CDN | 2025 | The Web Almanac by HTTP Archive

CDN chapter of the 2025 Web Almanac covering adoption of CDNs, top CDN players, the impact of CDNs on TLS, HTTP/2+, Zstandard, Brotli, Early Hints, and Client Hints adoption.

Behold, yet another article about HTTP headers, the unsung heroes of the internet that only developers care about πŸ€“. Apparently, these magical lines of text are crucial for everything from making your website scream to whispering sweet nothings to #APIs 🧐. But fear not, thanks to HTTPCOLON you've got a shiny, new, totally-not-overdone tool to inspect them! πŸŽ‰
https://httpcolon.dev/ #HTTPheaders #webdevelopment #developer #tools #technews #HackerNews #ngated
HTTP:COLON

Ah, the thrilling saga of HTTP headers! πŸš€ Let's add yet another layer of complexity for devs to misunderstand. #RateLimit headers: because what we really need is to encourage clients to burst like a #piΓ±ata at a child's birthday party. πŸŽ‰
https://dotat.at/@/2026-01-13-http-ratelimit.html #HTTPHeaders #DevsComplexity #ClientBursting #HackerNews #ngated
HTTP RateLimit headers – Tony Finch

Security | 2025 | The Web Almanac by HTTP Archive

Security chapter of the 2025 Web Almanac covering Transport Layer Security, content inclusion (CSP, SRI, Permissions Policy), web defense mechanisms (tackling XSS, XS-Leaks), drivers of security mechanism adoptions and security misconfigurations.

Fixing the URL params performance penalty

Tales of two pages… What's the difference between these two pages?: https://www.example.com/ https://www.example.com/?utm_source=email I mean they've got different URLs, but many of us would probably guess that that utm_source URL query parameters (or "URL params" or "search params" as it's

Web Performance Calendar

CORS Explained: Stop Struggling With Cross-Origin Errors, by (not on Mastodon or Bluesky):

https://archive.fo/5rWqj

#security #cors #httpheaders #http

RFC 8594: The Sunset HTTP Header Field

This specification defines the Sunset HTTP response header field, which indicates that a URI is likely to become unresponsive at a specified point in the future. It also defines a sunset link relation type that allows linking to resources providing information about an upcoming resource or service sunset.

IETF Datatracker
Chrome 140 introduces HTTP cookie prefix to combat client-side security threats: Chrome 140 beta introduces __Http and __HostHttp cookie prefixes on August 6, 2025, enabling servers to distinguish server-set from client-set cookies. https://ppc.land/chrome-140-introduces-http-cookie-prefix-to-combat-client-side-security-threats/ #Chrome140 #HTTPHeaders #WebSecurity #Cookies #ClientSideSecurity
Chrome 140 introduces HTTP cookie prefix to combat client-side security threats

Chrome 140 beta introduces __Http and __HostHttp cookie prefixes on August 6, 2025, enabling servers to distinguish server-set from client-set cookies.

PPC Land
πŸ§™β€β™‚οΈ Ah, yes, because nothing screams cutting-edge tech quite like slapping a fictional telegraph homage from a fantasy series onto modern HTTP headers. πŸ€¦β€β™‚οΈ Let's all pause to admire the nerdy zealotry that ensures the name of a character floats eternally through the internet... because nothing could be more crucial. πŸ™„
https://xclacksoverhead.org/home/about #cuttingEdgeTech #nerdyHumor #HTTPHeaders #fantasyTech #telegraphTribute #HackerNews #ngated
XClacksOverhead.org

Information on the X-Clacks-Overhead transmission header.

X-Clacks-Overhead
Progressive Dehancement

The one where I try my best to fight spam and not surrender

dbushell.com