Storing Responses in Caches
A cache MUST NOT store a response to any request, unless:
- The request method is understood by the cache and defined as being cacheable, and
- the response status code is understood by the cache, and
- the "no-store" cache directive (see Section 5.2) does not appear in request or response header fields, and
- the "private" response directive (see Section 5.2.2.6) does not appear in the response, if the cache is shared, and
- the Authorization header field (see Section 4.2 of
[RFC7235]) does not appear in the request, if the cache is shared, unless the response explicitly allows it (see Section 3.2), and - the response either:
- contains an Expires header field (see Section 5.3), or
- contains a max-age response directive (see Section 5.2.2.8), or
- contains a s-maxage response directive (see Section 5.2.2.9) and the cache is shared, or
- contains a Cache Control Extension (see Section 5.2.3) that allows it to be cached, or
- has a status code that is defined as cacheable by default (see Section 4.2.2), or
- contains a public response directive (see Section 5.2.2.5).
Note that any of the requirements listed above can be overridden by a cache-control extension; see Section 5.2.3.
In this context, a cache has "understood" a request method or a response status code if it recognizes it and implements all specified caching-related behavior.
Note that, in normal operation, some caches will not store a response that has neither a cache validator nor an explicit expiration time, as such responses are not usually useful to store. However, caches are not prohibited from storing such responses.