.xref.Part1.10"><cite title="HTTP/1.1, part 1: URIs, Connections, and Message Parsing">[Part1]</cite></a>, <a href="p1-messaging.html#uri" title="Uniform Resource Identifiers">Section 2.6</a>&gt;
757         </div>
758      </div>
759      <div id="caching.overview">
760         <h1 id="rfc.section.2"><a href="#rfc.section.2">2.</a>&nbsp;<a href="#caching.overview">Cache Operation</a></h1>
761         <div id="response.cacheability">
762            <h2 id="rfc.section.2.1"><a href="#rfc.section.2.1">2.1</a>&nbsp;<a href="#response.cacheability">Response Cacheability</a></h2>
763            <p id="rfc.section.2.1.p.1">A cache <em class="bcp14">MUST NOT</em> store a response to any request, unless:
764            </p>
765            <ul>
766               <li>The request method is understood by the cache and defined as being cacheable, and</li>
767               <li>the response status code is understood by the cache, and</li>
768               <li>the "no-store" cache directive (see <a href="#header.cache-control" id="rfc.xref.header.cache-control.1" title="Cache-Control">Section&nbsp;3.2</a>) does not appear in request or response header fields, and
769               </li>
770               <li>the "private" cache response directive (see <a href="#cache-response-directive" title="Response Cache-Control Directives">Section&nbsp;3.2.2</a> does not appear in the response, if the cache is shared, and
771               </li>
772               <li>the "Authorization" header field (see <a href="p7-auth.html#header.authorization" title="Authorization">Section 4.1</a> of <a href="#Part7" id="rfc.xref.Part7.1"><cite title="HTTP/1.1, part 7: Authentication">[Part7]</cite></a>) does not appear in the request, if the cache is shared, unless the response explicitly allows it (see <a href="#caching.authenticated.responses" title="Shared Caching of Authenticated Responses">Section&nbsp;2.6</a>), and
773               </li>
774               <li>the response either:
775                  <ul>
776                     <li>contains an Expires header field (see <a href="#header.expires" id="rfc.xref.header.expires.1" title="Expires">Section&nbsp;3.3</a>), or
777                     </li>
778                     <li>contains a max-age response cache directive (see <a href="#cache-response-directive" title="Response Cache-Control Directives">Section&nbsp;3.2.2</a>), or
779                     </li>
780                     <li>contains a s-maxage response cache directive and the cache is shared, or</li>
781                     <li>contains a Cache Control Extension (see <a href="#cache.control.extensions" title="Cache Control Extensions">Section&nbsp;3.2.3</a>) that allows it to be cached, or
782                     </li>
783                     <li>has a status code that can be served with heuristic freshness (see <a href="#heuristic.freshness" title="Calculating Heuristic Freshness">Section&nbsp;</a>).
784                     </li>
785                  </ul>
786               </li>
787            </ul>
788            <p id="rfc.section.2.1.p.2">In this context, a cache has "understood" a request method or a response status code if it recognises it and implements any
789               cache-specific behaviour. In particular, 206 Partial Content responses cannot be cached by an implementation that does not
790               handle partial content (see <a href="#errors.or.incomplete.response.cache.behavior" title="Storing Partial and Incomplete Responses">Section&nbsp;2.1.1</a>).
791            </p>
792            <p id="rfc.section.2.1.p.3">Note that in normal operation, most caches will not store a response that has neither a cache validator nor an explicit expiration
793               time, as such responses are not usually useful to store. However, caches are not prohibited from storing such responses.
794            </p>
795            <div id="errors.or.incomplete.response.cache.behavior">
796               <h3 id="rfc.section.2.1.1"><a href="#rfc.section.2.1.1">2.1.1</a>&nbsp;<a href="#errors.or.incomplete.response.cache.behavior">Storing Partial and Incomplete Responses</a></h3>
797               <p id="rfc.section.2.1.1.p.1">A cache that receives an incomplete response (for example, with fewer bytes of data than specified in a Content-Length header
798                  field) can store the response, but <em class="bcp14">MUST</em> treat it as a partial response <a href="#Part5" id="rfc.xref.Part5.1"><cite title="HTTP/1.1, part 5: Range Requests and Partial Responses">[Part5]</cite></a>. Partial responses can be combined as described in <a href="p5-range.html#combining.byte.ranges" title="Combining Ranges">Section 4</a> of <a href="#Part5" id="rfc.xref.Part5.2"><cite title="HTTP/1.1, part 5: Range Requests and Partial Responses">[Part5]</cite></a>; the result might be a full response or might still be partial. A cache <em class="bcp14">MUST NOT</em> return a partial response to a client without explicitly marking it as such using the 206 (Partial Content) status code.
799               </p>
800               <p id="rfc.section.2.1.1.p.2">A cache that does not support the Range and Content-Range header fields <em class="bcp14">MUST NOT</em> store incomplete or partial responses.
801               </p>
802            </div>
803         </div>
804         <div id="constructing.responses.from.caches">
805            <h2 id="rfc.section.2.2"><a href="#rfc.section.2.2">2.2</a>&nbsp;<a href="#constructing.responses.from.caches">Constructing Responses from Caches</a></h2>
806            <p id="rfc.section.2.2.p.1">For a presented request, a cache <em class="bcp14">MUST NOT</em> return a stored response, unless:
807            </p>
808            <ul>
809               <li>The presented effective request URI (<a href="p1-messaging.html#effective.request.uri" title="Effective Request URI">Section 4.3</a> of <a href="#Part1" id="rfc.xref.Part1.11"><cite title="HTTP/1.1, part 1: URIs, Connections, and Message Parsing">[Part1]</cite></a>) and that of the stored response match, and
810               </li>
811               <li>the request method associated with the stored response allows it to be used for the presented request, and</li>
812               <li>selecting header fields nominated by the stored response (if any) match those presented (see <a href="#caching.negotiated.responses" title="Caching Negotiated Responses">Section&nbsp;2.7</a>), and
813               </li>
814               <li>the presented request and stored response are free from directives that would prevent its use (see <a href="#header.cache-control" id="rfc.xref.header.cache-control.2" title="Cache-Control">Section&nbsp;3.2</a> and <a href="#header.pragma" id="rfc.xref.header.pragma.1" title="Pragma">Section&nbsp;3.4</a>), and
815               </li>
816               <li>the stored response is either:
817                  <ul>
818                     <li>fresh (see <a href="#expiration.model" title="Freshness Model">Section&nbsp;2.3</a>), or
819                     </li>
820                     <li>allowed to be served stale (see <a href="#serving.stale.responses" title="Serving Stale Responses">Section&nbsp;2.3.3</a>), or
821                     </li>
822                     <li>successfully validated (see <a href="#validation.model" title="Validation Model">Section&nbsp;2.4</a>).
823                     </li>
824                  </ul>
825               </li>
826            </ul>
827            <p id="rfc.section.2.2.p.2">When a stored response is used to satisfy a request without validation, a cache <em class="bcp14">MUST</em> include a single Age header field (<a href="#header.age" id="rfc.xref.header.age.1" title="Age">Section&nbsp;3.1</a>) in the response with a value equal to the stored response's current_age; see <a href="#age.calculations" title="Calculating Age">Section&nbsp;2.3.2</a>.
828            </p>
829            <p id="rfc.section.2.2.p.3">A cache <em class="bcp14">MUST</em> write through requests with methods that are unsafe (<a href="p2-semantics.html#safe.methods" title="Safe Methods">Section 7.1.1</a> of <a href="#Part2" id="rfc.xref.Part2.1"><cite title="HTTP/1.1, part 2: Message Semantics">[Part2]</cite></a>) to the origin server; i.e., a cache must not generate a reply to such a request before having forwarded the request and
830               having received a corresponding response.
831            </p>
832            <p id="rfc.section.2.2.p.4">Also, note that unsafe requests might invalidate already stored responses; see <a href="#invalidation.after.updates.or.deletions" title="Request Methods that Invalidate">Section&nbsp;2.5</a>.
833            </p>
834            <p id="rfc.section.2.2.p.5">A cache <em class="bcp14">MUST</em> use the most recent response (as determined by the Date header field) when more than one suitable response is stored. It can
835               also forward a request with "Cache-Control: max-age=0" or "Cache-Control: no-cache" to disambiguate which response to use.
836            </p>
837            <p id="rfc.section.2.2.p.6">A cache that does not have a clock available <em class="bcp14">MUST NOT</em> use stored responses without revalidating them on every use. A cache, especially a shared cache, <em class="bcp14">SHOULD</em> use a mechanism, such as NTP <a href="#RFC1305" id="rfc.xref.RFC1305.1"><cite title="Network Time Protocol (Version 3) Specification, Implementation">[RFC1305]</cite></a>, to synchronize its clock with a reliable external standard.
838            </p>
839         </div>
840         <div id="expiration.model">
841            <h2 id="rfc.section.2.3"><a href="#rfc.section.2.3">2.3</a>&nbsp;<a href="#expiration.model">Freshness Model</a></h2>
842            <p id="rfc.section.2.3.p.1">When a response is "fresh" in the cache, it can be used to satisfy subsequent requests without contacting the origin server,
843               thereby improving efficiency.
844            </p>
845            <p id="rfc.section.2.3.p.2">The primary mechanism for determining freshness is for an origin server to provide an explicit expiration time in the future,
846               using either the Expires header field (<a href="#header.expires" id="rfc.xref.header.expires.2" title="Expires">Section&nbsp;3.3</a>) or the max-age response cache directive (<a href="#cache-response-directive" title="Response Cache-Control Directives">Section&nbsp;3.2.2</a>). Generally, origin servers will assign future explicit expiration times to responses in the belief that the representation
847               is not likely to change in a semantically significant way before the expiration time is reached.
848            </p>
849            <p id="rfc.section.2.3.p.3">If an origin server wishes to force a cache to validate every request, it can assign an explicit expiration time in the past
850               to indicate that the response is already stale. Compliant caches will normally validate the cached response before reusing
851               it for subsequent requests (see <a href="#serving.stale.responses" title="Serving Stale Responses">Section&nbsp;2.3.3</a>).
852            </p>
853            <p id="rfc.section.2.3.p.4">Since origin servers do not always provide explicit expiration times, a cache <em class="bcp14">MAY</em> assign a heuristic expiration time when an explicit time is not specified, employing algorithms that use other header field
854               values (such as the Last-Modified time) to estimate a plausible expiration time. This specification does not provide specific
855               algorithms, but does impose worst-case constraints on their results.
856            </p>
857            <div id="rfc.figure.u.3"></div>
858            <p>The calculation to determine if a response is fresh is:</p><pre class="text">   response_is_fresh = (freshness_lifetime &gt; current_age)
859</pre><p id="rfc.section.2.3.p.6">The freshness_lifetime is defined in <a href="#calculating.freshness.lifetime" title="Calculating Freshness Lifetime">Section&nbsp;2.3.1</a>; the current_age is defined in <a href="#age.calculations" title="Calculating Age">Section&nbsp;2.3.2</a>.
860            </p>
861            <p id="rfc.section.2.3.p.7">Additionally, clients might need to influence freshness calculation. They can do this using several request cache directives,
862               with the effect of either increasing or loosening constraints on freshness. See <a href="#cache-request-directive" title="Request Cache-Control Directives">Section&nbsp;3.2.1</a>.
863            </p>
864            <p id="rfc.section.2.3.p.8"><span class="comment" id="ISSUE-no-req-for-directives">[<a href="#ISSUE-no-req-for-directives" class="smpl">ISSUE-no-req-for-directives</a>: there are not requirements directly applying to cache-request-directives and freshness.]</span>
865            </p>
866            <p id="rfc.section.2.3.p.9">Note that freshness applies only to cache operation; it cannot be used to force a user agent to refresh its display or reload
867               a resource. See <a href="#history.lists" title="History Lists">Section&nbsp;4</a> for an explanation of the difference between caches and history mechanisms.
