PAC cached for more than a day
low
A max-age of several days means a wrong or outdated PAC stays active on clients for that long. Keep the window at or below one day so that fixes propagate within a working day.
Why it matters
The cache lifetime is the upper bound on how long a mistake lives. With max-age=604800
a PAC that routes a critical application wrongly cannot be fixed centrally within the week
unless every client is restarted. One day is a practical maximum; ten minutes to one hour is
typical where proxy failover is managed through the PAC.
How to fix
Lower max-age to 86400 or less (3600 is a common choice).
Examples
Bad
HTTP/1.1 200 OK
Content-Type: application/x-ns-proxy-autoconfig
Cache-Control: max-age=2592000
Open bad example in checkerGood
HTTP/1.1 200 OK
Content-Type: application/x-ns-proxy-autoconfig
Cache-Control: max-age=3600
Open good example in checkerRelated rules
- No Cache-Control header on the PAC response PAC-D003
- PAC marked no-cache / no-store / max-age=0 PAC-D004