SIGN IN SIGN UP

[ResponseCaching] Correctly handle Vary: * in delimited or multi-value headers (RFC 9111) (#69210)

* Do not cache responses with Vary: * across multiple or delimited headers

- Comply with RFC 9111 § 4.1 by inspecting each delimited token within Vary headers.
- Iterate StringValues directly with StringTokenizer to prevent string allocations on hot paths.
- Add unit and integration tests covering multi-entry and delimited '*' headers.

Fixes #69192

* Use Span.Split for zero-allocation Vary header tokenization

* Update src/Middleware/ResponseCaching/src/ResponseCachingPolicyProvider.cs

Co-authored-by: Jiri Cincura ↹ <jiri@cincura.net>

* Update src/Middleware/ResponseCaching/src/ResponseCachingPolicyProvider.cs

Co-authored-by: Jiri Cincura ↹ <jiri@cincura.net>

---------

Co-authored-by: Jiri Cincura ↹ <jiri@cincura.net>
A
Ahmed Sadman Sadik committed
04421bcb45123eafa346bdff1f9c23f289095292
Parent: cc827b0
Committed by GitHub <noreply@github.com> on 9/11/2026, 11:42:52 AM