868            </p>
869            <div id="calculating.freshness.lifetime">
870               <h3 id="rfc.section.2.3.1"><a href="#rfc.section.2.3.1">2.3.1</a>&nbsp;<a href="#calculating.freshness.lifetime">Calculating Freshness Lifetime</a></h3>
871               <p id="rfc.section.2.3.1.p.1">A cache can calculate the freshness lifetime (denoted as freshness_lifetime) of a response by using the first match of: </p>
872               <ul>
873                  <li>If the cache is shared and the s-maxage response cache directive (<a href="#cache-response-directive" title="Response Cache-Control Directives">Section&nbsp;3.2.2</a>) is present, use its value, or
874                  </li>
875                  <li>If the max-age response cache directive (<a href="#cache-response-directive" title="Response Cache-Control Directives">Section&nbsp;3.2.2</a>) is present, use its value, or
876                  </li>
877                  <li>If the Expires response header field (<a href="#header.expires" id="rfc.xref.header.expires.3" title="Expires">Section&nbsp;3.3</a>) is present, use its value minus the value of the Date response header field, or
878                  </li>
879                  <li>Otherwise, no explicit expiration time is present in the response. A heuristic freshness lifetime might be applicable; see <a href="#heuristic.freshness" title="Calculating Heuristic Freshness">Section&nbsp;</a>.
880                  </li>
881               </ul>
882               <p id="rfc.section.2.3.1.p.2">Note that this calculation is not vulnerable to clock skew, since all of the information comes from the origin server.</p>
883               <div id="heuristic.freshness">
884                  <h4 id="rfc.section."><a href="#rfc.section."></a>&nbsp;<a href="#heuristic.freshness">Calculating Heuristic Freshness</a></h4>
885                  <p id="rfc.section.">If no explicit expiration time is present in a stored response that has a status code whose definition allows heuristic freshness
886                     to be used (including the following in <a href="" title="Status Code Definitions">Section 8</a> of <a href="#Part2" id="rfc.xref.Part2.2"><cite title="HTTP/1.1, part 2: Message Semantics">[Part2]</cite></a>: 200, 203, 206, 300, 301 and 410), a cache <em class="bcp14">MAY</em> calculate a heuristic expiration time. A cache <em class="bcp14">MUST NOT</em> use heuristics to determine freshness for responses with status codes that do not explicitly allow it.
887                  </p>
888                  <p id="rfc.section.">When a heuristic is used to calculate freshness lifetime, a cache <em class="bcp14">SHOULD</em> attach a Warning header field with a 113 warn-code to the response if its current_age is more than 24 hours and such a warning
889                     is not already present.
890                  </p>
891                  <p id="rfc.section.">Also, if the response has a Last-Modified header field (<a href="p4-conditional.html#header.last-modified" title="Last-Modified">Section 2.1</a> of <a href="#Part4" id="rfc.xref.Part4.1"><cite title="HTTP/1.1, part 4: Conditional Requests">[Part4]</cite></a>), a cache <em class="bcp14">SHOULD NOT</em> use a heuristic expiration value that is more than some fraction of the interval since that time. A typical setting of this
892                     fraction might be 10%.
893                  </p>
894                  <div class="note" id="rfc.section.">
895                     <p><b>Note:</b> RFC 2616 (<a href="#RFC2616" id="rfc.xref.RFC2616.1"><cite title="Hypertext Transfer Protocol -- HTTP/1.1">[RFC2616]</cite></a>, <a href="">Section 13.9</a>) required that caches do not calculate heuristic freshness for URIs with query components (i.e., those containing '?'). In
896                        practice, this has not been widely implemented. Therefore, servers are encouraged to send explicit directives (e.g., Cache-Control:
897                        no-cache) if they wish to preclude caching.
898                     </p>
899                  </div>
900               </div>
901            </div>
902            <div id="age.calculations">
903               <h3 id="rfc.section.2.3.2"><a href="#rfc.section.2.3.2">2.3.2</a>&nbsp;<a href="#age.calculations">Calculating Age</a></h3>
904               <p id="rfc.section.2.3.2.p.1">HTTP/1.1 uses the Age header field to convey the estimated age of the response message when obtained from a cache. The Age
905                  field value is the cache's estimate of the amount of time since the response was generated or validated by the origin server.
906                  In essence, the Age value is the sum of the time that the response has been resident in each of the caches along the path
907                  from the origin server, plus the amount of time it has been in transit along network paths.
908               </p>
909               <p id="rfc.section.2.3.2.p.2">The following data is used for the age calculation:</p>
910               <p id="rfc.section.2.3.2.p.3"><dfn>age_value</dfn>
911               </p>
912               <ul class="empty">
913                  <li>The term "age_value" denotes the value of the Age header field (<a href="#header.age" id="rfc.xref.header.age.2" title="Age">Section&nbsp;3.1</a>), in a form appropriate for arithmetic operation; or 0, if not available.
914                  </li>
915               </ul>
916               <p id="rfc.section.2.3.2.p.4"><dfn>date_value</dfn>
917               </p>
918               <ul class="empty">
919                  <li>HTTP/1.1 requires origin servers to send a Date header field, if possible, with every response, giving the time at which the
920                     response was generated. The term "date_value" denotes the value of the Date header field, in a form appropriate for arithmetic
921                     operations. See <a href="" title="Date">Section 9.3</a> of <a href="#Part1" id="rfc.xref.Part1.12"><cite title="HTTP/1.1, part 1: URIs, Connections, and Message Parsing">[Part1]</cite></a> for the definition of the Date header field, and for requirements regarding responses without it.
922                  </li>
923               </ul>
924               <p id="rfc.section.2.3.2.p.5"><dfn>now</dfn>
925               </p>
926               <ul class="empty">
927                  <li>The term "now" means "the current value of the clock at the host performing the calculation". A cache <em class="bcp14">SHOULD</em> use NTP (<a href="#RFC1305" id="rfc.xref.RFC1305.2"><cite title="Network Time Protocol (Version 3) Specification, Implementation">[RFC1305]</cite></a>) or some similar protocol to synchronize its clocks to a globally accurate time standard.
928                  </li>
929               </ul>
930               <p id="rfc.section.2.3.2.p.6"><dfn>request_time</dfn>
931               </p>
932               <ul class="empty">
933                  <li>The current value of the clock at the host at the time the request resulting in the stored response was made.</li>
934               </ul>
935               <p id="rfc.section.2.3.2.p.7"><dfn>response_time</dfn>
936               </p>
937               <ul class="empty">
938                  <li>The current value of the clock at the host at the time the response was received.</li>
939               </ul>
940               <p id="rfc.section.2.3.2.p.8">A response's age can be calculated in two entirely independent ways: </p>
941               <ol>
942                  <li>the "apparent_age": response_time minus date_value, if the local clock is reasonably well synchronized to the origin server's
943                     clock. If the result is negative, the result is replaced by zero.
944                  </li>
945                  <li>the "corrected_age_value", if all of the caches along the response path implement HTTP/1.1. A cache <em class="bcp14">MUST</em> interpret this value relative to the time the request was initiated, not the time that the response was received.
946                  </li>
947               </ol>
948               <div id="rfc.figure.u.4"></div><pre class="text">  apparent_age = max(0, response_time - date_value);
950  response_delay = response_time - request_time;
951  corrected_age_value = age_value + response_delay; 
952</pre><div id="rfc.figure.u.5"></div>
953               <p>These are combined as</p><pre class="text">  corrected_initial_age = max(apparent_age, corrected_age_value);
954</pre><p id="rfc.section.2.3.2.p.11">The current_age of a stored response can then be calculated by adding the amount of time (in seconds) since the stored response
955                  was last validated by the origin server to the corrected_initial_age.
956               </p>
957               <div id="rfc.figure.u.6"></div><pre class="text">  resident_time = now - response_time;
958  current_age = corrected_initial_age + resident_time;
960            <div id="serving.stale.responses">
961               <h3 id="rfc.section.2.3.3"><a href="#rfc.section.2.3.3">2.3.3</a>&nbsp;<a href="#serving.stale.responses">Serving Stale Responses</a></h3>
962               <p id="rfc.section.2.3.3.p.1">A "stale" response is one that either has explicit expiry information or is allowed to have heuristic expiry calculated, but
963                  is not fresh according to the calculations in <a href="#expiration.model" title="Freshness Model">Section&nbsp;2.3</a>.
964               </p>
965               <p id="rfc.section.2.3.3.p.2">A cache <em class="bcp14">MUST NOT</em> return a stale response if it is prohibited by an explicit in-protocol directive (e.g., by a "no-store" or "no-cache" cache
966                  directive, a "must-revalidate" cache-response-directive, or an applicable "s-maxage" or "proxy-revalidate" cache-response-directive;
967                  see <a href="#cache-response-directive" title="Response Cache-Control Directives">Section&nbsp;3.2.2</a>).
968               </p>
969               <p id="rfc.section.2.3.3.p.3">A cache <em class="bcp14">SHOULD NOT</em> return stale responses unless it is disconnected (i.e., it cannot contact the origin server or otherwise find a forward path)
970                  or doing so is explicitly allowed (e.g., by the max-stale request directive; see <a href="#cache-request-directive" title="Request Cache-Control Directives">Section&nbsp;3.2.1</a>).
971               </p>
972               <p id="rfc.section.2.3.3.p.4">A cache <em class="bcp14">SHOULD</em> append a Warning header field with the 110 warn-code (see <a href="#header.warning" id="rfc.xref.header.warning.1" title="Warning">Section&nbsp;3.6</a>) to stale responses. Likewise, a cache <em class="bcp14">SHOULD</em> add the 112 warn-code to stale responses if the cache is disconnected.
973               </p>
974               <p id="rfc.section.2.3.3.p.5">If a cache receives a first-hand response (either an entire response, or a 304 (Not Modified) response) that it would normally
975                  forward to the requesting client, and the received response is no longer fresh, the cache <em class="bcp14">SHOULD</em> forward it to the requesting client without adding a new Warning (but without removing any existing Warning header fields).
976                  A cache <em class="bcp14">SHOULD NOT</em> attempt to validate a response simply because that response became stale in transit.
977               </p>
978            </div>
979         </div>
980         <div id="validation.model">
981            <h2 id="rfc.section.2.4"><a href="#rfc.section.2.4">2.4</a>&nbsp;<a href="#validation.model">Validation Model</a></h2>
982            <p id="rfc.section.2.4.p.1">When a cache has one or more stored responses for a requested URI, but cannot serve any of them (e.g., because they are not
983               fresh, or one cannot be selected; see <a href="#caching.negotiated.responses" title="Caching Negotiated Responses">Section&nbsp;2.7</a>), it can use the conditional request mechanism <a href="#Part4" id="rfc.xref.Part4.2"><cite title="HTTP/1.1, part 4: Conditional Requests">[Part4]</cite></a> in the forwarded request to give the origin server an opportunity to both select a valid stored response to be used, and to
984               update it. This process is known as "validating" or "revalidating" the stored response.
985            </p>
986            <p id="rfc.section.2.4.p.2">When sending such a conditional request, a cache <em class="bcp14">SHOULD</em> add an If-Modified-Since header field whose value is that of the Last-Modified header field from the selected (see <a href="#caching.negotiated.responses" title="Caching Negotiated Responses">Section&nbsp;2.7</a>) stored response, if available.
987            </p>
988            <p id="rfc.section.2.4.p.3">Additionally, a cache <em class="bcp14">SHOULD</em> add an If-None-Match header field whose value is that of the ETag header field(s) from all responses stored for the requested
989               URI, if present. However, if any of the stored responses contains only partial content, the cache <em class="bcp14">SHOULD NOT</em> include its entity-tag in the If-None-Match header field unless the request is for a range that would be fully satisfied by
990               that stored response.
991            </p>
992            <p id="rfc.section.2.4.p.4">A 304 (Not Modified) response status code indicates that the stored response can be updated and reused; see <a href="#combining.responses" title="Combining Responses">Section&nbsp;2.8</a>.
993            </p>
994            <p id="rfc.section.2.4.p.5">A full response (i.e., one with a response body) indicates that none of the stored responses nominated in the conditional
995               request is suitable. Instead, a cache <em class="bcp14">SHOULD</em> use the full response to satisfy the request and <em class="bcp14">MAY</em> replace the stored response.
996            </p>
997            <p id="rfc.section.2.4.p.6">If a cache receives a 5xx response while attempting to validate a response, it <em class="bcp14">MAY</em> either forward this response to the requesting client, or act as if the server failed to respond. In the latter case, it <em class="bcp14">MAY</em> return a previously stored response (see <a href="#serving.stale.responses" title="Serving Stale Responses">Section&nbsp;2.3.3</a>).
998            </p>
999         </div>
1000         <div id="invalidation.after.updates.or.deletions">
1001            <h2 id="rfc.section.2.5"><a href="#rfc.section.2.5">2.5</a>&nbsp;<a href="#invalidation.after.updates.or.deletions">Request Methods that Invalidate</a></h2>
1002            <p id="rfc.section.2.5.p.1">Because unsafe request methods (<a href="p2-semantics.html#safe.methods" title="Safe Methods">Section 7.1.1</a> of <a href="#Part2" id="rfc.xref.Part2.3"><cite title="HTTP/1.1, part 2: Message Semantics">[Part2]</cite></a>) have the potential for changing state on the origin server, intervening caches can use them to keep their contents up-to-date.
1003            </p>
1004            <p id="rfc.section.2.5.p.2">A cache <em class="bcp14">MUST</em> invalidate the effective Request URI (<a href="p1-messaging.html#effective.request.uri" title="Effective Request URI">Section 4.3</a> of <a href="#Part1" id="rfc.xref.Part1.13"><cite title="HTTP/1.1, part 1: URIs, Connections, and Message Parsing">[Part1]</cite></a>) as well as the URI(s) in the Location and Content-Location header fields (if present) when the following request methods
1005               are received:
1006            </p>
1007            <ul>
1008               <li>PUT</li>
1009               <li>DELETE</li>
1010               <li>POST</li>
1011            </ul>
1012            <p id="rfc.section.2.5.p.3">However, a cache <em class="bcp14">MUST NOT</em> invalidate a URI from a Location or Content-Location header field if the host part of that URI differs from the host part
1013               in the effective request URI (<a href="p1-messaging.html#effective.request.uri" title="Effective Request URI">Section 4.3</a> of <a href="#Part1" id="rfc.xref.Part1.14"><cite title="HTTP/1.1, part 1: URIs, Connections, and Message Parsing">[Part1]</cite></a>). This helps prevent denial of service attacks.
1014            </p>
1015            <p id="rfc.section.2.5.p.4">A cache that passes through requests with methods it does not understand <em class="bcp14">SHOULD</em> invalidate the effective request URI (<a href="p1-messaging.html#effective.request.uri" title="Effective Request URI">Section 4.3</a> of <a href="#Part1" id="rfc.xref.Part1.15"><cite title="HTTP/1.1, part 1: URIs, Connections, and Message Parsing">[Part1]</cite></a>).
1016            </p>
1017            <p id="rfc.section.2.5.p.5">Here, "invalidate" means that the cache will either remove all stored responses related to the effective request URI, or will
1018               mark these as "invalid" and in need of a mandatory validation before they can be returned in response to a subsequent request.
1019            </p>
1020            <p id="rfc.section.2.5.p.6">Note that this does not guarantee that all appropriate responses are invalidated. For example, the request that caused the
1021               change at the origin server might not have gone through the cache where a response is stored.
1022            </p>
1023         </div>
1024         <div id="caching.authenticated.responses">
1025            <h2 id="rfc.section.2.6"><a href="#rfc.section.2.6">2.6</a>&nbsp;<a href="#caching.authenticated.responses">Shared Caching of Authenticated Responses</a></h2>
1026            <p id="rfc.section.2.6.p.1">A shared cache <em class="bcp14">MUST NOT</em> use a cached response to a request with an Authorization header field (<a href="p7-auth.html#header.authorization" title="Authorization">Section 4.1</a> of <a href="#Part7" id="rfc.xref.Part7.2"><cite title="HTTP/1.1, part 7: Authentication">[Part7]</cite></a>) to satisfy any subsequent request unless a cache directive that allows such responses to be stored is present in the response.
1027            </p>
1028            <p id="rfc.section.2.6.p.2">In this specification, the following Cache-Control response directives (<a href="#cache-response-directive" title="Response Cache-Control Directives">Section&nbsp;3.2.2</a>) have such an effect: must-revalidate, public, s-maxage.
1029            </p>
1030            <p id="rfc.section.2.6.p.3">Note that cached responses that contain the "must-revalidate" and/or "s-maxage" response directives are not allowed to be
1031               served stale (<a href="#serving.stale.responses" title="Serving Stale Responses">Section&nbsp;2.3.3</a>) by shared caches. In particular, a response with either "max-age=0, must-revalidate" or "s-maxage=0" cannot be used to satisfy
1032               a subsequent request without revalidating it on the origin server.
1033            </p>
1034         </div>
1035         <div id="caching.negotiated.responses">
1036            <h2 id="rfc.section.2.7"><a href="#rfc.section.2.7">2.7</a>&nbsp;<a href="#caching.negotiated.responses">Caching Negotiated Responses</a></h2>
1037            <p id="rfc.section.2.7.p.1">When a cache receives a request that can be satisfied by a stored response that has a Vary header field (<a href="#header.vary" id="rfc.xref.header.vary.1" title="Vary">Section&nbsp;3.5</a>), it <em class="bcp14">MUST NOT</em> use that response unless all of the selecting header fields nominated by the Vary header field match in both the original
1038               request (i.e., that associated with the stored response), and the presented request.
1039            </p>
1040            <p id="rfc.section.2.7.p.2">The selecting header fields from two requests are defined to match if and only if those in the first request can be transformed
1041               to those in the second request by applying any of the following:
1042            </p>
1043            <ul>
1044               <li>adding or removing whitespace, where allowed in the header field's syntax</li>
1045               <li>combining multiple header fields with the same field name (see <a href="p1-messaging.html#header.fields" title="Header Fields">Section 3.2</a> of <a href="#Part1" id="rfc.xref.Part1.16"><cite title="HTTP/1.1, part 1: URIs, Connections, and Message Parsing">[Part1]</cite></a>)
1046               </li>
1047               <li>normalizing both header field values in a way that is known to have identical semantics, according to the header field's specification
1048                  (e.g., re-ordering field values when order is not significant; case-normalization, where values are defined to be case-insensitive)
1049               </li>
1050            </ul>
1051            <p id="rfc.section.2.7.p.3">If (after any normalization that might take place) a header field is absent from a request, it can only match another request
1052               if it is also absent there.
1053            </p>
1054            <p id="rfc.section.2.7.p.4">A Vary header field-value of "*" always fails to match, and subsequent requests to that resource can only be properly interpreted
1055               by the origin server.
1056            </p>
1057            <p id="rfc.section.2.7.p.5">The stored response with matching selecting header fields is known as the selected response.</p>
1058            <p id="rfc.section.2.7.p.6">If no selected response is available, the cache <em class="bcp14">MAY</em> forward the presented request to the origin server in a conditional request; see <a href="#validation.model" title="Validation Model">Section&nbsp;2.4</a>.
1059            </p>
1060         </div>
1061         <div id="combining.responses">
1062            <h2 id="rfc.section.2.8"><a href="#rfc.section.2.8">2.8</a>&nbsp;<a href="#combining.responses">Combining Responses</a></h2>
1063            <p id="rfc.section.2.8.p.1">When a cache receives a 304 (Not Modified) response or a 206 (Partial Content) response (in this section, the "new" response"),
1064               it needs to create an updated response by combining the stored response with the new one, so that the updated response can
1065               be used to satisfy the request, and potentially update the cached response.
1066            </p>
1067            <p id="rfc.section.2.8.p.2">If the new response contains an ETag, it identifies the stored response to use. <span class="comment" id="TODO-mention-CL">[<a href="#TODO-mention-CL" class="smpl">TODO-mention-CL</a>: might need language about Content-Location here]</span><span class="comment" id="TODO-select-for-combine">[<a href="#TODO-select-for-combine" class="smpl">TODO-select-for-combine</a>: Shouldn't this be the selected response?]</span>
1068            </p>
1069            <p id="rfc.section.2.8.p.3">When the new response's status code is 206 (partial content), a cache <em class="bcp14">MUST NOT</em> combine it with the old response if either response does not have a validator, and <em class="bcp14">MUST NOT</em> combine it with the old response when those validators do not match with the strong comparison function (see <a href="p4-conditional.html#weak.and.strong.validators" title="Weak versus Strong">Section 2.2.2</a> of <a href="#Part4" id="rfc.xref.Part4.3"><cite title="HTTP/1.1, part 4: Conditional Requests">[Part4]</cite></a>).
1070            </p>
1071            <p id="rfc.section.2.8.p.4">The stored response header fields are used as those of the updated response, except that </p>
1072            <ul>
1073               <li>a cache <em class="bcp14">MUST</em> delete any stored Warning header fields with warn-code 1xx (see <a href="#header.warning" id="rfc.xref.header.warning.2" title="Warning">Section&nbsp;3.6</a>).
1074               </li>
1075               <li>a cache <em class="bcp14">MUST</em> retain any stored Warning header fields with warn-code 2xx.
1076               </li>
1077               <li>a cache <em class="bcp14">MUST</em> use other header fields provided in the new response to replace all instances of the corresponding header fields from the
1078                  stored response.
1079               </li>
1080            </ul>
1081            <p id="rfc.section.2.8.p.5">A cache <em class="bcp14">MUST</em> use the updated response header fields to replace those of the stored response (unless the stored response is removed). In
1082               the case of a 206 response, a cache <em class="bcp14">MAY</em> store the combined representation.
1083            </p>
1084         </div>
1085      </div>
1086      <div id="header.fields">
1087         <h1 id="rfc.section.3"><a href="#rfc.section.3">3.</a>&nbsp;<a href="#header.fields">Header Field Definitions</a></h1>
1088         <p id="rfc.section.3.p.1">This section defines the syntax and semantics of HTTP/1.1 header fields related to caching.</p>
1089         <div id="header.age">
1090            <div id="rfc.iref.a.2"></div>
1091            <div id="rfc.iref.h.2"></div>
1092            <h2 id="rfc.section.3.1"><a href="#rfc.section.3.1">3.1</a>&nbsp;<a href="#header.age">Age</a></h2>
1093            <p id="rfc.section.3.1.p.1">The "Age" header field conveys the sender's estimate of the amount of time since the response was generated or successfully
1094               validated at the origin server. Age values are calculated as specified in <a href="#age.calculations" title="Calculating Age">Section&nbsp;2.3.2</a>.
1095            </p>
1096            <div id="rfc.figure.u.7"></div><pre class="inline"><span id="rfc.iref.g.1"></span>  <a href="#header.age" class="smpl">Age</a> = <a href="" class="smpl">delta-seconds</a>
1097</pre><div id="">
1098               <p id="rfc.section.3.1.p.3"> Age field-values are non-negative integers, representing time in seconds.</p>
1099            </div>
1100            <div id="rfc.figure.u.8"></div><pre class="inline"><span id="rfc.iref.g.2"></span>  <a href="" class="smpl">delta-seconds</a>  = 1*<a href="#notation" class="smpl">DIGIT</a>
1101</pre><p id="rfc.section.3.1.p.5">If a cache receives a value larger than the largest positive integer it can represent, or if any of its age calculations overflows,
1102               it <em class="bcp14">MUST</em> transmit an Age header field with a field-value of 2147483648 (2<sup>31</sup>). Recipients parsing the Age header field-value <em class="bcp14">SHOULD</em> use an arithmetic type of at least 31 bits of range.
