<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.29 (Ruby 3.2.2) -->
<?rfc-ext html-pretty-print="prettyprint https://cdn.rawgit.com/google/code-prettify/master/loader/run_prettify.js"?>
<rfc xmlns:x="http://purl.org/net/xml2rfc/ext"
     category="std"
     consensus="true"
     docName="draft-ietf-httpbis-no-vary-search-02"
     ipr="trust200902"
     sortRefs="true"
     submissionType="IETF"
     symRefs="true"
     tocInclude="true"
     version="3">
   <x:feedback template="mailto:ietf-http-wg@w3.org?subject={docname},%20%22{section}%22\&amp;amp;body=%3c{ref}%3e:"/>
   <!-- xml2rfc v2v3 conversion 3.30.1 -->
   <front xmlns:xi="http://www.w3.org/2001/XInclude">
      <title abbrev="No-Vary-Search">The No-Vary-Search HTTP Response Header Field</title>
      <seriesInfo name="Internet-Draft" value="draft-ietf-httpbis-no-vary-search-latest"/>
      <author fullname="Domenic Denicola">
         <organization>Google LLC</organization>
         <address>
            <email>d@domenic.me</email>
         </address>
      </author>
      <author fullname="Jeremy Roman">
         <organization>Google LLC</organization>
         <address>
            <email>jbroman@chromium.org</email>
         </address>
      </author>
      <date day="17" month="September" year="2025"/>
      <area>Web and Internet Transport</area>
      <workgroup>HyperText Transfer Protocol</workgroup>
      <keyword>http</keyword>
      <keyword>caching</keyword>
      <abstract><?line 106?>
         <t>This specification defines a proposed HTTP response header field for changing how URL search parameters impact caching.</t>
      </abstract>
      <note removeInRFC="true">
         <name>About This Document</name>
         <t>The latest revision of this draft can be found at <eref target="https://httpwg.org/http-extensions/draft-ietf-httpbis-no-vary-search.html"/>. Status information for this document may be found at <eref target="https://datatracker.ietf.org/doc/draft-ietf-httpbis-no-vary-search/"/>.</t>
         <t>Discussion of this document takes place on the HTTP Working Group mailing list (<eref target="mailto:ietf-http-wg@w3.org"/>), which is archived at <eref target="https://lists.w3.org/Archives/Public/ietf-http-wg/"/>. Working Group information can be found at <eref target="https://httpwg.org/"/>.</t>
         <t>Source for this draft and an issue tracker can be found at <eref target="https://github.com/httpwg/http-extensions/labels/no-vary-search"/>.</t>
      </note>
   </front>
   <middle xmlns:xi="http://www.w3.org/2001/XInclude"><?line 110?>
      <section anchor="introduction">
         <name>Introduction</name>
         <t>HTTP caching <xref target="HTTP-CACHING"/> is based on reusing resources which match across a number of cache keys. One of the most prominent is the presented target URI (<xref section="7.1" sectionFormat="of" target="HTTP"/>). However, sometimes multiple URLs can represent the same resource. This leads to caches not always being as helpful as they could be: if the cache contains the resource under one URI, but the resource is then requested under another, the cached version will be ignored.</t>
         <t>The <tt>No-Vary-Search</tt> HTTP header field tackles a specific subset of this general problem, for when a resource has multiple URLs which differ only in certain query components. It allows resources to declare that some or all parts of the query do not semantically affect the served resource, and thus can be ignored for cache matching purposes. For example, if the order of the query parameter keys do not semantically affect the served resource, this is indicated using</t>
         <sourcecode type="http-message">
No-Vary-Search: key-order
</sourcecode>
         <t>If the specific query parameters (e.g., ones indicating something for analytics) do not semantically affect the served resource, this is indicated using</t>
         <sourcecode type="http-message">
No-Vary-Search: params=("utm_source" "utm_medium" "utm_campaign")
</sourcecode>
         <t>And if the resource instead wants to take an allowlist-based approach, where only certain known query parameters semantically affect the served resource, they can use</t>
         <sourcecode type="http-message">
No-Vary-Search: params, except=("productId")
</sourcecode>
         <t>
            <xref target="header-definition"/> defines the header, using the <xref target="STRUCTURED-FIELDS"/> framework. <xref target="data-model"/> and <xref target="parsing"/> illustrate the data model for how the header can be represented in specifications, and the process for parsing the raw output from the structured field parser into that data model. <xref target="comparing"/> gives the key algorithm for comparing if two URLs are equivalent under the influence of the header; notably, it leans on the decomposition of the query component into keys and values given by the <eref target="https://url.spec.whatwg.org/#concept-urlencoded">application/x-www-form-urlencoded</eref> format specified in <xref target="WHATWG-URL"/>. Finally, <xref target="caching"/> explains how to modify <xref target="HTTP-CACHING"/> to take into account this new equivalence.</t>
      </section>
      <section anchor="conventions-and-definitions">
         <name>Conventions and Definitions</name>
         <t>The key words "<bcp14>MUST</bcp14>", "<bcp14>MUST NOT</bcp14>", "<bcp14>REQUIRED</bcp14>", "<bcp14>SHALL</bcp14>", "<bcp14>SHALL NOT</bcp14>", "<bcp14>SHOULD</bcp14>", "<bcp14>SHOULD NOT</bcp14>", "<bcp14>RECOMMENDED</bcp14>", "<bcp14>NOT RECOMMENDED</bcp14>", "<bcp14>MAY</bcp14>", and "<bcp14>OPTIONAL</bcp14>" in this document are to be interpreted as described in BCP 14 <xref target="RFC2119"/>
            <xref target="RFC8174"/> when, and only when, they appear in all capitals, as shown here.</t>
         <?line -18?>
         <t>This document also adopts some conventions and notation typical in WHATWG and W3C usage, especially as it relates to algorithms. See <xref target="WHATWG-INFRA"/>, and in particular:</t>
         <ul spacing="normal">
            <li>
               <t>its definition of lists, including the list literal notation « 1, 2, 3 ».</t>
            </li>
            <li>
               <t>its definition of strings, including their representation as code units.</t>
            </li>
         </ul>
         <t>(Other concepts used are called out using inline references.)</t>
