Re: HTTP Content-Location header usage

Mark Nottingham <> Wed, 28 September 2016 06:15 UTC

Return-Path: <>
Received: from localhost (localhost []) by (Postfix) with ESMTP id DBDF112B391 for <>; Tue, 27 Sep 2016 23:15:31 -0700 (PDT)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: -9.237
X-Spam-Status: No, score=-9.237 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HEADER_FROM_DIFFERENT_DOMAINS=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RP_MATCHES_RCVD=-2.316, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id WfLkrRQchcZz for <>; Tue, 27 Sep 2016 23:15:30 -0700 (PDT)
Received: from ( []) (using TLSv1.2 with cipher DHE-RSA-AES128-SHA (128/128 bits)) (No client certificate requested) by (Postfix) with ESMTPS id 2B87312B337 for <>; Tue, 27 Sep 2016 23:15:30 -0700 (PDT)
Received: from lists by with local (Exim 4.80) (envelope-from <>) id 1bp85d-0006dX-3p for; Wed, 28 Sep 2016 06:11:33 +0000
Resent-Date: Wed, 28 Sep 2016 06:11:33 +0000
Resent-Message-Id: <>
Received: from ([]) by with esmtps (TLS1.2:DHE_RSA_AES_128_CBC_SHA1:128) (Exim 4.80) (envelope-from <>) id 1bp85R-0006Zi-5D for; Wed, 28 Sep 2016 06:11:21 +0000
Received: from ([]) by with esmtps (TLS1.2:DHE_RSA_AES_256_CBC_SHA256:256) (Exim 4.80) (envelope-from <>) id 1bp85P-0006r2-9F for; Wed, 28 Sep 2016 06:11:20 +0000
Received: from [] (unknown []) (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by (Postfix) with ESMTPSA id C10A922E1F3; Wed, 28 Sep 2016 02:10:54 -0400 (EDT)
Content-Type: text/plain; charset="utf-8"
Mime-Version: 1.0 (Mac OS X Mail 10.0 \(3226\))
From: Mark Nottingham <>
In-Reply-To: <>
Date: Wed, 28 Sep 2016 16:10:51 +1000
Content-Transfer-Encoding: quoted-printable
Message-Id: <>
References: <>
To: Никита Пискунов <>
X-Mailer: Apple Mail (2.3226)
Received-SPF: pass client-ip=;;
X-W3C-Hub-Spam-Status: No, score=-8.6
X-W3C-Hub-Spam-Report: AWL=1.039, BAYES_00=-1.9, RCVD_IN_DNSWL_LOW=-0.7, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, W3C_AA=-1, W3C_DB=-1, W3C_IRA=-1, W3C_IRR=-3, W3C_WL=-1
X-W3C-Scan-Sig: 1bp85P-0006r2-9F 56e830d61c078e1fd5a25b4c31c59dba
Subject: Re: HTTP Content-Location header usage
Archived-At: <>
X-Mailing-List: <> archive/latest/32424
Precedence: list
List-Id: <>
List-Help: <>
List-Post: <>
List-Unsubscribe: <>

> On 21 Sep. 2016, at 10:35 pm, Никита Пискунов <> wrote:
> Hello,
> i've already posted my comment about ambiguous Content-Location header usage description here as a GitHub Issue. And I've also decided to raise the discussion via email.
> So, my question is:
> The RFC 5789 discribes the apropriate usage of Content-Location header in PATCH:
> A response to this method is only cacheable if it contains explicit freshness information (such as an Expires header or "Cache-Control: max-age" directive) as well as the Content-Location header matching the Request-URI, indicating that the PATCH response body is a resource representation.
> So, it means, that Content-Location header must appear only if the actual represantation is the part of response body for PATCH.

No. Content-Location can appear; it indicates a URL for the representation in the message. *If* it matches the request-target, you can deduce that it's a representation of what's currently at that resource (after the PATCH is applied). But if it doesn't match, it can still appear.

> Also the usage of Content-Location is mentioned in another RFC 7231:
> For a state-changing request like PUT (Section 4.3.4) or POST (Section 4.3.3), it implies that the server's response contains the new representation of that resource, thereby distinguishing it from representations that might only report about the action (e.g., "It worked!"). This allows authoring applications to update their local copies without the need for a subsequent GET request.
> So, accordingly to this information in both RFCs, the apropriate usage of Content-Location with state-changing requests are following:
> Content-Location must appear in response only if response-body contains the new resourse representation.
> But, there is also an example in RFC 5789:
> Successful PATCH response to existing text file:
> HTTP/1.1 204 No Content
> Content-Location: /file.txt
> ETag: "e0023aa4f"
> The 204 response code is used because the response does not carry a message body (which a response with the 200 code would have). Note that other success codes could be used as well.
> Furthermore, the ETag response header field contains the ETag for the entity created by applying the PATCH, available at, as indicated by the Content-Location response header field.
> How you can see, there is a Content-Location presented in response with 204 status code (No content). Ofcourse, this response doesn't contain any body as well as new resourse representation. This fact adds some ambiguity in Content-Location header description. What is the correct usage of this header?

Mark Nottingham