Skip to content
Backend40-60 min

HTTP Caching and Cache-Control Headers

Use immutable caching for hashed assets, no-store for private data, and short revalidation windows for semi-dynamic public responses.

HTTPExpressNginxCDN

Prerequisites

  • A deployed app or local reverse proxy.
  • Knowledge of which routes are public, private, or static.
  • Access to server or hosting headers configuration.
1

Plan the implementation

Start by choosing the exact page, route, API, or deployment surface you want to improve. A narrow target makes the implementation measurable and easier to verify.

  1. Write down the current behavior and the user-facing problem it creates.
  2. Pick one measurable success signal such as bundle size, latency, error rate, security coverage, or UI responsiveness.
  3. Identify the files, routes, providers, and environment variables involved.
  4. Create a rollback note before changing production-sensitive configuration.
2

Set up the required tools

Install or configure only the tools needed for this implementation. Keep config close to the feature so future developers can find the moving parts quickly.

Implementation snippet
curl -I https://example.com/assets/app.js
curl -I https://example.com/api/me
Checklist
  • Dependencies are added to the correct workspace package.
  • Environment variables are documented in `.env.example` when needed.
  • Local development still starts without production-only secrets.
  • The change is small enough to review in one pull request.
3

Implement the core pattern

  1. Classify responses as immutable static, public dynamic, or private user data.
  2. Cache hashed assets for a long time with `immutable`.
  3. Mark authenticated and sensitive responses as `no-store`.
  4. Use `stale-while-revalidate` for public data that can be briefly stale.
  5. Verify final headers with `curl -I` and browser DevTools.
Implementation snippet
app.use("/assets", express.static("dist/assets", {
  immutable: true,
  maxAge: "1y",
}));

app.get("/api/me", requireAuth, (req, res) => {
  res.set("Cache-Control", "no-store");
  res.json({ user: req.user });
});
4

Handle edge cases

Checklist
  • Private user data is not cached by browsers or CDNs.
  • Hashed assets can be cached for one year.
  • HTML has short caching or revalidation behavior.
  • CDN rules do not override application safety headers incorrectly.
5

Verify before production

  1. Run the app locally and test the normal success path.
  2. Test one failure path, one empty state, and one slow-network or retry path.
  3. Run the project build and any related unit or integration tests.
  4. Check browser console, server logs, and network responses for hidden warnings.
  5. Document the final behavior, commands used, and any follow-up work.

Need implementation help?

Want this built correctly in your codebase?

Send us your stack, repo context, and the feature you need. We will help you implement it cleanly and hand over the working code.

Free scoping callFixed timelineFull source ownership
Get implementation help