diff --git a/jeeutil/src/main/java/de/muehlencord/shared/jeeutil/OwaspStandardFilter.java b/jeeutil/src/main/java/de/muehlencord/shared/jeeutil/OwaspStandardFilter.java index ff3d46b..6e7f699 100644 --- a/jeeutil/src/main/java/de/muehlencord/shared/jeeutil/OwaspStandardFilter.java +++ b/jeeutil/src/main/java/de/muehlencord/shared/jeeutil/OwaspStandardFilter.java @@ -51,6 +51,13 @@ public class OwaspStandardFilter implements Filter { // The only defined value, "nosniff", prevents Internet Explorer from MIME-sniffing a response away from the declared content-type. // This also applies to Google Chrome, when downloading extensions. res.addHeader("X-Content-Type-Options", "nosniff"); + + // disableing caching by Pragma setting + res.addHeader("Pragma", "no-cache"); + + // disabling caching by Cache-control settings + res.addHeader("Cache-control", "no-cache, no-store, must-revalidate, private"); + chain.doFilter(request, response); }