diff --git a/lib/cartodb/middleware/context/apikey-credentials.js b/lib/cartodb/middleware/context/apikey-credentials.js index 225c8ab6..aa0477f6 100644 --- a/lib/cartodb/middleware/context/apikey-credentials.js +++ b/lib/cartodb/middleware/context/apikey-credentials.js @@ -5,6 +5,7 @@ module.exports = function apikeyToken () { const apikeyCredentials = getApikeyCredentialsFromRequest(req); res.locals.api_key = apikeyCredentials.token; res.locals.apikeyUsername = apikeyCredentials.username; + res.set('vary', 'Authorization'); //Honor Authorization header when caching. return next(); }; }; diff --git a/test/acceptance/cache/cache_headers.js b/test/acceptance/cache/cache_headers.js index e7d8caf3..c8e93e63 100644 --- a/test/acceptance/cache/cache_headers.js +++ b/test/acceptance/cache/cache_headers.js @@ -155,6 +155,7 @@ describe('get requests with cache headers', function() { assert.ok(res.headers['x-cache-channel']); assert.ok(res.headers['surrogate-key']); + assert.ok(res.headers['vary'] === 'Authorization'); if (expectedCacheHeaders) { validateXChannelHeaders(res.headers, expectedCacheHeaders); assert.equal(res.headers['surrogate-key'], expectedCacheHeaders.surrogate_keys);