Hacker News

New stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. Common food additives linked to high blood pressure and heart disease(sciencedaily.com)
    discuss
  2. Interpreting a volcano's 'bulges' and predicting the next explosive eruption(vt.edu)
    discuss
  3. Log-Depth Recurrent Language Modeling(arxiv.org)
    discuss
  4. Automatically detecting AI text in my browser(seangoedecke.com)
    discuss
  5. Cognitive Offloading and the Bill That Comes Due(ninchiai.substack.com)
    discuss
  6. Show HN: CrunchMyPay – 50 pay calculators, every formula and source shown(crunchmypay.com)
    discuss
  7. Show HN: Chatlo – an iOS-native AI agent, now with Jev(apps.apple.com)
    discuss
  8. S3 is not a filesystem, and LSM trees never needed one [video](youtube.com)
    1comments
  9. Memory Control Signals Emerge Before Action in Long Horizon Agents(arxiv.org)
    discuss
  10. Changes to App Tracking Transparency in the E.U(daringfireball.net)
    discuss
  11. Eliminating Middlemen in Education Consulting(rivernova.vercel.app)
    discuss
  12. OpenAI agents plotted to access government health data amid Medicare (AU) hack(abc.net.au)
    discuss
  13. Meta Muse Charm(meta.com)
    3comments
  14. AI Isn't Going to Destroy Humanity–But the People Building It Might(theatlantic.com)
    1comments
  15. Greedy Decoding Is Not Precision-Invariant: Cross-Precision Output Divergence(arxiv.org)
    discuss
  16. Hackers Actively Exploit Check Point VPN Flaw(2tinteractive.com)
    1comments
  17. Moon Rabbit(wikipedia.org)
    2comments
  18. Reverse Jev: Ending a Reply with a Choice(kvit.app)
    discuss
  19. Intelligence Index vs. Cost per Task(lakebed.app)
    discuss
  20. The Misalignment Is Within: Why Mathematics Must Embrace the AI Paradigm(medium.com/b1nj0y)
    1comments
  21. OSS Author of Guake, HTTPretty, Lettuce and Sure is unemployed and needs help(twitter.com/gabrielfalcao)
    discuss
  22. Chrome Extension Job Alerts(talentize.com)
    discuss
  23. The Death of Reading (With James Marriott) [audio](econtalk.org)
    discuss
  24. Graph Technology Roundup – August 2026(gdb-engines.com)
    discuss
  25. Why China Can't Innovate (2014)(bambooinnovator.com)
    discuss
  26. An Interview with Rich Jaycobs(sfcompute.com)
    discuss
  27. The Complete History of the Elves of Middle-Earth [video](youtube.com)
    discuss
  28. A Key Safety Feature Shipped in the May OpenTofu Release(masterpoint.io)
    discuss
  29. Show HN: A game about fake news and memes(unspin.app)
    1comments
  30. Rendering pull requests in the GitHub Copilot app(github.blog)
    1comments

We just shipped support for the ugliest part of HTTP: Vary

88 pointsby 4h agoblog.cloudflare.com
15 comments
3h agoHN ↗

I've been wanting this from Cloudflare for years.

The classic problem here is if you do that thing where user agents that send "accept: text/html" get HTML, while user agents that don't get JSON or some other format.

This used to be impossible to deploy behind Cloudflare caching, because they ignored the Vary header on anything other than images - so you risked caching the JSON version and then serving it up to someone who was expecting HTML.

(Independent of the Cloudflare feature I ended up deciding never to use that pattern, because I prefer having URL that predictably returns HTML or JSON - I add a .json suffix to my apps to serve JSON instead.)

16m agoHN ↗

Frankly, the supposed variability of the Accept header never really sat all that well with me; in practice I much prefer working with explicitly versioned endpoints — one of the most infuriating things is having to hardcode "Accept: text/x-myorgname-custom-json-blob-v4" because omitting it would produce "406 Not Acceptable". Bonus points if that's the only Accept header the service would ever accept in all of three years of it working before being decommissioned. Double bonus points if v5 would be introduced behind a separate URI anyway (and it, too, would require precisely "Accept: text/x-myorgname-custom-json-blob-v5" and nothing else).

3h agoHN ↗

Nice to see. I’ve used vary to quite a bit of success on CloudFront back in the day.

I actually assumed when I started using Cloudflare that it did have vary support and it led to a serious bug in my sass app at the time.

3h agoHN ↗

I honestly thought they would never ship this. Holy hell this has been a long time coming.

Actual real content negotiation in 2026. Never thought I'd live to see the day.

3h agoHN ↗

"If the origin response does not include a Vary header, Cloudflare caches the response normally"[1]

"If one response omits it, Cloudflare could cache that response without the variance needed to keep it isolated."[2]

Will that non-Vary cache object front-run any Vary-segmented cache objects?

If so, probably worth adding a snippet rule to ensure every response has a Vary header?

1: https://developers.cloudflare.com/cache/concepts/vary/#how-v...

2: https://blog.cloudflare.com/vary-support/#how-a-response-mov...

2h agoHN ↗

finally. now maybe they'll have time to implement a working unsubscribe on their marketing emails.

2h agoHN ↗

Turns out their marketing can get to you through HN posts…

1h agoHN ↗

I had not actually realized what a mess Vary is.

Wow, sometimes I think it's amazing the web works at all!

1h agoHN ↗

It pains me to think about the important ones like varying on session cookie and authorization headers, and how badly some middleware can confuse things.

We generate custom content for a given authentication context. We definitely want caching at the user agent, but we want the cache keyed by the authenticated identity. Otherwise something like logging out and logging in as a different identity can produce monstrously confused results when an SPA or similar mixes some cached and some fresh responses into one page.

52m agoHN ↗

Cache invalidation, one of the two hard problems in computer science.

I'm sure most people here already knows the joke, but for the lucky 10,000, here's the full joke:

There are only two hard problems in computer science. Naming things, cache invalidation, and off-by-one errors.

45m agoHN ↗

Imagine if we actually built a remote application delivery platform instead of cobbling one onto a glorified document reader

1h agoHN ↗

If this surprises you, remember that Cloudflare doesn't cache HTML by default.

56m agoHN ↗

They can't do that because a CMS under Cloudflare needs to be configured to bust the Cloudflare cache when content is edited or the user will see cached content after they edit a page.

55m agoHN ↗

OTOH a CMS that doesn’t send correct cache headers is already broken

14m agoHN ↗

That might be the default configuration if your CMS doesn't return any cache-control headers. But Cloudflare definitely [0] supports must-revalidate and etag or last-modified, which is also probably supported by whatever CMS you're using. HTTP conditional requests are very old and very widely supported.

[0] Okay, my claim is only definite up to my memory of using Cloudflare for a fairly high-traffic circa 2019-2022. I haven't used Cloudflare after that point, but a quick search of their docs shows support