Skip to content

webui: rely on the HTTP cache headers instead of cache busting - #157

Merged
jens-maus merged 1 commit into
mainfrom
jens-maus/webui-cache-control
Oct 9, 2026
Merged

jens-maus merged 1 commit into
mainfrom
jens-maus/webui-cache-control

Conversation

@jens-maus

@jens-maus jens-maus commented Oct 9, 2026 •

Copy link
Copy Markdown
Member

Original OpenCCU rootfs patch: 0026
Original filename: 0026-WebUI-Fix-CacheControl.patch
Original patch: https://github.com/OpenCCU/OpenCCU/blob/fa019f34f/buildroot-external/package/openccu-base/rootfs-patches/0026-WebUI-Fix-CacheControl.patch
Original changes: OpenCCU/OpenCCU@165dc091f (OpenCCU/OpenCCU#245) and OpenCCU/OpenCCU@12c017c26

The WebUI tried to avoid stale browser caches in several ad hoc ways: _version_ and AvoidBrowserCache URL parameters, cache: false in jQuery requests, and cache-control meta tags (also emitted by put_meta_nocache in the device parameter pages). These either did not help after an update or prevented caching altogether. OpenCCU instead sends Cache-Control: private, no-cache, must-revalidate, no-transform, max-age=0 for non-image files (max-age=120 for images) from its lighttpd configuration, so browsers revalidate with ETags. ReGaHss itself answers with Cache-Control: no-store, no-cache.

This is the second of three migrations that depend on each other: 0002 (Bootstrap, #155) is in, and 0036 (favicons) uses context lines changed here.

This applies the patch 1:1:

  • src/webui/rega/www/login.htm, logout.htm, pages/index.htm, index.htm, src/webui/www/error/error-500.html, error-503.html, src/webui/www/tools/designer.html: no _version_ parameters and no cache-control meta tags.
  • src/webui/www/tools/js/common/httploader.js and src/webui/www_source/webui/js/common/httploader.js: no _version_ parameter (addVersion() removed).
  • src/webui/www_source/config/js/ic_common.js: no AvoidBrowserCache parameter. src/webui/www/config/ic_common.tcl and ic_neweasymode.cgi no longer list it in IGNORE_PARAMS. In this repository it was only added by this function.
  • src/webui/www/config/ic_common.tcl: put_meta_nocache is removed together with all its callers (ic_common.tcl, ic_ifacecmd.cgi); no other caller exists in this repository.
  • src/webui/www/webui/js/lang/loadTextResource.js and src/webui/www_source/webui/js/headerbar.js: no cache: false (the language files are still executed as scripts, jQuery detects them by their application/javascript content type).
  • src/webui/www_source/webui/js/homematic.com.js: the version and firmware checks against the eQ-3 servers get a ts=<Date.now()> parameter, because their responses are not under the control of the local web server.
  • src/webui/www/config/cp_maintenance.cgi: the EULA request uses cache: false, and the software update dialog no longer asks to clear the browser cache after the update (dialogSettingsCMDialogPerformSoftwareUpdateP2/Li1-Li3).

webui.js is assembled from www_source, so its five hunks of the rootfs patch are applied to httploader.js, headerbar.js, homematic.com.js (two hunks) and config/js/ic_common.js. Encodings and line endings are preserved (CRLF files: ic_common.tcl, ic_neweasymode.cgi, the error pages, index.htm, tools/js/common/httploader.js, and the www_source files except config/js/ic_common.js). The root www/ copies are unused legacy files and are left unchanged.

Other OpenCCU rootfs patches also modify these files (among them 0001, 0007, 0008, 0012, 0031, 0036, 0119, 0135, 0149, 0154, 0163-0165 and 0173). They still apply with zero fuzz.

Validation

  • OpenCCU scripts/base-patch-migration.py validate with the canonical Buildroot 2026.08 git4 archive of this branch (43d94689, sha256 0c2336d85afa6be5496b26898234a125bd363308fffb148bfa188a5dd9d008fd) and --skip-patch 0026: PASS (the other 64 rootfs patches apply with zero fuzz).
  • compare against the current pin baseline (b9ce345d, all 65 patches as of build(openccu-base): migrate patch 0002 OpenCCU#4399): IDENTICAL (4668 entries).

OpenCCU cleanup PR (removing patch 0026 and updating the pin): OpenCCU/OpenCCU#4403


Generated by Claude Code

Summary by CodeRabbit

  • Updates
    • Removed fixed version parameters and cache-bypass settings from web interface pages and requests.
    • Firmware and device-firmware checks now include a timestamp in their requests.
    • Simplified the firmware-update progress message by removing its step-by-step details.

Generated by Claude Code

The WebUI tried to avoid stale browser caches in several ad hoc ways:
_version_ and AvoidBrowserCache URL parameters, cache: false in jQuery
requests and cache-control meta tags (also emitted by put_meta_nocache
in the device parameter pages). These either did not help after an
update or prevented caching altogether.

Remove them, and rely on the Cache-Control response headers of the web
server, which let browsers revalidate the files with ETags. The update
dialog no longer asks to clear the browser cache after an update. The
EULA is loaded with cache: false, and the version checks against the
eQ-3 servers get a timestamp parameter because their responses are not
under the control of the local web server.
@coderabbitai

coderabbitai Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 4172264f-623a-450f-a647-83d8f73013fa

📥 Commits

Reviewing files that changed from the base of the PR and between b9ce345 and 43d9468.


📒 Files selected for processing (17)
  • src/webui/rega/www/index.htm
  • src/webui/rega/www/login.htm
  • src/webui/rega/www/logout.htm
  • src/webui/rega/www/pages/index.htm
  • src/webui/www/config/cp_maintenance.cgi
  • src/webui/www/config/ic_common.tcl
  • src/webui/www/config/ic_ifacecmd.cgi
  • src/webui/www/config/ic_neweasymode.cgi
  • src/webui/www/error/error-500.html
  • src/webui/www/error/error-503.html
  • src/webui/www/tools/designer.html
  • src/webui/www/tools/js/common/httploader.js
  • src/webui/www/webui/js/lang/loadTextResource.js
  • src/webui/www_source/config/js/ic_common.js
  • src/webui/www_source/webui/js/common/httploader.js
  • src/webui/www_source/webui/js/headerbar.js
  • src/webui/www_source/webui/js/homematic.com.js

💤 Files with no reviewable changes (7)
  • src/webui/www/config/ic_ifacecmd.cgi
  • src/webui/www/tools/designer.html
  • src/webui/rega/www/index.htm
  • src/webui/www_source/config/js/ic_common.js
  • src/webui/www_source/webui/js/headerbar.js
  • src/webui/www/tools/js/common/httploader.js
  • src/webui/www_source/webui/js/common/httploader.js

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.



📝 Walkthrough

Walkthrough

The Web UI removes several no-cache directives and cache-busting parameters. Some AJAX cache settings and profile parameter handling also change. Homematic firmware requests add timestamp parameters. The firmware-update progress message no longer includes its update-step text.

Changes

Web UI cache handling

Layer / File(s) Summary
Remove HTML no-cache metadata
src/webui/rega/www/index.htm, src/webui/rega/www/pages/index.htm, src/webui/www/config/ic_common.tcl, src/webui/www/config/ic_ifacecmd.cgi, src/webui/www/tools/designer.html
The pages no longer emit the removed cache-control, pragma, and expiration metadata. The shared put_meta_nocache procedure and its calls are removed.
Remove cache-busting URL parameters
src/webui/rega/www/login.htm, src/webui/rega/www/logout.htm, src/webui/rega/www/pages/index.htm, src/webui/www/error/error-*.html, src/webui/www/tools/js/common/httploader.js, src/webui/www_source/webui/js/common/httploader.js, src/webui/www_source/config/js/ic_common.js
Resource URLs and request helpers no longer add fixed version or random AvoidBrowserCache parameters.
Update AJAX cache and parameter handling
src/webui/www/config/cp_maintenance.cgi, src/webui/www/webui/js/lang/loadTextResource.js, src/webui/www_source/webui/js/headerbar.js, src/webui/www/config/ic_common.tcl, src/webui/www/config/ic_neweasymode.cgi
The EULA request adds cache: false. The language-resource and header-bar AJAX requests no longer set their previous cache options. Profile handling no longer excludes AvoidBrowserCache.
Add timestamps to Homematic requests
src/webui/www_source/webui/js/homematic.com.js
Firmware-version and device-firmware requests append the current timestamp as a ts query parameter.

Firmware update progress message

Layer / File(s) Summary
Shorten the update progress message
src/webui/www/config/cp_maintenance.cgi
The progress message no longer includes the step-2 paragraph or the ordered list of update steps. The call still passes "_empty_" for controls.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~12 minutes

Change: Bug fix


Merge Risk: ⚪ Minimal · up to 43d94

Local WebUI resources will rely on response revalidation instead of cache-busting URLs. No concrete regression was established in the changed paths, so the merge risk is minimal.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 2 files. (8 skipped: 8 … Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check Passed The title clearly and concisely describes the main change: removing WebUI cache-busting mechanisms and relying on HTTP cache headers.
Linked Issues check Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check Passed Check skipped because no linked issues were found for this pull request.

Full details: Docstring Coverage

Explanation

Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 2 files. (8 skipped: 8 unsupported.)



  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR

🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR


  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@jens-maus

Copy link
Copy Markdown
Member Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@jens-maus

Copy link
Copy Markdown
Member Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@jens-maus
jens-maus merged commit 7d8dbdd into main Oct 9, 2026
5 checks passed
@jens-maus
jens-maus deleted the jens-maus/webui-cache-control branch October 9, 2026 11:24
jens-maus added a commit to OpenCCU/OpenCCU that referenced this pull request Oct 9, 2026
This removes OpenCCU rootfs patch 0026-WebUI-Fix-CacheControl.patch, now that OpenCCU/OpenCCU-Base#157 is merged.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant