diff --git a/app/controllers/api/v1/accounts_controller.rb b/app/controllers/api/v1/accounts_controller.rb index ce54225ba..46087ec36 100644 --- a/app/controllers/api/v1/accounts_controller.rb +++ b/app/controllers/api/v1/accounts_controller.rb @@ -50,7 +50,6 @@ class Api::V1::AccountsController < Api::BaseController end def cache_keys - expires_in 10.seconds, public: false, stale_while_revalidate: 5.minutes render json: { cache_keys: cache_keys_for_account }, status: :ok end diff --git a/spec/controllers/api/v1/accounts_controller_spec.rb b/spec/controllers/api/v1/accounts_controller_spec.rb index 929d39543..1a67e441c 100644 --- a/spec/controllers/api/v1/accounts_controller_spec.rb +++ b/spec/controllers/api/v1/accounts_controller_spec.rb @@ -216,14 +216,15 @@ RSpec.describe 'Accounts API', type: :request do expect(response.parsed_body['cache_keys'].keys).to match_array(%w[account_user canned_response custom_attribute_definition inbox label team]) end - it 'sets the appropriate cache headers' do + it 'does not allow cached cache key responses' do get "/api/v1/accounts/#{account.id}/cache_keys", headers: admin.create_new_auth_token, as: :json - expect(response.headers['Cache-Control']).to include('max-age=10') + expect(response.headers['Cache-Control']).to include('max-age=0') expect(response.headers['Cache-Control']).to include('private') - expect(response.headers['Cache-Control']).to include('stale-while-revalidate=300') + expect(response.headers['Cache-Control']).to include('must-revalidate') + expect(response.headers['Cache-Control']).not_to include('stale-while-revalidate') end end