1103            </p>
1104            <p id="rfc.section.3.1.p.6">The presence of an Age header field in a response implies that a response is not first-hand. However, the converse is not
1105               true, since HTTP/1.0 caches might not implement the Age header field.
1106            </p>
1107         </div>
1108         <div id="header.cache-control">
1109            <div id="rfc.iref.c.4"></div>
1110            <div id="rfc.iref.h.3"></div>
1111            <h2 id="rfc.section.3.2"><a href="#rfc.section.3.2">3.2</a>&nbsp;<a href="#header.cache-control">Cache-Control</a></h2>
1112            <p id="rfc.section.3.2.p.1">The "Cache-Control" header field is used to specify directives for caches along the request/response chain. Such cache directives
1113               are unidirectional in that the presence of a directive in a request does not imply that the same directive is to be given
1114               in the response.
1115            </p>
1116            <p id="rfc.section.3.2.p.2">A cache <em class="bcp14">MUST</em> obey the requirements of the Cache-Control directives defined in this section. See <a href="#cache.control.extensions" title="Cache Control Extensions">Section&nbsp;3.2.3</a> for information about how Cache-Control directives defined elsewhere are handled.
1117            </p>
1118            <div class="note" id="rfc.section.3.2.p.3">
1119               <p><b>Note:</b> HTTP/1.0 caches might not implement Cache-Control and might only implement Pragma: no-cache (see <a href="#header.pragma" id="rfc.xref.header.pragma.2" title="Pragma">Section&nbsp;3.4</a>).
1120               </p>
1121            </div>
1122            <p id="rfc.section.3.2.p.4">A proxy, whether or not it implements a cache, <em class="bcp14">MUST</em> pass cache directives through in forwarded messages, regardless of their significance to that application, since the directives
1123               might be applicable to all recipients along the request/response chain. It is not possible to target a directive to a specific
1124               cache.
1125            </p>
1126            <div id="rfc.figure.u.9"></div><pre class="inline"><span id="rfc.iref.g.3"></span><span id="rfc.iref.g.4"></span>  <a href="#header.cache-control" class="smpl">Cache-Control</a>   = 1#<a href="#header.cache-control" class="smpl">cache-directive</a>
1128  <a href="#header.cache-control" class="smpl">cache-directive</a> = <a href="#header.cache-control" class="smpl">cache-request-directive</a>
1129     / <a href="#header.cache-control" class="smpl">cache-response-directive</a>
1131  <a href="#header.cache-control" class="smpl">cache-extension</a> = <a href="#core.rules" class="smpl">token</a> [ "=" ( <a href="#core.rules" class="smpl">token</a> / <a href="#core.rules" class="smpl">quoted-string</a> ) ]
1132</pre><div id="cache-request-directive">
1133               <h3 id="rfc.section.3.2.1"><a href="#rfc.section.3.2.1">3.2.1</a>&nbsp;<a href="#cache-request-directive">Request Cache-Control Directives</a></h3>
1134               <div id="rfc.figure.u.10"></div><pre class="inline"><span id="rfc.iref.g.5"></span>  <a href="#header.cache-control" class="smpl">cache-request-directive</a> =
1135       "no-cache"
1136     / "no-store"
1137     / "max-age" "=" <a href="" class="smpl">delta-seconds</a>
1138     / "max-stale" [ "=" <a href="" class="smpl">delta-seconds</a> ]
1139     / "min-fresh" "=" <a href="" class="smpl">delta-seconds</a>
1140     / "no-transform"
1141     / "only-if-cached"
1142     / <a href="#header.cache-control" class="smpl">cache-extension</a>
1143</pre><p id="rfc.section.3.2.1.p.2"><dfn>no-cache</dfn> <span id="rfc.iref.c.5"></span> <span id="rfc.iref.n.1"></span>
1144               </p>
1145               <ul class="empty">
1146                  <li>The no-cache request directive indicates that a cache <em class="bcp14">MUST NOT</em> use a stored response to satisfy the request without successful validation on the origin server.
1147                  </li>
1148               </ul>
1149               <p id="rfc.section.3.2.1.p.3"><dfn>no-store</dfn> <span id="rfc.iref.c.6"></span> <span id="rfc.iref.n.2"></span>
1150               </p>
1151               <ul class="empty">
1152                  <li>The no-store request directive indicates that a cache <em class="bcp14">MUST NOT</em> store any part of either this request or any response to it. This directive applies to both private and shared caches. "<em class="bcp14">MUST NOT</em> store" in this context means that the cache <em class="bcp14">MUST NOT</em> intentionally store the information in non-volatile storage, and <em class="bcp14">MUST</em> make a best-effort attempt to remove the information from volatile storage as promptly as possible after forwarding it.
1153                  </li>
1154                  <li>This directive is NOT a reliable or sufficient mechanism for ensuring privacy. In particular, malicious or compromised caches
1155                     might not recognize or obey this directive, and communications networks might be vulnerable to eavesdropping.
1156                  </li>
1157                  <li>Note that if a request containing this directive is satisfied from a cache, the no-store request directive does not apply
1158                     to the already stored response.
1159                  </li>
1160               </ul>
1161               <p id="rfc.section.3.2.1.p.4"><dfn>max-age</dfn> <span id="rfc.iref.c.7"></span> <span id="rfc.iref.m.1"></span>
1162               </p>
1163               <ul class="empty">
1164                  <li>The max-age request directive indicates that the client is willing to accept a response whose age is no greater than the specified
1165                     time in seconds. Unless the max-stale request directive is also present, the client is not willing to accept a stale response.
1166                  </li>
1167               </ul>
1168               <p id="rfc.section.3.2.1.p.5"><dfn>max-stale</dfn> <span id="rfc.iref.c.8"></span> <span id="rfc.iref.m.2"></span>
1169               </p>
1170               <ul class="empty">
1171                  <li>The max-stale request directive indicates that the client is willing to accept a response that has exceeded its expiration
1172                     time. If max-stale is assigned a value, then the client is willing to accept a response that has exceeded its expiration time
1173                     by no more than the specified number of seconds. If no value is assigned to max-stale, then the client is willing to accept
1174                     a stale response of any age.
1175                  </li>
1176               </ul>
1177               <p id="rfc.section.3.2.1.p.6"><dfn>min-fresh</dfn> <span id="rfc.iref.c.9"></span> <span id="rfc.iref.m.3"></span>
1178               </p>
1179               <ul class="empty">
1180                  <li>The min-fresh request directive indicates that the client is willing to accept a response whose freshness lifetime is no less
1181                     than its current age plus the specified time in seconds. That is, the client wants a response that will still be fresh for
1182                     at least the specified number of seconds.
1183                  </li>
1184               </ul>
1185               <p id="rfc.section.3.2.1.p.7"><dfn>no-transform</dfn> <span id="rfc.iref.c.10"></span> <span id="rfc.iref.n.3"></span>
1186               </p>
1187               <ul class="empty">
1188                  <li>The no-transform request directive indicates that an intermediary (whether or not it implements a cache) <em class="bcp14">MUST NOT</em> change the Content-Encoding, Content-Range or Content-Type request header fields, nor the request representation.
1189                  </li>
1190               </ul>
1191               <p id="rfc.section.3.2.1.p.8"><dfn>only-if-cached</dfn> <span id="rfc.iref.c.11"></span> <span id="rfc.iref.o.1"></span>
1192               </p>
1193               <ul class="empty">
1194                  <li>The only-if-cached request directive indicates that the client only wishes to return a stored response. If it receives this
1195                     directive, a cache <em class="bcp14">SHOULD</em> either respond using a stored response that is consistent with the other constraints of the request, or respond with a 504
1196                     (Gateway Timeout) status code. If a group of caches is being operated as a unified system with good internal connectivity,
1197                     a member cache <em class="bcp14">MAY</em> forward such a request within that group of caches.
1198                  </li>
1199               </ul>
1200            </div>
1201            <div id="cache-response-directive">
1202               <h3 id="rfc.section.3.2.2"><a href="#rfc.section.3.2.2">3.2.2</a>&nbsp;<a href="#cache-response-directive">Response Cache-Control Directives</a></h3>
1203               <div id="rfc.figure.u.11"></div><pre class="inline"><span id="rfc.iref.g.6"></span>  <a href="#header.cache-control" class="smpl">cache-response-directive</a> =
1204       "public"
1205     / "private" [ "=" <a href="#notation" class="smpl">DQUOTE</a> 1#<a href="#abnf.dependencies" class="smpl">field-name</a> <a href="#notation" class="smpl">DQUOTE</a> ]
1206     / "no-cache" [ "=" <a href="#notation" class="smpl">DQUOTE</a> 1#<a href="#abnf.dependencies" class="smpl">field-name</a> <a href="#notation" class="smpl">DQUOTE</a> ]
1207     / "no-store"
1208     / "no-transform"
1209     / "must-revalidate"
1210     / "proxy-revalidate"
1211     / "max-age" "=" <a href="" class="smpl">delta-seconds</a>
1212     / "s-maxage" "=" <a href="" class="smpl">delta-seconds</a>
1213     / <a href="#header.cache-control" class="smpl">cache-extension</a>
1214</pre><p id="rfc.section.3.2.2.p.2"><dfn>public</dfn> <span id="rfc.iref.c.12"></span> <span id="rfc.iref.p.2"></span>
1215               </p>
1216               <ul class="empty">
1217                  <li>The public response directive indicates that a response whose associated request contains an 'Authentication' header <em class="bcp14">MAY</em> be stored (see <a href="#caching.authenticated.responses" title="Shared Caching of Authenticated Responses">Section&nbsp;2.6</a>).
1218                  </li>
1219               </ul>
1220               <p id="rfc.section.3.2.2.p.3"><dfn>private</dfn> <span id="rfc.iref.c.13"></span> <span id="rfc.iref.p.3"></span>
1221               </p>
1222               <ul class="empty">
1223                  <li>The private response directive indicates that the response message is intended for a single user and <em class="bcp14">MUST NOT</em> be stored by a shared cache. A private cache <em class="bcp14">MAY</em> store the response.
1224                  </li>
1225                  <li>If the private response directive specifies one or more field-names, this requirement is limited to the field-values associated
1226                     with the listed response header fields. That is, a shared cache <em class="bcp14">MUST NOT</em> store the specified field-names(s), whereas it <em class="bcp14">MAY</em> store the remainder of the response message.
1227                  </li>
1228                  <li><b>Note:</b> This usage of the word private only controls where the response can be stored; it cannot ensure the privacy of the message
1229                     content. Also, private response directives with field-names are often handled by implementations as if an unqualified private
1230                     directive was received; i.e., the special handling for the qualified form is not widely implemented.
1231                  </li>
1232               </ul>
1233               <p id="rfc.section.3.2.2.p.4"><dfn>no-cache</dfn> <span id="rfc.iref.c.14"></span> <span id="rfc.iref.n.4"></span>
1234               </p>
1235               <ul class="empty">
1236                  <li>The no-cache response directive indicates that the response MUST NOT be used to satisfy a subsequent request without successful
1237                     validation on the origin server. This allows an origin server to prevent a cache from using it to satisfy a request without
1238                     contacting it, even by caches that have been configured to return stale responses.
1239                  </li>
1240                  <li>If the no-cache response directive specifies one or more field-names, this requirement is limited to the field-values associated
1241                     with the listed response header fields. That is, a cache <em class="bcp14">MUST NOT</em> send the specified field-name(s) in the response to a subsequent request without successful validation on the origin server.
1242                     This allows an origin server to prevent the re-use of certain header fields in a response, while still allowing caching of
1243                     the rest of the response.
