HTTP headers that matter
Caching and content negotiation live in headers. `Cache-Control` decides whether your CDN does any work at all.
#http#cache#cors#headers
text
Content-Type: application/json
Accept: application/json
Authorization: Bearer <token>
Cache-Control: public, max-age=31536000, immutable # hashed assets
Cache-Control: no-store # personal data
ETag / If-None-Match # 304 revalidation
Access-Control-Allow-Origin: https://example.com # CORS
Retry-After: 30 # with 429 / 503