Our requirement came from a security test. Immediately after logging out from our Web site you might push the back button and view cached webpages.A piece around should be to set a brief-dwelling cookie with a relentless identify but a GUID price to make the illusion of an "authentication token". A max-age of one next is enough (tested in 136 and 1