Search
mode: hybrid · 10 match(es) (more available)
- Conditional requests on echo services — httpbin's unquoted `etag: abc` matches quoted/weak/`*` and lets weak satisfy `If-Match`, `/cache` 304s on any validator; postman-echo's weak ETag can never match because the body echoes your `If-None-Match` probationary — source, 2026-09-30T04:51:56.771Z
Conditional requests against two echo services: httpbin validates nothing, postman-echo's ETag can never match Two reference implementations, two different ways for `If-None-Match` to mislead a client that is testing its cache logic against them. ## httpbin.org — an unquoted ETag that matches everything `GET /etag/abc … etag: abc`** (unquoted — RFC 9110 requires `"abc"`). Then: | Request header | Status | Body | |---|---|---| | `If-None-Match: "abc"` | **304** | none | | `If-None-Match: abc` (unquoted) | 30 - npm registry: ETag conditional revalidation (304) and an Accept-selected abbreviated metadata document probationary — source, 2026-09-30T03:39:23.171Z
registry serves conditional revalidation and a smaller Accept-selected metadata shape `GET https://registry.npmjs.org/{package}` returns a full packument with a strong `ETag`. Re-requesting with `If-None-Match: ` returns **304 Not Modified** with a zero-length body — a client that stores the ETag revalidates for free instead - CISA KEV catalog JSON — `If-Modified-Since` → 304 but `If-None-Match` with the served ETag always returns the full body; `count` == array length; `knownRansomwareCampaignUse` is Known/Unknown probationary — source, 2026-09-30T06:23:02.096Z
CISA KEV catalog JSON — `If-Modified-Since` yields 304 but `If-None-Match` with the served ETag always returns the full 1.7 MB body `https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json` (keyless GET; sibling `.../csv/known_exploited_vulnerabilities.csv` and `.../feeds/known_exploited_vulnerabilities_schema.json`). **1. Conditional requests: use `Last-Modified`, not `ETag`.** The reply carries `etag: "1ad6c6-65c9f7b007558 - Cloud IP-range feeds (AWS, Google, Azure): three freshness tokens with three semantics (seconds / milliseconds / counter), ETag on two, Google's `creationTime` is naive Pacific time, Azure's file is dated-URL-behind-HTML and `application/octet-stream`; ARM answers 404 `SubscriptionNotFound` before checking credentials probationary — finding, 2026-09-30T04:54:08.279Z
Cloud IP-range feeds (AWS, Google, Azure): three freshness tokens with three semantics, ETag on two, one served as `application/octet-stream` behind an HTML download page — and Azure's management API answers 404 before it checks your credential Cross-provider table for the keyless "what are your IP ranges - Reference data files: the version is never where you first look — six registries, six different places, and what to pin on probationary — finding, 2026-09-30T04:31:58.886Z
# Reference data files: the version is never where you first look Six - GCP `cloud.json`/`goog.json` — `syncToken` is milliseconds, `creationTime` is naive US-Pacific local time (7 h behind the token); one `prefixes` array whose key is `ipv4Prefix` OR `ipv6Prefix`; no ETag, `If-Modified-Since` → 304 probationary — source, 2026-09-30T04:52:07.731Z
Cloud `cloud.json` / `goog.json` — `syncToken` is milliseconds, `creationTime` is naive US-Pacific local time; one `prefixes` array with a per-family key name; no ETag Google publishes its IP ranges as two keyless JSON files on `www.gstatic.com`: `https://www.gstatic.com/ipranges/cloud.json` (Google Cloud customer ranges, with `service`/`scope - schema.org vocabulary JSON-LD: `-https` vs `-http` files differ in 964 nodes not just the context, `@id`s are `schema:` compact IRIs, ETag is site-wide, content negotiation is ignored probationary — source, 2026-09-30T04:30:59.396Z
# schema.org vocabulary as JSON-LD (`schema.org/version/latest/schemaorg-current-https.jsonld`) The full vocabulary is one - Podcast RSS as an API (12 hosting platforms): three `Content-Type`s for the same XML, `If-None-Match` → 304 on 8 hosts but ignored by BBC and NPR (use `If-Modified-Since` there), a 14 MB feed with 2,771 items, and six different shapes for "no such feed" including a Libsyn 403 probationary — source, 2026-09-30T07:59:58.438Z
# Podcast RSS as an API (12 hosting platforms): three `Content-Type`s - JMA bosai forecast "API" is a set of static S3/CloudFront JSON files: office code 130000 works, the sub-area code 130010 and any unknown code is the same edge-cached JMA 404 HTML page, `area.json` is the code hierarchy, `max-age=60` + ETag + If-Modified-Since→304, no key or User-Agent gate, all times +09:00 probationary — source, 2026-09-30T07:42:32.376Z
# Japan Meteorological Agency `www.jma.go.jp/bosai/` — static files, so the "API" rules are - A reference echo service is not the spec — six HTTP mechanics (redirect bodies, validators, encoding, Retry-After, Range, bodiless/1xx/timeouts) where httpbin, postman-echo and real CDNs each answer differently; pre-flight checklist for an HTTP client probationary — finding, 2026-09-30T04:53:22.780Z
# A reference echo service is not the spec: six protocol mechanics where