      </section>
      <section anchor="header-definition">
         <name>HTTP header field definition</name>
         <t>The <tt>No-Vary-Search</tt> HTTP header field is a structured field <xref target="STRUCTURED-FIELDS"/> whose value <bcp14>MUST</bcp14> be a dictionary (<xref section="3.2" sectionFormat="of" target="STRUCTURED-FIELDS"/>).</t>
         <t>It has the following authoring conformance requirements:</t>
         <ul spacing="normal">
            <li>
               <t>If present, the <tt>key-order</tt> entry's value <bcp14>MUST</bcp14> be a boolean (<xref section="3.3.6" sectionFormat="of" target="STRUCTURED-FIELDS"/>).</t>
            </li>
            <li>
               <t>If present, the <tt>params</tt> entry's value <bcp14>MUST</bcp14> be either a boolean (<xref section="3.3.6" sectionFormat="of" target="STRUCTURED-FIELDS"/>) or an inner list (<xref section="3.1.1" sectionFormat="of" target="STRUCTURED-FIELDS"/>).</t>
            </li>
            <li>
               <t>If present, the <tt>except</tt> entry's value <bcp14>MUST</bcp14> be an inner list (<xref section="3.1.1" sectionFormat="of" target="STRUCTURED-FIELDS"/>).</t>
            </li>
            <li>
               <t>The <tt>except</tt> entry <bcp14>MUST</bcp14> only be present if the <tt>params</tt> entry is also present, and the <tt>params</tt> entry's value is the boolean value true.</t>
            </li>
         </ul>
         <t>The dictionary <bcp14>MAY</bcp14> contain entries whose keys are not one of <tt>key-order</tt>, <tt>params</tt>, and <tt>except</tt>, but their meaning is not defined by this specification. Implementations of this specification will ignore such entries (but future documents might assign meaning to such entries).</t>
         <aside>
            <t>As always, the authoring conformance requirements are not binding on implementations. Implementations instead need to implement the processing model given by the <iref item="obtain a URL search variance"/>
               <xref format="none" target="obtain-a-url-search-variance">obtain a URL search variance</xref> algorithm (<xref target="obtain-a-url-search-variance"/>).</t>
         </aside>
      </section>
      <section anchor="data-model">
         <name>Data model</name>
         <t>A <em>URL search variance</em> consists of the following:</t>
         <dl newline="true">
            <dt>no-vary params</dt>
            <dd>
               <t>either the special value <strong>wildcard</strong> or a list of strings</t>
            </dd>
            <dt>vary params</dt>
            <dd>
               <t>either the special value <strong>wildcard</strong> or a list of strings</t>
            </dd>
            <dt>vary on key order</dt>
            <dd>
               <t>a boolean</t>
            </dd>
         </dl>
         <t>
            <iref item="default URL search variance" primary="true"/> The <em>
               <iref item="default URL search variance"/>default URL search variance</em> is a URL search variance whose no-vary params is an empty list, vary params is <strong>wildcard</strong>, and vary on key order is true.</t>
         <t>The <iref item="obtain a URL search variance"/>
            <xref format="none" target="obtain-a-url-search-variance">obtain a URL search variance</xref> algorithm (<xref target="obtain-a-url-search-variance"/>) ensures that all URL search variances obey the following constraints:</t>
         <ul spacing="normal">
            <li>
               <t>vary params is a list if and only if the no-vary params is <strong>wildcard</strong>; and</t>
            </li>
            <li>
               <t>no-vary params is a list if and only if the vary params is <strong>wildcard</strong>.</t>
            </li>
         </ul>
      </section>
      <section anchor="parsing">
         <name>Parsing</name>
         <section anchor="parse-a-url-search-variance">
            <name>Parse a URL search variance</name>
            <t>
               <iref item="parse a URL search variance" primary="true"/> To <em>
                  <iref item="parse a URL search variance"/>
                  <xref format="none" target="parse-a-url-search-variance">parse a URL search variance</xref>
               </em> given <em>value</em>:</t>
            <ol spacing="normal" type="1">
               <li>
                  <t>If <em>value</em> is null, then return the <iref item="default URL search variance"/>default URL search variance.</t>
               </li>
               <li>
                  <t>Let <em>result</em> be a new URL search variance.</t>
               </li>
               <li>
                  <t>Set <em>result</em>'s vary on key order to true.</t>
               </li>
               <li>
                  <t>If <em>value</em>["<tt>key-order</tt>"] exists:</t>
                  <ol spacing="normal" type="1">
                     <li>
                        <t>If <em>value</em>["<tt>key-order</tt>"] is not a boolean, then return the <iref item="default URL search variance"/>default URL search variance.</t>
                     </li>
                     <li>
                        <t>Set <em>result</em>'s vary on key order to the boolean negation of <em>value</em>["<tt>key-order</tt>"].</t>
                     </li>
                  </ol>
               </li>
               <li>
                  <t>If <em>value</em>["<tt>params</tt>"] exists:</t>
                  <ol spacing="normal" type="1">
                     <li>
                        <t>If <em>value</em>["<tt>params</tt>"] is a boolean:</t>
                        <ol spacing="normal" type="1">
                           <li>
                              <t>If <em>value</em>["<tt>params</tt>"] is true, then:</t>
                              <ol spacing="normal" type="1">
                                 <li>
                                    <t>Set <em>result</em>'s no-vary params to <strong>wildcard</strong>.</t>
                                 </li>
                                 <li>
                                    <t>Set <em>result</em>'s vary params to the empty list.</t>
                                 </li>
                              </ol>
                           </li>
                           <li>
                              <t>Otherwise:</t>
                              <ol spacing="normal" type="1">
                                 <li>
                                    <t>Set <em>result</em>'s no-vary params to the empty list.</t>
                                 </li>
                                 <li>
                                    <t>Set <em>result</em>'s vary params to <strong>wildcard</strong>.</t>
                                 </li>
                              </ol>
                           </li>
                        </ol>
                     </li>
                     <li>
                        <t>Otherwise, if <em>value</em>["<tt>params</tt>"] is an array:</t>
                        <ol spacing="normal" type="1">
                           <li>
                              <t>If any item in <em>value</em>["<tt>params</tt>"] is not a string, then return the <iref item="default URL search variance"/>default URL search variance.</t>
                           </li>
                           <li>
                              <t>Set <em>result</em>'s no-vary params to the result of applying <iref item="parse a key"/>
                                 <xref format="none" target="parse-a-key">parse a key</xref> (<xref target="parse-a-key"/>) to each item in <em>value</em>["<tt>params</tt>"].</t>
                           </li>
                           <li>
                              <t>Set <em>result</em>'s vary params to <strong>wildcard</strong>.</t>
                           </li>
                        </ol>
                     </li>
                     <li>
                        <t>Otherwise, return the <iref item="default URL search variance"/>default URL search variance.</t>
                     </li>
                  </ol>
               </li>
               <li>
                  <t>If <em>value</em>["<tt>except</tt>"] exists:</t>
                  <ol spacing="normal" type="1">
                     <li>
                        <t>If <em>value</em>["<tt>params</tt>"] is not true, then return the <iref item="default URL search variance"/>default URL search variance.</t>
                     </li>
                     <li>
                        <t>If <em>value</em>["<tt>except</tt>"] is not an array, then return the <iref item="default URL search variance"/>default URL search variance.</t>
                     </li>
                     <li>
                        <t>If any item in <em>value</em>["<tt>except</tt>"] is not a string, then return the <iref item="default URL search variance"/>default URL search variance.</t>
                     </li>
                     <li>
                        <t>Set <em>result</em>'s vary params to the result of applying <iref item="parse a key"/>
                           <xref format="none" target="parse-a-key">parse a key</xref> (<xref target="parse-a-key"/>) to each item in <em>value</em>["<tt>except</tt>"].</t>
                     </li>
                  </ol>
               </li>
               <li>
                  <t>Return <em>result</em>.</t>
               </li>
            </ol>
            <aside>
               <t>In general, this algorithm is strict and tends to return the <iref item="default URL search variance"/>default URL search variance whenever it sees something it doesn't recognize. This is because the <iref item="default URL search variance"/>default URL search variance behavior will just cause fewer cache hits, which is an acceptable fallback behavior.</t>
               <t>However, unrecognized keys at the top level are ignored, to make it easier to extend this specification in the future. To avoid misbehavior with existing client software, such extensions will likely expand, rather than reduce, the set of requests that a cached response can match.</t>
            </aside>
            <aside>
               <t>The input to this algorithm is generally obtained by parsing a structured field (<xref section="4.2" sectionFormat="of" target="STRUCTURED-FIELDS"/>) using field_type "dictionary".</t>
            </aside>
         </section>
         <section anchor="obtain-a-url-search-variance">
            <name>Obtain a URL search variance</name>
            <t>
               <iref item="obtain a URL search variance" primary="true"/> To <em>
                  <iref item="obtain a URL search variance"/>
                  <xref format="none" target="obtain-a-url-search-variance">obtain a URL search variance</xref>
               </em> given a <eref target="https://fetch.spec.whatwg.org/#concept-response">response</eref>
               <em>response</em>:</t>
            <ol spacing="normal" type="1">
               <li>
                  <t>Let <em>fieldValue</em> be the result of <eref target="https://fetch.spec.whatwg.org/#concept-header-list-get-structured-header">getting a structured field value</eref>
                     <xref target="FETCH"/> given `<tt>No-Vary-Search</tt>` and "<tt>dictionary</tt>" from <em>response</em>'s header list.</t>
               </li>
               <li>
                  <t>Return the result of parsing a URL search variance (<xref target="parse-a-url-search-variance"/>) given <em>fieldValue</em>. <iref item="parse a URL search variance"/>
                  </t>
               </li>
            </ol>
            <section anchor="examples">
               <name>Examples</name>
               <t>The following illustrates how various inputs are parsed, in terms of their impacting on the resulting no-vary params and vary params:</t>
               <table>
                  <thead>
                     <tr>
                        <th align="left">Input</th>
                        <th align="left">Result</th>
                     </tr>
                  </thead>
                  <tbody>
                     <tr>
                        <td align="left">
                           <tt>No-Vary-Search: params</tt>
                        </td>
                        <td align="left">no-vary params: <strong>wildcard</strong>
                           <br/>vary params: (empty list)</td>
                     </tr>
                     <tr>
                        <td align="left">
                           <tt>No-Vary-Search: params=("a")</tt>
                        </td>
                        <td align="left">no-vary params: « "<tt>a</tt>" »<br/>vary params: <strong>wildcard</strong>
                        </td>
                     </tr>
                     <tr>
                        <td align="left">
                           <tt>No-Vary-Search: params, except=("x")</tt>
                        </td>
                        <td align="left">no-vary params: <strong>wildcard</strong>
                           <br/>vary params: « "<tt>x</tt>" »</td>
                     </tr>
                  </tbody>
               </table>
               <t>The following inputs are all invalid and will cause the <iref item="default URL search variance"/>default URL search variance to be returned:</t>
               <ul spacing="compact">
                  <li>
                     <t>
                        <tt>No-Vary-Search: unknown-key</tt>
                     </t>
                  </li>
                  <li>
                     <t>
                        <tt>No-Vary-Search: key-order="not a boolean"</tt>
                     </t>
                  </li>
                  <li>
                     <t>
                        <tt>No-Vary-Search: params="not a boolean or inner list"</tt>
                     </t>
                  </li>
                  <li>
                     <t>
                        <tt>No-Vary-Search: params=(not-a-string)</tt>
                     </t>
                  </li>
                  <li>
                     <t>
                        <tt>No-Vary-Search: params=("a"), except=("x")</tt>
                     </t>
                  </li>
                  <li>
                     <t>
                        <tt>No-Vary-Search: params=(), except=()</tt>
                     </t>
                  </li>
                  <li>
                     <t>
                        <tt>No-Vary-Search: params=?0, except=("x")</tt>
                     </t>
                  </li>
                  <li>
                     <t>
                        <tt>No-Vary-Search: params, except=(not-a-string)</tt>
                     </t>
                  </li>
                  <li>
                     <t>
                        <tt>No-Vary-Search: params, except="not an inner list"</tt>
                     </t>
                  </li>
                  <li>
                     <t>
                        <tt>No-Vary-Search: params, except=?1</tt>
                     </t>
                  </li>
                  <li>
                     <t>
                        <tt>No-Vary-Search: except=("x")</tt>
                     </t>
                  </li>
                  <li>
                     <t>
                        <tt>No-Vary-Search: except=()</tt>
                     </t>
                  </li>
               </ul>
               <t>The following inputs are valid, but somewhat unconventional. They are shown alongside their more conventional form.</t>
               <table>
                  <thead>
                     <tr>
                        <th align="left">Input</th>
                        <th align="left">Conventional form</th>
                     </tr>
                  </thead>
                  <tbody>
                     <tr>
                        <td align="left">
                           <tt>No-Vary-Search: params=?1</tt>
                        </td>
                        <td align="left">
                           <tt>No-Vary-Search: params</tt>
                        </td>
                     </tr>
                     <tr>
                        <td align="left">
                           <tt>No-Vary-Search: key-order=?1</tt>
                        </td>
                        <td align="left">
                           <tt>No-Vary-Search: key-order</tt>
                        </td>
                     </tr>
                     <tr>
                        <td align="left">
                           <tt>No-Vary-Search: params, key-order, except=("x")</tt>
                        </td>
                        <td align="left">
                           <tt>No-Vary-Search: key-order, params, except=("x")</tt>
                        </td>
                     </tr>
                     <tr>
                        <td align="left">
                           <tt>No-Vary-Search: params=?0</tt>
                        </td>
                        <td align="left">(omit the header)</td>
                     </tr>
                     <tr>
                        <td align="left">
                           <tt>No-Vary-Search: params=()</tt>
                        </td>
                        <td align="left">(omit the header)</td>
                     </tr>
                     <tr>
                        <td align="left">
                           <tt>No-Vary-Search: key-order=?0</tt>
                        </td>
                        <td align="left">(omit the header)</td>
                     </tr>
                  </tbody>
               </table>
            </section>
         </section>
         <section anchor="parse-a-key">
            <name>Parse a key</name>
            <t>
               <iref item="parse a key" primary="true"/> To <em>
                  <iref item="parse a key"/>
                  <xref format="none" target="parse-a-key">parse a key</xref>
               </em> given an ASCII string <em>keyString</em>:</t>
            <ol spacing="normal" type="1">
               <li>
                  <t>Let <em>keyBytes</em> be the <eref target="https://infra.spec.whatwg.org/#isomorphic-encode">isomorphic encoding</eref>
                     <xref target="WHATWG-INFRA"/> of <em>keyString</em>.</t>
               </li>
               <li>
                  <t>Replace any 0x2B (+) in <em>keyBytes</em> with 0x20 (SP).</t>
               </li>
               <li>
                  <t>Let <em>keyBytesDecoded</em> be the <eref target="https://url.spec.whatwg.org/#percent-decode">percent-decoding</eref>
                     <xref target="WHATWG-URL"/> of <em>keyBytes</em>.</t>
               </li>
               <li>
                  <t>Let <em>keyStringDecoded</em> be the <eref target="https://encoding.spec.whatwg.org/#utf-8-decode-without-bom">UTF-8 decoding without BOM</eref>
                     <xref target="WHATWG-ENCODING"/> of <em>keyBytesDecoded</em>.</t>
               </li>
               <li>
                  <t>Return <em>keyStringDecoded</em>.</t>
               </li>
            </ol>
            <section anchor="examples-1">
               <name>Examples</name>
               <t>The <iref item="parse a key"/>
                  <xref format="none" target="parse-a-key">parse a key</xref> algorithm allows encoding non-ASCII key strings in the ASCII structured header format, similar to how the <eref target="https://url.spec.whatwg.org/#concept-urlencoded">application/x-www-form-urlencoded</eref> format <xref target="WHATWG-URL"/> allows encoding an entire entry list of keys and values in ASCII URL format. For example,</t>
               <sourcecode type="http-message">
No-Vary-Search: params=("%C3%A9+%E6%B0%97")
</sourcecode>
               <t>will result in a URL search variance whose vary params are « "<tt>é 気</tt>" ». As explained in a later example, the canonicalization process during equivalence testing means this will treat as equivalent URL strings such as:</t>
               <!-- link "a later example" and "equivalence testing" -->
               <ul spacing="normal">
                  <li>
                     <t>
                        <tt>https://example.com/?é 気=1</tt>
                     </t>
                  </li>
                  <li>
                     <t>
                        <tt>https://example.com/?é+気=2</tt>
                     </t>
                  </li>
                  <li>
                     <t>
                        <tt>https://example.com/?%C3%A9%20気=3</tt>
                     </t>
                  </li>
                  <li>
                     <t>
                        <tt>https://example.com/?%C3%A9+%E6%B0%97=4</tt>
                     </t>
                  </li>
               </ul>
               <t>and so on, since they all are <eref target="https://url.spec.whatwg.org/#concept-urlencoded-parser">parsed</eref>
                  <xref target="WHATWG-URL"/> to having the same key "<tt>é 気</tt>".</t>
            </section>
         </section>
      </section>
      <section anchor="comparing">
         <name>Comparing</name>
         <t>
            <iref item="equivalent modulo search variance" primary="true"/> Two <eref target="https://url.spec.whatwg.org/#concept-url">URLs</eref>
            <xref target="WHATWG-URL"/>
            <em>urlA</em> and <em>urlB</em> are <em>equivalent modulo search variance</em> given a URL search variance <em>searchVariance</em> if the following algorithm returns true:</t>
         <ol spacing="normal" type="1">
            <li>
               <t>If the scheme, username, password, host, port, or path of <em>urlA</em> and <em>urlB</em> differ, then return false.</t>
            </li>
            <li>
               <t>If <em>searchVariance</em> is equivalent to the <iref item="default URL search variance"/>default URL search variance, then:</t>
               <ol spacing="normal" type="1">
                  <li>
                     <t>If <em>urlA</em>'s query equals <em>urlB</em>'s query, then return true.</t>
                  </li>
                  <li>
                     <t>Return false.</t>
                  </li>
               </ol>
               <t>In this case, even URL pairs that might appear the same after running the <eref target="https://url.spec.whatwg.org/#concept-urlencoded-parser">application/x-www-form-urlencoded parser</eref>
                  <xref target="WHATWG-URL"/> on their queries, such as <tt>https://example.com/a</tt> and <tt>https://example.com/a?</tt>, or <tt>https://example.com/foo?a=b&amp;&amp;&amp;c</tt> and <tt>https://example.com/foo?a=b&amp;c=</tt>, will be treated as inequivalent.</t>
            </li>
            <li>
               <t>Let <em>searchParamsA</em> and <em>searchParamsB</em> be empty lists.</t>
            </li>
            <li>
               <t>If <em>urlA</em>'s query is not null, then set <em>searchParamsA</em> to the result of running the <eref target="https://url.spec.whatwg.org/#concept-urlencoded-parser">application/x-www-form-urlencoded parser</eref>
                  <xref target="WHATWG-URL"/> given the <eref target="https://infra.spec.whatwg.org/#isomorphic-encode">isomorphic encoding</eref>
                  <xref target="WHATWG-INFRA"/> of <em>urlA</em>'s query.</t>
            </li>
            <li>
               <t>If <em>urlB</em>'s query is not null, then set <em>searchParamsB</em> to the result of running the <eref target="https://url.spec.whatwg.org/#concept-urlencoded-parser">application/x-www-form-urlencoded parser</eref>
                  <xref target="WHATWG-URL"/> given the <eref target="https://infra.spec.whatwg.org/#isomorphic-encode">isomorphic encoding</eref>
                  <xref target="WHATWG-INFRA"/> of <em>urlB</em>'s query.</t>
            </li>
            <li>
               <t>If <em>searchVariance</em>'s no-vary params is a list, then:</t>
               <ol spacing="normal" type="1">
                  <li>
                     <t>Set <em>searchParamsA</em> to a list containing those items <em>pair</em> in <em>searchParamsA</em> where <em>searchVariance</em>'s no-vary params does not contain <em>pair</em>[0].</t>
                  </li>
                  <li>
                     <t>Set <em>searchParamsB</em> to a list containing those items <em>pair</em> in <em>searchParamsB</em> where <em>searchVariance</em>'s no-vary params does not contain <em>pair</em>[0].</t>
                  </li>
               </ol>
            </li>
            <li>
               <t>Otherwise, if <em>searchVariance</em>'s vary params is a list, then:</t>
               <ol spacing="normal" type="1">
                  <li>
                     <t>Set <em>searchParamsA</em> to a list containing those items <em>pair</em> in <em>searchParamsA</em> where <em>searchVariance</em>'s vary params contains <em>pair</em>[0].</t>
                  </li>
                  <li>
                     <t>Set <em>searchParamsB</em> to a list containing those items <em>pair</em> in <em>searchParamsB</em> where <em>searchVariance</em>'s vary params contains <em>pair</em>[0].</t>
                  </li>
               </ol>
            </li>
            <li>
               <t>If <em>searchVariance</em>'s vary on key order is false, then:</t>
               <ol spacing="normal" type="1">
                  <li>
                     <t>Let <em>keyLessThan</em> be an algorithm taking as inputs two pairs (<em>keyA</em>, <em>valueA</em>) and (<em>keyB</em>, <em>valueB</em>), which returns whether <em>keyA</em> is <eref target="https://infra.spec.whatwg.org/#code-unit-less-than">code unit less than</eref>
                        <xref target="WHATWG-INFRA"/>
                        <em>keyB</em>.</t>
                  </li>
                  <li>
                     <t>Set <em>searchParamsA</em> to the result of sorting <em>searchParamsA</em> in ascending order with <em>keyLessThan</em>.</t>
                  </li>
                  <li>
                     <t>Set <em>searchParamsB</em> to the result of sorting <em>searchParamsB</em> in ascending order with <em>keyLessThan</em>.</t>
                  </li>
               </ol>
            </li>
            <li>
               <t>If <em>searchParamsA</em>'s size is not equal to <em>searchParamsB</em>'s size, then return false.</t>
            </li>
            <li>
               <t>Let <em>i</em> be 0.</t>
            </li>
            <li>
               <t>While <em>i</em> &lt; <em>searchParamsA</em>'s size:</t>
               <ol spacing="normal" type="1">
                  <li>
                     <t>If <em>searchParamsA</em>[<em>i</em>][0] does not equal <em>searchParamsB</em>[<em>i</em>][0], then return false.</t>
                  </li>
                  <li>
                     <t>If <em>searchParamsA</em>[<em>i</em>][1] does not equal <em>searchParamsB</em>[<em>i</em>][1], then return false.</t>
                  </li>
                  <li>
                     <t>Set <em>i</em> to <em>i</em> + 1.</t>
                  </li>
               </ol>
            </li>
            <li>
               <t>Return true.</t>
            </li>
         </ol>
         <section anchor="examples-2">
            <name>Examples</name>
            <t>Due to how the application/x-www-form-urlencoded parser canonicalizes query strings, there are some cases where query strings which do not appear obviously equivalent, will end up being treated as equivalent after parsing.</t>
            <t>So, for example, given any non-default value for <tt>No-Vary-Search</tt>, such as <tt>No-Vary-Search: key-order</tt>, we will have the following equivalences:</t>
            <dl newline="true">
               <dt>
                  <tt>https://example.com</tt>
                  <br/>
                  <tt>https://example.com/?</tt>
               </dt>
               <dd>A null query is parsed the same as an empty string</dd>
               <dt>
                  <tt>https://example.com/?a=x</tt>
                  <br/>
                  <tt>https://example.com/?%61=%78</tt>
               </dt>
               <dd>Parsing performs percent-decoding</dd>
               <dt>
                  <tt>https://example.com/?a=é</tt>
                  <br/>
                  <tt>https://example.com/?a=%C3%A9</tt>
               </dt>
               <dd>Parsing performs percent-decoding</dd>
               <dt>
                  <tt>https://example.com/?a=%f6</tt>
                  <br/>
                  <tt>https://example.com/?a=%ef%bf%bd</tt>
               </dt>
               <dd>Both values are parsed as U+FFFD (�)</dd>
               <dt>
                  <tt>https://example.com/?a=x&amp;&amp;&amp;&amp;</tt>
                  <br/>
                  <tt>https://example.com/?a=x</tt>
               </dt>
               <dd>Parsing splits on <tt>&amp;</tt> and discards empty strings</dd>
               <dt>
                  <tt>https://example.com/?a=</tt>
                  <br/>
                  <tt>https://example.com/?a</tt>
               </dt>
               <dd>Both parse as having an empty string value for <tt>a</tt>
               </dd>
               <dt>
                  <tt>https://example.com/?a=%20</tt>
                  <br/>
                  <tt>https://example.com/?a=+</tt>
                  <br/>
                  <tt>https://example.com/?a= &amp;</tt>
               </dt>
               <dd>
                  <tt>+</tt> and <tt>%20</tt> are both parsed as U+0020 SPACE</dd>
            </dl>
         </section>
      </section>
      <section anchor="caching">
         <name>Caching</name>
         <t>If a cache <xref target="HTTP-CACHING"/> implements this specification, the presented target URI requirement in <xref section="4" sectionFormat="of" target="HTTP-CACHING"/> is replaced with:</t>
         <ul spacing="normal">
            <li>
               <t>one of the following:</t>
               <ul spacing="normal">
                  <li>
                     <t>the presented target URI (<xref section="7.1" sectionFormat="of" target="HTTP"/>) and that of the stored response match, or</t>
                  </li>
                  <li>
                     <t>the presented target URI and that of the stored response are equivalent modulo search variance (<xref target="comparing"/>), given the variance obtained (<xref target="obtain-a-url-search-variance"/>) from the stored response.</t>
                  </li>
               </ul>
            </li>
         </ul>
         <t>Cache implementations <bcp14>MAY</bcp14> fail to reuse a stored response whose target URI matches <em>only</em> modulo URL search variance, if the cache has more recently stored a response which:</t>
         <ul spacing="normal">
            <li>
               <t>has a target URI which is equal to the presented target URI, excluding the query, and</t>
            </li>
            <li>
               <t>has a non-empty value for the <tt>No-Vary-Search</tt> field, and</t>
            </li>
            <li>
               <t>has a <tt>No-Vary-Search</tt> field value different from the stored response being considered for reuse.</t>
            </li>
         </ul>
         <aside>
            <t>Caches aren't required to reuse stored responses, generally. However, the above expressly empowers caches to, if it is advantageous for performance or other reasons, search a smaller number of stored responses.</t>
            <t>That is, because caches might store more than one response for a given pathname, they need a way to efficiently look up the No-Vary-Search value without accessing all cached responses. Such a cache might take steps like the following to identify a stored response in a performant way, before checking the other conditions in <xref section="4" sectionFormat="of" target="HTTP-CACHING"/>:</t>
            <ol spacing="normal" type="1">
               <li>
                  <t>Let exactMatch be cache[presentedTargetURI]. If it is a stored response that can be reused, return it.</t>
               </li>
               <li>
                  <t>Let targetPath be presentedTargetURI, with query parameters removed.</t>
               </li>
               <li>
                  <t>Let lastNVS be mostRecentNVS[targetPath]. If it does not exist, return null.</t>
               </li>
               <li>
                  <t>Let simplifiedURL be the result of simplifying presentedTargetURI according to lastNVS (by removing query parameters which are not significant, and stable sorting parameters by key, if key order is to be be ignored).</t>
               </li>
               <li>
                  <t>Let nvsMatch be cache[simplifiedURL]. If it does not exist, return null. (It is assumed that this was written when storing in the cache, in addition to the exact URL.)</t>
               </li>
               <li>
                  <t>Let searchVariance be obtained (<xref target="obtain-a-url-search-variance"/>) from nvsMatch.</t>
               </li>
               <li>
                  <t>If nvsMatch's target URI and presentedTargetURI are not equivalent modulo search variance (<xref target="comparing"/>) given searchVariance, then return null.</t>
               </li>
               <li>
                  <t>If nvsMatch is a stored response that can be reused, return it. Otherwise, return null.</t>
               </li>
            </ol>
         </aside>
         <t>To aid cache implementation efficiency, servers <bcp14>SHOULD NOT</bcp14> send different non-empty values for the <tt>No-Vary-Search</tt> field in response to requests for a given pathname over time, unless there is a need to update how they handle the query component. Doing so would cause cache implementations that use a strategy like the above to miss some stored responses that could otherwise have been reused.</t>
      </section>
      <section anchor="security-considerations">
         <name>Security Considerations</name>
         <t>The main risk to be aware of is the impact of mismatched URLs. In particular, this could cause the user to see a response that was originally fetched from a URL different from the one displayed when they hovered a link, or the URL displayed in the URL bar.</t>
         <t>However, since the impact is limited to query parameters, this does not cross the relevant security boundary, which is the <eref target="https://html.spec.whatwg.org/multipage/browsers.html#concept-origin">origin</eref>
            <xref target="HTML"/>. (Or perhaps just the <eref target="https://url.spec.whatwg.org/#concept-url-host">host</eref>, from <eref target="https://url.spec.whatwg.org/#url-rendering-simplification">the perspective of web browser security UI</eref>. <xref target="WHATWG-URL"/>) Indeed, we have already given origins complete control over how they present the (URL, reponse body) pair, including on the client side via technology such as <eref target="https://html.spec.whatwg.org/multipage/nav-history-apis.html#dom-history-replacestate">history.replaceState()</eref> or service workers.</t>
      </section>
      <section anchor="privacy-considerations">
         <name>Privacy Considerations</name>
         <t>This proposal is adjacent to the highly-privacy-relevant space of <eref target="https://privacycg.github.io/nav-tracking-mitigations/#terminology">navigational tracking</eref>, which often uses query parameters to pass along user identifiers. However, we believe this proposal itself does not have privacy impacts. It does not interfere with <eref target="https://privacycg.github.io/nav-tracking-mitigations/#deployed-mitigations">existing navigational tracking mitigations</eref>, or any known future ones being contemplated. Indeed, if a page were to encode user identifiers in its URL, the only ability this proposal gives is to <em>reduce</em> such user tracking by preventing server processing of such user IDs (since the server is bypassed in favor of the cache). <xref target="NAV-TRACKING-MITIGATIONS"/>
         </t>
      </section>
      <section anchor="iana-considerations">
         <name>IANA Considerations</name>
         <t>IANA should do the following:</t>
         <section anchor="http-field-names">
            <name>HTTP Field Names</name>
            <t>Enter the following into the Hypertext Transfer Protocol (HTTP) Field Name Registry:</t>
            <dl>
               <dt>Field Name</dt>
               <dd>
                  <t>
                     <tt>No-Vary-Search</tt>
                  </t>
               </dd>
               <dt>Status</dt>
               <dd>
                  <t>permanent</t>
               </dd>
               <dt>Structured Type</dt>
               <dd>
                  <t>Dictionary</t>
               </dd>
               <dt>Reference</dt>
               <dd>
                  <t>this document</t>
               </dd>
               <dt>Comments</dt>
               <dd>
                  <t>(none)</t>
               </dd>
            </dl>
         </section>
      </section>
   </middle>
   <back xmlns:xi="http://www.w3.org/2001/XInclude">
      <references anchor="sec-combined-references">
         <name>References</name>
         <references anchor="sec-normative-references">
            <name>Normative References</name>
            <reference anchor="HTTP">
               <front>
                  <title>HTTP Semantics</title>
                  <author fullname="R. Fielding"
                          initials="R."
                          role="editor"
                          surname="Fielding"/>
                  <author fullname="M. Nottingham"
                          initials="M."
                          role="editor"
                          surname="Nottingham"/>
                  <author fullname="J. Reschke"
                          initials="J."
                          role="editor"
                          surname="Reschke"/>
                  <date month="June" year="2022"/>
               </front>
               <seriesInfo name="STD" value="97"/>
               <seriesInfo name="RFC" value="9110"/>
               <seriesInfo name="DOI" value="10.17487/RFC9110"/>
            </reference>
            <reference anchor="HTTP-CACHING">
               <front>
                  <title>HTTP Caching</title>
                  <author fullname="R. Fielding"
                          initials="R."
                          role="editor"
                          surname="Fielding"/>
                  <author fullname="M. Nottingham"
                          initials="M."
                          role="editor"
                          surname="Nottingham"/>
                  <author fullname="J. Reschke"
                          initials="J."
                          role="editor"
                          surname="Reschke"/>
                  <date month="June" year="2022"/>
               </front>
               <seriesInfo name="STD" value="98"/>
               <seriesInfo name="RFC" value="9111"/>
               <seriesInfo name="DOI" value="10.17487/RFC9111"/>
            </reference>
            <reference anchor="FETCH" target="https://fetch.spec.whatwg.org/">
               <front>
                  <title>Fetch Living Standard</title>
                  <author fullname="Anne van Kesteren" initials="A." surname="van Kesteren">
                     <organization>Apple Inc.</organization>
                  </author>
                  <date>n.d.</date>
               </front>
               <annotation>WHATWG</annotation>
            </reference>
            <reference anchor="STRUCTURED-FIELDS">
               <front>
                  <title>Structured Field Values for HTTP</title>
                  <author fullname="M. Nottingham" initials="M." surname="Nottingham"/>
                  <author fullname="P-H. Kamp" surname="P-H. Kamp"/>
                  <date month="February" year="2021"/>
               </front>
               <seriesInfo name="RFC" value="8941"/>
               <seriesInfo name="DOI" value="10.17487/RFC8941"/>
            </reference>
            <reference anchor="WHATWG-ENCODING" target="https://encoding.spec.whatwg.org/">
               <front>
                  <title>Encoding Living Standard</title>
                  <author fullname="Anne van Kesteren" initials="A." surname="van Kesteren">
                     <organization>Apple Inc.</organization>
                  </author>
                  <date>n.d.</date>
               </front>
               <annotation>WHATWG</annotation>
            </reference>
            <reference anchor="WHATWG-INFRA" target="https://infra.spec.whatwg.org/">
               <front>
                  <title>Infra Living Standard</title>
                  <author fullname="Anne van Kesteren" initials="A." surname="van Kesteren">
                     <organization>Apple Inc.</organization>
                  </author>
                  <author fullname="Domenic Denicola" initials="D." surname="Denicola">
                     <organization>Google LLC</organization>
                  </author>
                  <date>n.d.</date>
               </front>
               <annotation>WHATWG</annotation>
            </reference>
            <reference anchor="WHATWG-URL" target="https://url.spec.whatwg.org/">
               <front>
                  <title>URL Living Standard</title>
                  <author fullname="Anne van Kesteren" initials="A." surname="van Kesteren">
                     <organization>Apple Inc.</organization>
                  </author>
                  <date>n.d.</date>
               </front>
               <annotation>WHATWG</annotation>
            </reference>
            <reference anchor="RFC2119">
               <front>
                  <title>Key words for use in RFCs to Indicate Requirement Levels</title>
                  <author fullname="S. Bradner" initials="S." surname="Bradner"/>
                  <date month="March" year="1997"/>
               </front>
               <seriesInfo name="BCP" value="14"/>
               <seriesInfo name="RFC" value="2119"/>
               <seriesInfo name="DOI" value="10.17487/RFC2119"/>
            </reference>
            <reference anchor="RFC8174">
               <front>
                  <title>Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words</title>
                  <author fullname="B. Leiba" initials="B." surname="Leiba"/>
                  <date month="May" year="2017"/>
               </front>
               <seriesInfo name="BCP" value="14"/>
               <seriesInfo name="RFC" value="8174"/>
               <seriesInfo name="DOI" value="10.17487/RFC8174"/>
            </reference>
         </references>
         <references anchor="sec-informative-references">
            <name>Informative References</name>
            <reference anchor="HTML" target="https://html.spec.whatwg.org/">
               <front>
                  <title>HTML Living Standard</title>
                  <author fullname="Anne van Kesteren" initials="A." surname="van Kesteren">
                     <organization>Apple Inc.</organization>
                  </author>
                  <date>n.d.</date>
               </front>
               <annotation>WHATWG</annotation>
            </reference>
            <reference anchor="NAV-TRACKING-MITIGATIONS"
                       target="https://privacycg.github.io/nav-tracking-mitigations/">
               <front>
                  <title>Navigational-Tracking Mitigations</title>
                  <author fullname="Pete Snyder" initials="P." surname="Snyder">
                     <organization>Brave Software, Inc.</organization>
                  </author>
                  <author fullname="Jeffrey Yasskin" initials="J." surname="Yasskin">
                     <organization>Google LLC</organization>
                  </author>
                  <date>n.d.</date>
               </front>
               <annotation>W3C Privacy CG</annotation>
            </reference>
         </references>
      </references>
      <?line 501?>
      <section anchor="acknowledgments" numbered="false">
         <name>Acknowledgments</name>
         <t>This document benefited from valuable reviews and suggestions by:</t>
         <ul spacing="normal">
            <li>
               <t>Adam Rice</t>
            </li>
            <li>
               <t>Julian Reschke</t>
            </li>
            <li>
               <t>Kevin McNee</t>
            </li>
            <li>
               <t>Liviu Tinta</t>
            </li>
            <li>
               <t>Mark Nottingham</t>
            </li>
            <li>
               <t>Martin Thomson</t>
            </li>
            <li>
               <t>Valentin Gosu</t>
            </li>
         </ul>
      </section>
   </back>
</rfc>