1244                  </li>
1245                  <li><b>Note:</b> Most HTTP/1.0 caches will not recognize or obey this directive. Also, no-cache response directives with field-names are often
1246                     handled by implementations as if an unqualified no-cache directive was received; i.e., the special handling for the qualified
1247                     form is not widely implemented.
1248                  </li>
1249               </ul>
1250               <p id="rfc.section.3.2.2.p.5"><dfn>no-store</dfn> <span id="rfc.iref.c.15"></span> <span id="rfc.iref.n.5"></span>
1251               </p>
1252               <ul class="empty">
1253                  <li>The no-store response directive indicates that a cache <em class="bcp14">MUST NOT</em> store any part of either the immediate request or response. This directive applies to both private and shared caches. "<em class="bcp14">MUST NOT</em> store" in this context means that the cache <em class="bcp14">MUST NOT</em> intentionally store the information in non-volatile storage, and <em class="bcp14">MUST</em> make a best-effort attempt to remove the information from volatile storage as promptly as possible after forwarding it.
1254                  </li>
1255                  <li>This directive is NOT a reliable or sufficient mechanism for ensuring privacy. In particular, malicious or compromised caches
1256                     might not recognize or obey this directive, and communications networks might be vulnerable to eavesdropping.
1257                  </li>
1258               </ul>
1259               <p id="rfc.section.3.2.2.p.6"><dfn>must-revalidate</dfn> <span id="rfc.iref.c.16"></span> <span id="rfc.iref.m.4"></span>
1260               </p>
1261               <ul class="empty">
1262                  <li>The must-revalidate response directive indicates that once it has become stale, a cache <em class="bcp14">MUST NOT</em> use the response to satisfy subsequent requests without successful validation on the origin server.
1263                  </li>
1264                  <li>The must-revalidate directive is necessary to support reliable operation for certain protocol features. In all circumstances
1265                     a cache <em class="bcp14">MUST</em> obey the must-revalidate directive; in particular, if a cache cannot reach the origin server for any reason, it <em class="bcp14">MUST</em> generate a 504 (Gateway Timeout) response.
1266                  </li>
1267                  <li>A server <em class="bcp14">SHOULD</em> send the must-revalidate directive if and only if failure to validate a request on the representation could result in incorrect
1268                     operation, such as a silently unexecuted financial transaction.
1269                  </li>
1270               </ul>
1271               <p id="rfc.section.3.2.2.p.7"><dfn>proxy-revalidate</dfn> <span id="rfc.iref.c.17"></span> <span id="rfc.iref.p.4"></span>
1272               </p>
1273               <ul class="empty">
1274                  <li>The proxy-revalidate response directive has the same meaning as the must-revalidate response directive, except that it does
1275                     not apply to private caches.
1276                  </li>
1277               </ul>
1278               <p id="rfc.section.3.2.2.p.8"><dfn>max-age</dfn> <span id="rfc.iref.c.18"></span> <span id="rfc.iref.m.5"></span>
1279               </p>
1280               <ul class="empty">
1281                  <li>The max-age response directive indicates that the response is to be considered stale after its age is greater than the specified
1282                     number of seconds.
1283                  </li>
1284               </ul>
1285               <p id="rfc.section.3.2.2.p.9"><dfn>s-maxage</dfn> <span id="rfc.iref.c.19"></span> <span id="rfc.iref.s.3"></span>
1286               </p>
1287               <ul class="empty">
1288                  <li>The s-maxage response directive indicates that, in shared caches, the maximum age specified by this directive overrides the
1289                     maximum age specified by either the max-age directive or the Expires header field. The s-maxage directive also implies the
1290                     semantics of the proxy-revalidate response directive.
1291                  </li>
1292               </ul>
1293               <p id="rfc.section.3.2.2.p.10"><dfn>no-transform</dfn> <span id="rfc.iref.c.20"></span> <span id="rfc.iref.n.6"></span>
1294               </p>
1295               <ul class="empty">
1296                  <li>The no-transform response directive indicates that an intermediary (regardless of whether it implements a cache) <em class="bcp14">MUST NOT</em> change the Content-Encoding, Content-Range or Content-Type response header fields, nor the response representation.
1297                  </li>
1298               </ul>
1299            </div>
1300            <div id="cache.control.extensions">
1301               <h3 id="rfc.section.3.2.3"><a href="#rfc.section.3.2.3">3.2.3</a>&nbsp;<a href="#cache.control.extensions">Cache Control Extensions</a></h3>
1302               <p id="rfc.section.3.2.3.p.1">The Cache-Control header field can be extended through the use of one or more cache-extension tokens, each with an optional
1303                  value. Informational extensions (those that do not require a change in cache behavior) can be added without changing the semantics
1304                  of other directives. Behavioral extensions are designed to work by acting as modifiers to the existing base of cache directives.
1305                  Both the new directive and the standard directive are supplied, such that applications that do not understand the new directive
1306                  will default to the behavior specified by the standard directive, and those that understand the new directive will recognize
1307                  it as modifying the requirements associated with the standard directive. In this way, extensions to the cache-control directives
1308                  can be made without requiring changes to the base protocol.
1309               </p>
1310               <p id="rfc.section.3.2.3.p.2">This extension mechanism depends on an HTTP cache obeying all of the cache-control directives defined for its native HTTP-version,
1311                  obeying certain extensions, and ignoring all directives that it does not understand.
1312               </p>
1313               <p id="rfc.section.3.2.3.p.3">For example, consider a hypothetical new response directive called "community" that acts as a modifier to the private directive.
1314                  We define this new directive to mean that, in addition to any private cache, any cache that is shared only by members of the
1315                  community named within its value may cache the response. An origin server wishing to allow the UCI community to use an otherwise
1316                  private response in their shared cache(s) could do so by including
1317               </p>
1318               <div id="rfc.figure.u.12"></div><pre class="text">  Cache-Control: private, community="UCI"
1319</pre><p id="rfc.section.3.2.3.p.5">A cache seeing this header field will act correctly even if the cache does not understand the community cache-extension, since
1320                  it will also see and understand the private directive and thus default to the safe behavior.
1321               </p>
1322               <p id="rfc.section.3.2.3.p.6">A cache <em class="bcp14">MUST</em> be ignore unrecognized cache directives; it is assumed that any cache directive likely to be unrecognized by an HTTP/1.1 cache
1323                  will be combined with standard directives (or the response's default cacheability) such that the cache behavior will remain
1324                  minimally correct even if the cache does not understand the extension(s).
1325               </p>
1326               <p id="rfc.section.3.2.3.p.7">The HTTP Cache Directive Registry defines the name space for the cache directives.</p>
1327               <p id="rfc.section.3.2.3.p.8">A registration <em class="bcp14">MUST</em> include the following fields:
1328               </p>
1329               <ul>
1330                  <li>Cache Directive Name</li>
1331                  <li>Pointer to specification text</li>
1332               </ul>
1333               <p id="rfc.section.3.2.3.p.9">Values to be added to this name space are subject to IETF review (<a href="#RFC5226" id="rfc.xref.RFC5226.1"><cite title="Guidelines for Writing an IANA Considerations Section in RFCs">[RFC5226]</cite></a>, <a href="">Section 4.1</a>).
1334               </p>
1335               <p id="rfc.section.3.2.3.p.10">The registry itself is maintained at &lt;<a href=""></a>&gt;.
1336               </p>
1337            </div>
1338         </div>
1339         <div id="header.expires">
1340            <div id="rfc.iref.e.2"></div>
1341            <div id="rfc.iref.h.4"></div>
1342            <h2 id="rfc.section.3.3"><a href="#rfc.section.3.3">3.3</a>&nbsp;<a href="#header.expires">Expires</a></h2>
1343            <p id="rfc.section.3.3.p.1">The "Expires" header field gives the date/time after which the response is considered stale. See <a href="#expiration.model" title="Freshness Model">Section&nbsp;2.3</a> for further discussion of the freshness model.
1344            </p>
1345            <p id="rfc.section.3.3.p.2">The presence of an Expires field does not imply that the original resource will change or cease to exist at, before, or after
1346               that time.
1347            </p>
1348            <p id="rfc.section.3.3.p.3">The field-value is an absolute date and time as defined by HTTP-date in <a href="" title="Date/Time Formats: Full Date">Section 6.1</a> of <a href="#Part1" id="rfc.xref.Part1.17"><cite title="HTTP/1.1, part 1: URIs, Connections, and Message Parsing">[Part1]</cite></a>; a sender <em class="bcp14">MUST</em> use the rfc1123-date format.
1349            </p>
1350            <div id="rfc.figure.u.13"></div><pre class="inline"><span id="rfc.iref.g.7"></span>  <a href="#header.expires" class="smpl">Expires</a> = <a href="#abnf.dependencies" class="smpl">HTTP-date</a>
1351</pre><div id="rfc.figure.u.14"></div>
1352            <p>For example</p><pre class="text">  Expires: Thu, 01 Dec 1994 16:00:00 GMT
1353</pre><div class="note" id="rfc.section.3.3.p.6">
1354               <p><b>Note:</b> If a response includes a Cache-Control field with the max-age directive (see <a href="#cache-response-directive" title="Response Cache-Control Directives">Section&nbsp;3.2.2</a>), that directive overrides the Expires field. Likewise, the s-maxage directive overrides Expires in shared caches.
1355               </p>
1356            </div>
1357            <p id="rfc.section.3.3.p.7">A server <em class="bcp14">SHOULD NOT</em> send Expires dates more than one year in the future.
1358            </p>
1359            <p id="rfc.section.3.3.p.8">A cache <em class="bcp14">MUST</em> treat other invalid date formats, especially including the value "0", as in the past (i.e., "already expired").
1360            </p>
1361         </div>
1362         <div id="header.pragma">
1363            <div id="rfc.iref.p.5"></div>
1364            <div id="rfc.iref.h.5"></div>
1365            <h2 id="rfc.section.3.4"><a href="#rfc.section.3.4">3.4</a>&nbsp;<a href="#header.pragma">Pragma</a></h2>
1366            <p id="rfc.section.3.4.p.1">The "Pragma" header field is used to include implementation-specific directives that might apply to any recipient along the
1367               request/response chain. All pragma directives specify optional behavior from the viewpoint of the protocol; however, some
1368               systems <em class="bcp14">MAY</em> require that behavior be consistent with the directives.
1369            </p>
1370            <div id="rfc.figure.u.15"></div><pre class="inline"><span id="rfc.iref.g.8"></span><span id="rfc.iref.g.9"></span><span id="rfc.iref.g.10"></span>  <a href="#header.pragma" class="smpl">Pragma</a>           = 1#<a href="#header.pragma" class="smpl">pragma-directive</a>
1371  <a href="#header.pragma" class="smpl">pragma-directive</a> = "no-cache" / <a href="#header.pragma" class="smpl">extension-pragma</a>
1372  <a href="#header.pragma" class="smpl">extension-pragma</a> = <a href="#core.rules" class="smpl">token</a> [ "=" ( <a href="#core.rules" class="smpl">token</a> / <a href="#core.rules" class="smpl">quoted-string</a> ) ]
1373</pre><p id="rfc.section.3.4.p.3">When the no-cache directive is present in a request message, a cache <em class="bcp14">SHOULD</em> forward the request toward the origin server even if it has a stored copy of what is being requested. This pragma directive
1374               has the same semantics as the no-cache response directive (see <a href="#cache-response-directive" title="Response Cache-Control Directives">Section&nbsp;3.2.2</a>) and is defined here for backward compatibility with HTTP/1.0. A client <em class="bcp14">SHOULD</em> include both header fields when a no-cache request is sent to a server not known to be HTTP/1.1 compliant. A cache <em class="bcp14">SHOULD</em> treat "Pragma: no-cache" as if the client had sent "Cache-Control: no-cache".
1375            </p>
1376            <div class="note" id="rfc.section.3.4.p.4">
1377               <p><b>Note:</b> Because the meaning of "Pragma: no-cache" as a header field is not actually specified, it does not provide a reliable replacement
1378                  for "Cache-Control: no-cache" in a response.
