sub (/src/:job) {
return NOT_FOUND if !job;
my $isowner = remote_user && remote_user->id eq job->rawowner;
- forbid !$isowner && (job->private || job->problem->private || job->contest && job->contest->is_running);
- my @headers = ('X-Forever' => 1, 'Cache-Control' => 'public, max-age=604800', 'Content-Type' => CONTENT_TYPES->{job->format});
+ my $private = job->private || job->problem->private || job->contest && job->contest->is_running;
+ forbid !$isowner && $private;
+ my $privacy = $private ? 'private' : 'public';
+ my @headers = ('X-Forever' => 1, 'Cache-Control' => "$privacy, max-age=604800", 'Content-Type' => CONTENT_TYPES->{job->format});
+ push @headers, (Vary => 'Authorization') if $private;
[200, \@headers, [job->source]]
},