Be very careful with 301 and 308 redirects

Updated . Posted . Visible to the public. Repeats.

Browsers support different types of redirects.

Be very careful with these status codes:

  • 301 Moved Permanently
  • 308 Permanent Redirect

Most browsers seem to cache these redirects forever, unless you set different Cache-Control headers. If you don't have any cache control headers, you can never change them without forcing users to empty their cache.

Note

By default Show archive.org snapshot Rails sends a header Cache-Control: max-age=0, private, must-revalidate with all responses, including redirects. That means redirects are never cached by browsers.

You do need to pay attention if you redirect outside of Rails, e.g. via your web server configuration.

Dealing with incorrectly cached redirects

The only fix is to keep redirecting the user to the correct page, so if you had

301
/page1
/page2

but you want

301
/page1
/page3

your only fix is to change it to

301
301
/page1
/page2
/page3

This means that /page2 will become unusable as its own page.

Note that a 301 with an explicit expiry via Cache-Control is fine, and might be preferred for SEO purposes.


Related: Rails: Default HTTP status codes when redirecting

Tobias Kraze
Last edit
Dominik Schöler
Keywords
http, redirect_to
License
Source code in this card is licensed under the MIT License.
Posted by Tobias Kraze to makandra dev (2017-09-14 15:25)