为何Cloudflare对隐私浏览器返回缓存结果、常规浏览器返回动态结果?
问题描述
网站采用Bluehost提供的缓存服务,预期仅缓存图片、脚本等静态资源。但出现以下异常:
- 常规浏览器访问动态URL(如
https://sitename.foo/some_path)时,响应头返回Cf-Cache-Status: DYNAMIC,符合动态页面不缓存的预期; - 隐私浏览器访问同一URL时,返回旧内容,响应头显示
Cf-Cache-Status: HIT; - 该差异在Chrome、Firefox中多次测试均一致,清除常规浏览器Cookie后也会出现相同情况;
- 不仅普通页面URL,表单POST URL也存在此问题,且POST请求头包含
Pragma: no-cache和Cache-Control: no-cache。
请求响应头对比
Firefox常规浏览器(带Cookie)
请求头
GET /<somepath>/ HTTP/2 Host: <somehost> User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:135.0) Gecko/20100101 Firefox/135.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-US,en;q=0.5 Accept-Encoding: gzip, deflate, br, zstd Connection: keep-alive Cookie: <some cookies> Upgrade-Insecure-Requests: 1 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 Priority: u=0, i
响应头
HTTP/2 200 date: Thu, 27 Feb 2025 03:13:27 GMT content-type: text/html; charset=UTF-8 x-content-type-options: nosniff vary: Accept-Encoding host-header: c2hhcmVkLmJsdWVob3N0LmNvbQ== x-newfold-cache-level: 1 x-endurance-cache-level: 2 x-nginx-cache: WordPress cf-cache-status: DYNAMIC set-cookie: <some cookies> SameSite=None server: cloudflare cf-ray: 9184ffbf1d04df10-SEA content-encoding: gzip X-Firefox-Spdy: h2
Firefox隐私浏览器(无Cookie,带DNT)
请求头
GET /<somepath>/ HTTP/2 Host: <somehost> User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:135.0) Gecko/20100101 Firefox/135.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-US,en;q=0.5 Accept-Encoding: gzip, deflate, br, zstd DNT: 1 Sec-GPC: 1 Connection: keep-alive Upgrade-Insecure-Requests: 1 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 Priority: u=0, i
响应头
HTTP/2 200 date: Thu, 27 Feb 2025 03:16:25 GMT content-type: text/html; charset=UTF-8 x-content-type-options: nosniff vary: Accept-Encoding host-header: c2hhcmVkLmJsdWVob3N0LmNvbQ== x-newfold-cache-level: 1 x-endurance-cache-level: 2 x-nginx-cache: WordPress last-modified: Thu, 27 Feb 2025 03:16:25 GMT cf-cache-status: HIT set-cookie: <some cookies> server: cloudflare cf-ray: 91850416bc4d680a-SEA content-encoding: gzip X-Firefox-Spdy: h2
原因解析
Cloudflare的Cookie缓存规则
Cloudflare默认会对携带Cookie的请求跳过缓存(返回DYNAMIC),因为带Cookie的请求通常对应个性化内容,不适合缓存。而隐私浏览器首次访问时无Cookie,Cloudflare判定该请求为非个性化请求,触发缓存命中逻辑,返回之前缓存的内容。Bluehost多层缓存的影响
从响应头的x-newfold-cache-level、x-endurance-cache-level和x-nginx-cache: WordPress可以看出,网站同时启用了Bluehost的Newfold/Endurance缓存层和WordPress的Nginx缓存。这些缓存层可能提前缓存了动态页面的响应,且返回给Cloudflare的响应头未明确标记为不可缓存(比如缺少Cache-Control: private或no-store),导致Cloudflare将该响应纳入缓存范围,当无Cookie请求到来时返回缓存内容。POST请求被缓存的异常原因
按HTTP规范,POST请求默认不应被缓存,但这里出现缓存命中,原因可能包括:
- 客户端的
Pragma: no-cache和Cache-Control: no-cache是客户端指令,服务器端(包括Cloudflare和Bluehost缓存层)若未严格遵守,仍可能缓存响应; - Bluehost的缓存层可能错误地缓存了POST请求的响应,之后Cloudflare又缓存了该结果,当无Cookie的POST请求到来时,触发缓存命中;
- Cloudflare的缓存规则被Bluehost的配置覆盖,允许缓存POST请求的响应。
内容的提问来源于stack exchange,提问作者Denise Draper
相关产品推荐
相关产品推荐

