From b417f5c9b22e4f67fc6c8c2f409fddb9d78a6fca Mon Sep 17 00:00:00 2001 From: Hermes Date: Fri, 2 Oct 2026 02:43:27 +0000 Subject: [PATCH] fixes: no-store cache headers on agent-facing routes; stale command cleanup --- server.js | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/server.js b/server.js index 3655a15..f616e32 100644 --- a/server.js +++ b/server.js @@ -51,6 +51,15 @@ function authMiddleware(req, res, next) { return res.status(401).json({ error: 'unauthorized' }); } app.use(authMiddleware); + +// Agent-facing files must never be edge-cached (stale-agent incident 2026-10-01) +app.use((req, res, next) => { + if (req.path.startsWith('/agent.py') || req.path.startsWith('/install') || req.path.startsWith('/bin/')) { + res.setHeader('Cache-Control', 'no-store, must-revalidate'); + res.setHeader('CF-Cache-Status', 'BYPASS'); + } + next(); +}); app.get('/api/auth/check', (req, res) => { if (!AUTH_TOKEN) return res.json({ ok: true, authRequired: false }); res.json({ ok: true, authRequired: true });