1379               </p>
1380            </div>
1381            <p id="rfc.section.3.4.p.5">This mechanism is deprecated; no new Pragma directives will be defined in HTTP.</p>
1382         </div>
1383         <div id="header.vary">
1384            <div id="rfc.iref.v.2"></div>
1385            <div id="rfc.iref.h.6"></div>
1386            <h2 id="rfc.section.3.5"><a href="#rfc.section.3.5">3.5</a>&nbsp;<a href="#header.vary">Vary</a></h2>
1387            <p id="rfc.section.3.5.p.1">The "Vary" header field conveys the set of header fields that were used to select the representation.</p>
1388            <p id="rfc.section.3.5.p.2">Caches use this information, in part, to determine whether a stored response can be used to satisfy a given request; see <a href="#caching.negotiated.responses" title="Caching Negotiated Responses">Section&nbsp;2.7</a>. determines, while the response is fresh, whether a cache is permitted to use the response to reply to a subsequent request
1389               without validation; see <a href="#caching.negotiated.responses" title="Caching Negotiated Responses">Section&nbsp;2.7</a>.
1390            </p>
1391            <p id="rfc.section.3.5.p.3">In uncacheable or stale responses, the Vary field value advises the user agent about the criteria that were used to select
1392               the representation.
1393            </p>
1394            <div id="rfc.figure.u.16"></div><pre class="inline"><span id="rfc.iref.g.11"></span>  <a href="#header.vary" class="smpl">Vary</a> = "*" / 1#<a href="#abnf.dependencies" class="smpl">field-name</a>
1395</pre><p id="rfc.section.3.5.p.5">The set of header fields named by the Vary field value is known as the selecting header fields.</p>
1396            <p id="rfc.section.3.5.p.6">A server <em class="bcp14">SHOULD</em> include a Vary header field with any cacheable response that is subject to server-driven negotiation. Doing so allows a cache
1397               to properly interpret future requests on that resource and informs the user agent about the presence of negotiation on that
1398               resource. A server <em class="bcp14">MAY</em> include a Vary header field with a non-cacheable response that is subject to server-driven negotiation, since this might provide
1399               the user agent with useful information about the dimensions over which the response varies at the time of the response.
1400            </p>
1401            <p id="rfc.section.3.5.p.7">A Vary field value of "*" signals that unspecified parameters not limited to the header fields (e.g., the network address
1402               of the client), play a role in the selection of the response representation; therefore, a cache cannot determine whether this
1403               response is appropriate. A proxy <em class="bcp14">MUST NOT</em> generate the "*" value.
1404            </p>
1405            <p id="rfc.section.3.5.p.8">The field-names given are not limited to the set of standard header fields defined by this specification. Field names are
1406               case-insensitive.
1407            </p>
1408         </div>
1409         <div id="header.warning">
1410            <div id="rfc.iref.w.1"></div>
1411            <div id="rfc.iref.h.7"></div>
1412            <h2 id="rfc.section.3.6"><a href="#rfc.section.3.6">3.6</a>&nbsp;<a href="#header.warning">Warning</a></h2>
1413            <p id="rfc.section.3.6.p.1">The "Warning" header field is used to carry additional information about the status or transformation of a message that might
1414               not be reflected in the message. This information is typically used to warn about possible incorrectness introduced by caching
1415               operations or transformations applied to the payload of the message.
1416            </p>
1417            <p id="rfc.section.3.6.p.2">Warnings can be used for other purposes, both cache-related and otherwise. The use of a warning, rather than an error status
1418               code, distinguishes these responses from true failures.
1419            </p>
1420            <p id="rfc.section.3.6.p.3">Warning header fields can in general be applied to any message, however some warn-codes are specific to caches and can only
1421               be applied to response messages.
1422            </p>
1423            <div id="rfc.figure.u.17"></div><pre class="inline"><span id="rfc.iref.g.12"></span><span id="rfc.iref.g.13"></span><span id="rfc.iref.g.14"></span><span id="rfc.iref.g.15"></span><span id="rfc.iref.g.16"></span><span id="rfc.iref.g.17"></span>  <a href="#header.warning" class="smpl">Warning</a>       = 1#<a href="#header.warning" class="smpl">warning-value</a>
1425  <a href="#header.warning" class="smpl">warning-value</a> = <a href="#header.warning" class="smpl">warn-code</a> <a href="#notation" class="smpl">SP</a> <a href="#header.warning" class="smpl">warn-agent</a> <a href="#notation" class="smpl">SP</a> <a href="#header.warning" class="smpl">warn-text</a>
1426                                        [<a href="#notation" class="smpl">SP</a> <a href="#header.warning" class="smpl">warn-date</a>]
1428  <a href="#header.warning" class="smpl">warn-code</a>  = 3<a href="#notation" class="smpl">DIGIT</a>
1429  <a href="#header.warning" class="smpl">warn-agent</a> = ( <a href="#abnf.dependencies" class="smpl">uri-host</a> [ ":" <a href="#abnf.dependencies" class="smpl">port</a> ] ) / <a href="#abnf.dependencies" class="smpl">pseudonym</a>
1430                  ; the name or pseudonym of the server adding
1431                  ; the Warning header field, for use in debugging
1432  <a href="#header.warning" class="smpl">warn-text</a>  = <a href="#core.rules" class="smpl">quoted-string</a>
1433  <a href="#header.warning" class="smpl">warn-date</a>  = <a href="#notation" class="smpl">DQUOTE</a> <a href="#abnf.dependencies" class="smpl">HTTP-date</a> <a href="#notation" class="smpl">DQUOTE</a>
1434</pre><p id="rfc.section.3.6.p.5">Multiple warnings can be attached to a response (either by the origin server or by a cache), including multiple warnings with
1435               the same code number, only differing in warn-text.
1436            </p>
1437            <p id="rfc.section.3.6.p.6">When this occurs, the user agent <em class="bcp14">SHOULD</em> inform the user of as many of them as possible, in the order that they appear in the response.
1438            </p>
1439            <p id="rfc.section.3.6.p.7">Systems that generate multiple Warning header fields <em class="bcp14">SHOULD</em> order them with this user agent behavior in mind. New Warning header fields <em class="bcp14">SHOULD</em> be added after any existing Warning headers fields.
1440            </p>
1441            <p id="rfc.section.3.6.p.8">Warnings are assigned three digit warn-codes. The first digit indicates whether the Warning is required to be deleted from
1442               a stored response after validation:
1443            </p>
1444            <ul>
1445               <li>1xx Warnings describe the freshness or validation status of the response, and so <em class="bcp14">MUST</em> be deleted by a cache after validation. They can only be generated by a cache when validating a cached entry, and <em class="bcp14">MUST NOT</em> be generated in any other situation.
1446               </li>
1447               <li>2xx Warnings describe some aspect of the representation that is not rectified by a validation (for example, a lossy compression
1448                  of the representation) and <em class="bcp14">MUST NOT</em> be deleted by a cache after validation, unless a full response is returned, in which case they <em class="bcp14">MUST</em> be.
1449               </li>
1450            </ul>
1451            <p id="rfc.section.3.6.p.9">If an implementation sends a message with one or more Warning header fields to a receiver whose version is HTTP/1.0 or lower,
1452               then the sender <em class="bcp14">MUST</em> include in each warning-value a warn-date that matches the Date header field in the message.
1453            </p>
1454            <p id="rfc.section.3.6.p.10">If a system receives a message with a warning-value that includes a warn-date, and that warn-date is different from the Date
1455               value in the response, then that warning-value <em class="bcp14">MUST</em> be deleted from the message before storing, forwarding, or using it. (preventing the consequences of naive caching of Warning
1456               header fields.) If all of the warning-values are deleted for this reason, the Warning header field <em class="bcp14">MUST</em> be deleted as well.
1457            </p>
1458            <p id="rfc.section.3.6.p.11">The following warn-codes are defined by this specification, each with a recommended warn-text in English, and a description
1459               of its meaning.
1460            </p>
1461            <p id="rfc.section.3.6.p.12"> 110 Response is stale </p>
1462            <ul class="empty">
1463               <li>A cache <em class="bcp14">SHOULD</em> include this whenever the returned response is stale.
1464               </li>
1465            </ul>
1466            <p id="rfc.section.3.6.p.13"> 111 Revalidation failed </p>
1467            <ul class="empty">
1468               <li>A cache <em class="bcp14">SHOULD</em> include this when returning a stale response because an attempt to validate the response failed, due to an inability to reach
1469                  the server.
1470               </li>
1471            </ul>
1472            <p id="rfc.section.3.6.p.14"> 112 Disconnected operation </p>
1473            <ul class="empty">
1474               <li>A cache <em class="bcp14">SHOULD</em> b include this if it is intentionally disconnected from the rest of the network for a period of time.
1475               </li>
1476            </ul>
1477            <p id="rfc.section.3.6.p.15"> 113 Heuristic expiration </p>
1478            <ul class="empty">
1479               <li>A cache <em class="bcp14">SHOULD</em> include this if it heuristically chose a freshness lifetime greater than 24 hours and the response's age is greater than 24
1480                  hours.
1481               </li>
1482            </ul>
1483            <p id="rfc.section.3.6.p.16"> 199 Miscellaneous warning </p>
1484            <ul class="empty">
1485               <li>The warning text can include arbitrary information to be presented to a human user, or logged. A system receiving this warning <em class="bcp14">MUST NOT</em> take any automated action, besides presenting the warning to the user.
1486               </li>
1487            </ul>
1488            <p id="rfc.section.3.6.p.17"> 214 Transformation applied </p>
1489            <ul class="empty">
1490               <li><em class="bcp14">MUST</em> be added by a proxy if it applies any transformation to the representation, such as changing the content-coding, media-type,
1491                  or modifying the representation data, unless this Warning code already appears in the response.
1492               </li>
1493            </ul>
1494            <p id="rfc.section.3.6.p.18"> 299 Miscellaneous persistent warning </p>
1495            <ul class="empty">
1496               <li>The warning text can include arbitrary information to be presented to a human user, or logged. A system receiving this warning <em class="bcp14">MUST NOT</em> take any automated action.
1497               </li>
1498            </ul>
1499         </div>
1500      </div>
1501      <div id="history.lists">
1502         <h1 id="rfc.section.4"><a href="#rfc.section.4">4.</a>&nbsp;<a href="#history.lists">History Lists</a></h1>
1503         <p id="rfc.section.4.p.1">User agents often have history mechanisms, such as "Back" buttons and history lists, that can be used to redisplay a representation
1504            retrieved earlier in a session.
1505         </p>
1506         <p id="rfc.section.4.p.2">The freshness model (<a href="#expiration.model" title="Freshness Model">Section&nbsp;2.3</a>) does not necessarily apply to history mechanisms. I.e., a history mechanism can display a previous representation even if
1507            it has expired.
1508         </p>
1509         <p id="rfc.section.4.p.3">This does not prohibit the history mechanism from telling the user that a view might be stale, or from honoring cache directives
1510            (e.g., Cache-Control: no-store).
1511         </p>
1512      </div>
1513      <div id="IANA.considerations">
1514         <h1 id="rfc.section.5"><a href="#rfc.section.5">5.</a>&nbsp;<a href="#IANA.considerations">IANA Considerations</a></h1>
1515         <div id="cache.directive.registration">
1516            <h2 id="rfc.section.5.1"><a href="#rfc.section.5.1">5.1</a>&nbsp;<a href="#cache.directive.registration">Cache Directive Registry</a></h2>
1517            <p id="rfc.section.5.1.p.1">The registration procedure for HTTP Cache Directives is defined by <a href="#cache.control.extensions" title="Cache Control Extensions">Section&nbsp;3.2.3</a> of this document.
1518            </p>
1519            <p id="rfc.section.5.1.p.2">The HTTP Cache Directive Registry shall be created at &lt;<a href=""></a>&gt; and be populated with the registrations below:
1520            </p>
1521            <div id="rfc.table.1">
1522               <div id="iana.cache.directive.registration.table"></div>
1523               <table class="tt full left" cellpadding="3" cellspacing="0">
1524                  <thead>
1525                     <tr>
1526                        <th>Cache Directive</th>
1527                        <th>Reference</th>
1528                     </tr>
1529                  </thead>
1530                  <tbody>
1531                     <tr>
1532                        <td class="left">max-age</td>
1533                        <td class="left"><a href="#cache-request-directive" title="Request Cache-Control Directives">Section&nbsp;3.2.1</a>, <a href="#cache-response-directive" title="Response Cache-Control Directives">Section&nbsp;3.2.2</a>
1534                        </td>
1535                     </tr>
1536                     <tr>
1537                        <td class="left">max-stale</td>
1538                        <td class="left"><a href="#cache-request-directive" title="Request Cache-Control Directives">Section&nbsp;3.2.1</a>
1539                        </td>
1540                     </tr>
1541                     <tr>
1542                        <td class="left">min-fresh</td>
1543                        <td class="left"><a href="#cache-request-directive" title="Request Cache-Control Directives">Section&nbsp;3.2.1</a>
1544                        </td>
1545                     </tr>
1546                     <tr>
1547                        <td class="left">must-revalidate</td>
1548                        <td class="left"><a href="#cache-response-directive" title="Response Cache-Control Directives">Section&nbsp;3.2.2</a>
1549                        </td>
1550                     </tr>
1551                     <tr>
1552                        <td class="left">no-cache</td>
1553                        <td class="left"><a href="#cache-request-directive" title="Request Cache-Control Directives">Section&nbsp;3.2.1</a>, <a href="#cache-response-directive" title="Response Cache-Control Directives">Section&nbsp;3.2.2</a>
1554                        </td>
1555                     </tr>
1556                     <tr>
1557                        <td class="left">no-store</td>
1558                        <td class="left"><a href="#cache-request-directive" title="Request Cache-Control Directives">Section&nbsp;3.2.1</a>, <a href="#cache-response-directive" title="Response Cache-Control Directives">Section&nbsp;3.2.2</a>
1559                        </td>
1560                     </tr>
1561                     <tr>
1562                        <td class="left">no-transform</td>
1563                        <td class="left"><a href="#cache-request-directive" title="Request Cache-Control Directives">Section&nbsp;3.2.1</a>, <a href="#cache-response-directive" title="Response Cache-Control Directives">Section&nbsp;3.2.2</a>
1564                        </td>
1565                     </tr>
1566                     <tr>
1567                        <td class="left">only-if-cached</td>
1568                        <td class="left"><a href="#cache-request-directive" title="Request Cache-Control Directives">Section&nbsp;3.2.1</a>
1569                        </td>
1570                     </tr>
1571                     <tr>
1572                        <td class="left">private</td>
1573                        <td class="left"><a href="#cache-response-directive" title="Response Cache-Control Directives">Section&nbsp;3.2.2</a>
1574                        </td>
1575                     </tr>
1576                     <tr>
1577                        <td class="left">proxy-revalidate</td>
1578                        <td class="left"><a href="#cache-response-directive" title="Response Cache-Control Directives">Section&nbsp;3.2.2</a>
1579                        </td>
1580                     </tr>
1581                     <tr>
1582                        <td class="left">public</td>
1583                        <td class="left"><a href="#cache-response-directive" title="Response Cache-Control Directives">Section&nbsp;3.2.2</a>
1584                        </td>
1585                     </tr>
1586                     <tr>
1587                        <td class="left">s-maxage</td>
1588                        <td class="left"><a href="#cache-response-directive" title="Response Cache-Control Directives">Section&nbsp;3.2.2</a>
1589                        </td>
1590                     </tr>
1591                     <tr>
1592                        <td class="left">stale-if-error</td>
1593                        <td class="left"><a href="#RFC5861" id="rfc.xref.RFC5861.1"><cite title="HTTP Cache-Control Extensions for Stale Content">[RFC5861]</cite></a>, <a href="">Section 4</a>
1594                        </td>
1595                     </tr>
1596                     <tr>
1597                        <td class="left">stale-while-revalidate</td>
1598                        <td class="left"><a href="#RFC5861" id="rfc.xref.RFC5861.2"><cite title="HTTP Cache-Control Extensions for Stale Content">[RFC5861]</cite></a>, <a href="">Section 3</a>
1599                        </td>
1600                     </tr>
1601                  </tbody>
1602               </table>
1603            </div>
1604         </div>
1605         <div id="header.field.registration">
1606            <h2 id="rfc.section.5.2"><a href="#rfc.section.5.2">5.2</a>&nbsp;<a href="#header.field.registration">Header Field Registration</a></h2>
1607            <p id="rfc.section.5.2.p.1">The Message Header Field Registry located at &lt;<a href=""></a>&gt; shall be updated with the permanent registrations below (see <a href="#RFC3864" id="rfc.xref.RFC3864.1"><cite title="Registration Procedures for Message Header Fields">[RFC3864]</cite></a>):
1608            </p>
1609            <div id="rfc.table.2">
1610               <div id="iana.header.registration.table"></div>
1611               <table class="tt full left" cellpadding="3" cellspacing="0">
1612                  <thead>
1613                     <tr>
1614                        <th>Header Field Name</th>
1615                        <th>Protocol</th>
1616                        <th>Status</th>
1617                        <th>Reference</th>
1618                     </tr>
1619                  </thead>
1620                  <tbody>
1621                     <tr>
1622                        <td class="left">Age</td>
1623                        <td class="left">http</td>
1624                        <td class="left">standard</td>
1625                        <td class="left"><a href="#header.age" id="rfc.xref.header.age.3" title="Age">Section&nbsp;3.1</a>
1626                        </td>
1627                     </tr>
1628                     <tr>
1629                        <td class="left">Cache-Control</td>
1630                        <td class="left">http</td>
1631                        <td class="left">standard</td>
1632                        <td class="left"><a href="#header.cache-control" id="rfc.xref.header.cache-control.3" title="Cache-Control">Section&nbsp;3.2</a>
1633                        </td>
1634                     </tr>
1635                     <tr>
1636                        <td class="left">Expires</td>
1637                        <td class="left">http</td>
1638                        <td class="left">standard</td>
1639                        <td class="left"><a href="#header.expires" id="rfc.xref.header.expires.4" title="Expires">Section&nbsp;3.3</a>
1640                        </td>
1641                     </tr>
1642                     <tr>
1643                        <td class="left">Pragma</td>
1644                        <td class="left">http</td>
1645                        <td class="left">standard</td>
1646                        <td class="left"><a href="#header.pragma" id="rfc.xref.header.pragma.3" title="Pragma">Section&nbsp;3.4</a>
1647                        </td>
1648                     </tr>
1649                     <tr>
1650                        <td class="left">Vary</td>
1651                        <td class="left">http</td>
1652                        <td class="left">standard</td>
1653                        <td class="left"><a href="#header.vary" id="rfc.xref.header.vary.2" title="Vary">Section&nbsp;3.5</a>
1654                        </td>
1655                     </tr>
1656                     <tr>
1657                        <td class="left">Warning</td>
1658                        <td class="left">http</td>
1659                        <td class="left">standard</td>
1660                        <td class="left"><a href="#header.warning" id="rfc.xref.header.warning.3" title="Warning">Section&nbsp;3.6</a>
1661                        </td>
1662                     </tr>
1663                  </tbody>
1664               </table>
1665            </div>
1666            <p id="rfc.section.5.2.p.2">The change controller is: "IETF ( - Internet Engineering Task Force".</p>
1667         </div>
1668      </div>
1669      <div id="security.considerations">
1670         <h1 id="rfc.section.6"><a href="#rfc.section.6">6.</a>&nbsp;<a href="#security.considerations">Security Considerations</a></h1>
1671         <p id="rfc.section.6.p.1">Caches expose additional potential vulnerabilities, since the contents of the cache represent an attractive target for malicious
1672            exploitation. Because cache contents persist after an HTTP request is complete, an attack on the cache can reveal information
1673            long after a user believes that the information has been removed from the network. Therefore, cache contents need to be protected
1674            as sensitive information.
1675         </p>
1676      </div>
1677      <div id="ack">
1678         <h1 id="rfc.section.7"><a href="#rfc.section.7">7.</a>&nbsp;<a href="#ack">Acknowledgments</a></h1>
1679         <p id="rfc.section.7.p.1">Much of the content and presentation of the caching design is due to suggestions and comments from individuals including:
1680            Shel Kaphan, Paul Leach, Koen Holtman, David Morris, and Larry Masinter.
1681         </p>
1682      </div>
1683      <h1 id="rfc.references"><a id="rfc.section.8" href="#rfc.section.8">8.</a> References
1684      </h1>
1685      <h2 id="rfc.references.1"><a href="#rfc.section.8.1" id="rfc.section.8.1">8.1</a> Normative References
1686      </h2>
1687      <table>
1688         <tr>
1689            <td class="reference"><b id="Part1">[Part1]</b></td>
1690            <td class="top"><a href="" title="Adobe Systems Incorporated">Fielding, R., Ed.</a>, <a href="" title="Alcatel-Lucent Bell Labs">Gettys, J.</a>, <a href="" title="Hewlett-Packard Company">Mogul, J.</a>, <a href="" title="Microsoft Corporation">Frystyk, H.</a>, <a href="" title="Adobe Systems Incorporated">Masinter, L.</a>, <a href="" title="Microsoft Corporation">Leach, P.</a>, <a href="" title="World Wide Web Consortium">Berners-Lee, T.</a>, <a href="" title="World Wide Web Consortium">Lafon, Y., Ed.</a>, and <a href="" title="greenbytes GmbH">J. Reschke, Ed.</a>, “<a href="">HTTP/1.1, part 1: URIs, Connections, and Message Parsing</a>”, Internet-Draft&nbsp;draft-ietf-httpbis-p1-messaging-14 (work in progress), April&nbsp;2011.
1691            </td>
1692         </tr>
1693         <tr>
1694            <td class="reference"><b id="Part2">[Part2]</b></td>
1695            <td class="top"><a href="" title="Adobe Systems Incorporated">Fielding, R., Ed.</a>, <a href="" title="Alcatel-Lucent Bell Labs">Gettys, J.</a>, <a href="" title="Hewlett-Packard Company">Mogul, J.</a>, <a href="" title="Microsoft Corporation">Frystyk, H.</a>, <a href="" title="Adobe Systems Incorporated">Masinter, L.</a>, <a href="" title="Microsoft Corporation">Leach, P.</a>, <a href="" title="World Wide Web Consortium">Berners-Lee, T.</a>, <a href="" title="World Wide Web Consortium">Lafon, Y., Ed.</a>, and <a href="" title="greenbytes GmbH">J. Reschke, Ed.</a>, “<a href="">HTTP/1.1, part 2: Message Semantics</a>”, Internet-Draft&nbsp;draft-ietf-httpbis-p2-semantics-14 (work in progress), April&nbsp;2011.
1696            </td>
1697         </tr>
1698         <tr>
1699            <td class="reference"><b id="Part4">[Part4]</b></td>
1700            <td class="top"><a href="" title="Adobe Systems Incorporated">Fielding, R., Ed.</a>, <a href="" title="Alcatel-Lucent Bell Labs">Gettys, J.</a>, <a href="" title="Hewlett-Packard Company">Mogul, J.</a>, <a href="" title="Microsoft Corporation">Frystyk, H.</a>, <a href="" title="Adobe Systems Incorporated">Masinter, L.</a>, <a href="" title="Microsoft Corporation">Leach, P.</a>, <a href="" title="World Wide Web Consortium">Berners-Lee, T.</a>, <a href="" title="World Wide Web Consortium">Lafon, Y., Ed.</a>, and <a href="" title="greenbytes GmbH">J. Reschke, Ed.</a>, “<a href="">HTTP/1.1, part 4: Conditional Requests</a>”, Internet-Draft&nbsp;draft-ietf-httpbis-p4-conditional-14 (work in progress), April&nbsp;2011.
1701            </td>
1702         </tr>
1703         <tr>
1704            <td class="reference"><b id="Part5">[Part5]</b></td>
1705            <td class="top"><a href="" title="Adobe Systems Incorporated">Fielding, R., Ed.</a>, <a href="" title="Alcatel-Lucent Bell Labs">Gettys, J.</a>, <a href="" title="Hewlett-Packard Company">Mogul, J.</a>, <a href="" title="Microsoft Corporation">Frystyk, H.</a>, <a href="" title="Adobe Systems Incorporated">Masinter, L.</a>, <a href="" title="Microsoft Corporation">Leach, P.</a>, <a href="" title="World Wide Web Consortium">Berners-Lee, T.</a>, <a href="" title="World Wide Web Consortium">Lafon, Y., Ed.</a>, and <a href="" title="greenbytes GmbH">J. Reschke, Ed.</a>, “<a href="">HTTP/1.1, part 5: Range Requests and Partial Responses</a>”, Internet-Draft&nbsp;draft-ietf-httpbis-p5-range-14 (work in progress), April&nbsp;2011.
1706            </td>
1707         </tr>
1708         <tr>
1709            <td class="reference"><b id="Part7">[Part7]</b></td>
1710            <td class="top"><a href="" title="Adobe Systems Incorporated">Fielding, R., Ed.</a>, <a href="" title="Alcatel-Lucent Bell Labs">Gettys, J.</a>, <a href="" title="Hewlett-Packard Company">Mogul, J.</a>, <a href="" title="Microsoft Corporation">Frystyk, H.</a>, <a href="" title="Adobe Systems Incorporated">Masinter, L.</a>, <a href="" title="Microsoft Corporation">Leach, P.</a>, <a href="" title="World Wide Web Consortium">Berners-Lee, T.</a>, <a href="" title="World Wide Web Consortium">Lafon, Y., Ed.</a>, and <a href="" title="greenbytes GmbH">J. Reschke, Ed.</a>, “<a href="">HTTP/1.1, part 7: Authentication</a>”, Internet-Draft&nbsp;draft-ietf-httpbis-p7-auth-14 (work in progress), April&nbsp;2011.
1711            </td>
1712         </tr>
1713         <tr>
1714            <td class="reference"><b id="RFC2119">[RFC2119]</b></td>
1715            <td class="top"><a href="" title="Harvard University">Bradner, S.</a>, “<a href="">Key words for use in RFCs to Indicate Requirement Levels</a>”, BCP&nbsp;14, RFC&nbsp;2119, March&nbsp;1997.
1716            </td>
1717         </tr>
1718         <tr>
1719            <td class="reference"><b id="RFC5234">[RFC5234]</b></td>
1720            <td class="top"><a href="" title="Brandenburg InternetWorking">Crocker, D., Ed.</a> and <a href="" title="THUS plc.">P. Overell</a>, “<a href="">Augmented BNF for Syntax Specifications: ABNF</a>”, STD&nbsp;68, RFC&nbsp;5234, January&nbsp;2008.
1721            </td>
1722         </tr>
1723      </table>
1724      <h2 id="rfc.references.2"><a href="#rfc.section.8.2" id="rfc.section.8.2">8.2</a> Informative References
1725      </h2>
1726      <table>
1727         <tr>
1728            <td class="reference"><b id="RFC1305">[RFC1305]</b></td>
1729            <td class="top"><a href="" title="University of Delaware, Electrical Engineering Department">Mills, D.</a>, “<a href="">Network Time Protocol (Version 3) Specification, Implementation</a>”, RFC&nbsp;1305, March&nbsp;1992.
1730            </td>
1731         </tr>
1732         <tr>
1733            <td class="reference"><b id="RFC2616">[RFC2616]</b></td>
1734            <td class="top"><a href="" title="University of California, Irvine">Fielding, R.</a>, <a href="" title="W3C">Gettys, J.</a>, <a href="" title="Compaq Computer Corporation">Mogul, J.</a>, <a href="" title="MIT Laboratory for Computer Science">Frystyk, H.</a>, <a href="" title="Xerox Corporation">Masinter, L.</a>, <a href="" title="Microsoft Corporation">Leach, P.</a>, and <a href="" title="W3C">T. Berners-Lee</a>, “<a href="">Hypertext Transfer Protocol -- HTTP/1.1</a>”, RFC&nbsp;2616, June&nbsp;1999.
1735            </td>
1736         </tr>
1737         <tr>
1738            <td class="reference"><b id="RFC3864">[RFC3864]</b></td>
1739            <td class="top"><a href="" title="Nine by Nine">Klyne, G.</a>, <a href="" title="BEA Systems">Nottingham, M.</a>, and <a href="" title="HP Labs">J. Mogul</a>, “<a href="">Registration Procedures for Message Header Fields</a>”, BCP&nbsp;90, RFC&nbsp;3864, September&nbsp;2004.
1740            </td>
1741         </tr>
1742         <tr>
1743            <td class="reference"><b id="RFC5226">[RFC5226]</b></td>
1744            <td class="top"><a href="" title="IBM">Narten, T.</a> and <a href="" title="Google">H. Alvestrand</a>, “<a href="">Guidelines for Writing an IANA Considerations Section in RFCs</a>”, BCP&nbsp;26, RFC&nbsp;5226, May&nbsp;2008.
1745            </td>
1746         </tr>
1747         <tr>
1748            <td class="reference"><b id="RFC5861">[RFC5861]</b></td>
1749            <td class="top"><a href="" title="Yahoo! Inc.">Nottingham, M.</a>, “<a href="">HTTP Cache-Control Extensions for Stale Content</a>”, RFC&nbsp;5861, April&nbsp;2010.
1750            </td>
1751         </tr>
1752      </table>
1753      <div id="changes.from.rfc.2616">
1754         <h1 id="rfc.section.A" class="np"><a href="#rfc.section.A">A.</a>&nbsp;<a href="#changes.from.rfc.2616">Changes from RFC 2616</a></h1>
1755         <p id="rfc.section.A.p.1">Make the specified age calculation algorithm less conservative. (<a href="#age.calculations" title="Calculating Age">Section&nbsp;2.3.2</a>)
1756         </p>
1757         <p id="rfc.section.A.p.2">Remove requirement to consider Content-Location in successful responses in order to determine the appropriate response to
1758            use. (<a href="#validation.model" title="Validation Model">Section&nbsp;2.4</a>)
1759         </p>
1760         <p id="rfc.section.A.p.3">Clarify denial of service attack avoidance requirement. (<a href="#invalidation.after.updates.or.deletions" title="Request Methods that Invalidate">Section&nbsp;2.5</a>)
1761         </p>
1762         <p id="rfc.section.A.p.4">Change ABNF productions for header fields to only define the field value. (<a href="#header.fields" title="Header Field Definitions">Section&nbsp;3</a>)
1763         </p>
1764         <p id="rfc.section.A.p.5">Do not mention RFC 2047 encoding and multiple languages in Warning header fields anymore, as these aspects never were implemented.
1765            (<a href="#header.warning" id="rfc.xref.header.warning.4" title="Warning">Section&nbsp;3.6</a>)
1766         </p>
1767      </div>
1768      <div id="collected.abnf">
1769         <h1 id="rfc.section.B"><a href="#rfc.section.B">B.</a>&nbsp;<a href="#collected.abnf">Collected ABNF</a></h1>
1770         <div id="rfc.figure.u.18"></div><pre class="inline"><a href="#header.age" class="smpl">Age</a> = delta-seconds
1772<a href="#header.cache-control" class="smpl">Cache-Control</a> = *( "," OWS ) cache-directive *( OWS "," [ OWS
1773 cache-directive ] )
1775<a href="#header.expires" class="smpl">Expires</a> = HTTP-date
1777<a href="#abnf.dependencies" class="smpl">HTTP-date</a> = &lt;HTTP-date, defined in [Part1], Section 6.1&gt;
1779<a href="#core.rules" class="smpl">OWS</a> = &lt;OWS, defined in [Part1], Section 1.2.2&gt;
1781<a href="#header.pragma" class="smpl">Pragma</a> = *( "," OWS ) pragma-directive *( OWS "," [ OWS
1782 pragma-directive ] )
1784<a href="#header.vary" class="smpl">Vary</a> = "*" / ( *( "," OWS ) field-name *( OWS "," [ OWS field-name ]
1785 ) )
1787<a href="#header.warning" class="smpl">Warning</a> = *( "," OWS ) warning-value *( OWS "," [ OWS warning-value ]
1788 )
1790<a href="#header.cache-control" class="smpl">cache-directive</a> = cache-request-directive / cache-response-directive
1791<a href="#header.cache-control" class="smpl">cache-extension</a> = token [ "=" ( token / quoted-string ) ]
1792<a href="#header.cache-control" class="smpl">cache-request-directive</a> = "no-cache" / "no-store" / ( "max-age="
1793 delta-seconds ) / ( "max-stale" [ "=" delta-seconds ] ) / (
1794 "min-fresh=" delta-seconds ) / "no-transform" / "only-if-cached" /
1795 cache-extension
1796<a href="#header.cache-control" class="smpl">cache-response-directive</a> = "public" / ( "private" [ "=" DQUOTE *( ","
1797 OWS ) field-name *( OWS "," [ OWS field-name ] ) DQUOTE ] ) / (
1798 "no-cache" [ "=" DQUOTE *( "," OWS ) field-name *( OWS "," [ OWS
1799 field-name ] ) DQUOTE ] ) / "no-store" / "no-transform" /
1800 "must-revalidate" / "proxy-revalidate" / ( "max-age=" delta-seconds
1801 ) / ( "s-maxage=" delta-seconds ) / cache-extension
1803<a href="" class="smpl">delta-seconds</a> = 1*DIGIT
1805<a href="#header.pragma" class="smpl">extension-pragma</a> = token [ "=" ( token / quoted-string ) ]
1807<a href="#abnf.dependencies" class="smpl">field-name</a> = &lt;field-name, defined in [Part1], Section 3.2&gt;
1809<a href="#abnf.dependencies" class="smpl">port</a> = &lt;port, defined in [Part1], Section 2.6&gt;
1810<a href="#header.pragma" class="smpl">pragma-directive</a> = "no-cache" / extension-pragma
1811<a href="#abnf.dependencies" class="smpl">pseudonym</a> = &lt;pseudonym, defined in [Part1], Section 9.9&gt;
1813<a href="#core.rules" class="smpl">quoted-string</a> = &lt;quoted-string, defined in [Part1], Section 1.2.2&gt;
1815<a href="#core.rules" class="smpl">token</a> = &lt;token, defined in [Part1], Section 1.2.2&gt;
1817<a href="#abnf.dependencies" class="smpl">uri-host</a> = &lt;uri-host, defined in [Part1], Section 2.6&gt;
1819<a href="#header.warning" class="smpl">warn-agent</a> = ( uri-host [ ":" port ] ) / pseudonym
1820<a href="#header.warning" class="smpl">warn-code</a> = 3DIGIT
1821<a href="#header.warning" class="smpl">warn-date</a> = DQUOTE HTTP-date DQUOTE
1822<a href="#header.warning" class="smpl">warn-text</a> = quoted-string
1823<a href="#header.warning" class="smpl">warning-value</a> = warn-code SP warn-agent SP warn-text [ SP warn-date
1824 ]
1825</pre><div id="rfc.figure.u.19"></div>
1826         <p>ABNF diagnostics:</p><pre class="inline">; Age defined but not used
1827; Cache-Control defined but not used
1828; Expires defined but not used
1829; Pragma defined but not used
1830; Vary defined but not used
1831; Warning defined but not used
