Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Do not expose version numbers via the js and css cache busting mechanism #201

markkap opened this Issue Dec 21, 2018 · 0 comments


None yet
1 participant
Copy link

markkap commented Dec 21, 2018

Right now each JS and CSS url is a appended with a cache busting parameter of the style of ver=1.0.0.
While it is not too hard to guess the core version from the actual content of the files, we still want to minimize the number of ways to do it, and therefor at the very least the version number should be replaced with something which is not directly the core version number.

First idea that comes into my mind right now is and MD5 of the version number concatenated with one of the "nonce" related random number, or maybe even just with the site's url.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
You can’t perform that action at this time.