Hi @arvind ,
here are some high-level details on how the dispatcher validates and caches secure content.
- Dispatcher determines that the requested content is cached and valid.
- Dispatcher sends a request message to the render. The HEAD section includes all of the header lines from the browser request.
- The render calls the auth checker servlet to perform the security check and responds to Dispatcher. The response message includes an HTTP status code of 200 to indicate that the user is authorized.
- Dispatcher sends a response message to the browser that consists of the header lines from the render response and the cached content in the body.
To implement permission-sensitive caching, perform the following tasks:
- Develop a servlet that performs authentication and authorization
- Configure the Dispatcher
More details about implementation can be found in the documentation below
Hope this helps!