Skip to content

Send Vary: Authorization with moderation counts - #235

Merged
admdly merged 1 commit into
mainfrom
extensions/moderation-counts-vary
Sep 17, 2026
Merged

admdly merged 1 commit into
mainfrom
extensions/moderation-counts-vary

Conversation

@admdly

@admdly admdly commented Sep 17, 2026

Copy link
Copy Markdown
Contributor

Follow-up to #234, addressing the cubic review thread: the authenticated GET /moderation/counts response now sets Vary: Authorization, matching the revisions queue route, so intermediaries can't serve moderator-only counts across authorization headers. The counts test asserts the header.

@admdly admdly self-assigned this Sep 17, 2026

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 2 files

Auto-approved: Adds a Vary: Authorization header to the moderation counts endpoint to prevent intermediaries from caching moderator-specific responses across users, with a test asserting the header.

Re-trigger cubic

@admdly
admdly merged commit 3b17c2e into main Sep 17, 2026
9 checks passed
@admdly
admdly deleted the extensions/moderation-counts-vary branch September 17, 2026 20:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant