Clear-Site-Data
header clears browsing data (cookies, storage, cache) associated with the requesting website. It allows web developers to have more control over the data stored locally by a browser for their origins.
| Header type | Response header |
|---|---|
| Forbidden header name | no |
Clear-Site-Data
header accepts one or more directives. If all types of data should be cleared, the wildcard directive (
"*"
) can be used.
// Single directive Clear-Site-Data: "cache" // Multiple directives (comma separated) Clear-Site-Data: "cache", "cookies" // Wild card Clear-Site-Data: "*"
All directives must comply with the quoted-string grammar . A directive that does not include the double quotes is invalid.
"cache"
Indicates that the server wishes to remove all cookies for the origin of the response URL. HTTP authentication credentials are also cleared out. This affects the entire registered domain, including subdomains. So https://example.com as well as https://stage.example.com, will have cookies cleared.
"storage"
localStorage.clear
),
sessionStorage.clear
),
IDBFactory.deleteDatabase
),
ServiceWorkerRegistration.unregister
),
NPP_ClearSiteData
).
"executionContexts"
Location.reload
).
"*"
(wildcard)
Indicates that the server wishes to clear all types of data for the origin of the response. If more data types are added in future versions of this header, they will also be covered by it.
If a user signs out of your website or service, you might want to remove locally stored data. You can achieve that by adding the
Clear-Site-Data
header when sending the page confirming that logging out from the site has been accomplished successfully (https://example.com/logout, for example):
Clear-Site-Data: "cache", "cookies", "storage", "executionContexts"
If this header is delivered with the response at https://example.com/clear-cookies, all cookies on the same domain https://example.com and any subdomains (like https://stage.example.com, etc), will be cleared out.
Clear-Site-Data: "cookies"
| 规范 | 状态 | Title |
|---|---|---|
| Clear Site Data | 工作草案 | 初始定义。 |
| Desktop | Mobile | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
Clear-Site-Data
Experimental
|
Chrome 完整支持 61 | Edge 完整支持 ≤79 |
Firefox
完整支持
63
|
IE ? | Opera 完整支持 48 | Safari ? | WebView Android 完整支持 61 | Chrome Android 完整支持 61 |
Firefox Android
完整支持
63
|
Opera Android 完整支持 45 | Safari iOS ? | Samsung Internet Android 完整支持 8.0 |
"cache"
Experimental
|
Chrome 完整支持 61 | Edge 完整支持 ≤79 |
Firefox
完整支持
63
|
IE ? | Opera 完整支持 48 | Safari ? | WebView Android 完整支持 61 | Chrome Android 完整支持 61 |
Firefox Android
完整支持
63
|
Opera Android 完整支持 45 | Safari iOS ? | Samsung Internet Android 完整支持 8.0 |
"cookies"
Experimental
|
Chrome 完整支持 61 | Edge 完整支持 ≤79 |
Firefox
完整支持
63
|
IE ? | Opera 完整支持 48 | Safari ? | WebView Android 完整支持 61 | Chrome Android 完整支持 61 |
Firefox Android
完整支持
63
|
Opera Android 完整支持 45 | Safari iOS ? | Samsung Internet Android 完整支持 8.0 |
"executionContexts"
Experimental
|
Chrome
不支持
No
注意事项
|
Edge
不支持
No
注意事项
|
Firefox
不支持
63 — 68
|
IE ? | Opera 不支持 No | Safari ? | WebView Android 不支持 No | Chrome Android 不支持 No |
Firefox Android
不支持
63 — 68
|
Opera Android 不支持 No | Safari iOS ? | Samsung Internet Android 完整支持 8.0 |
"storage"
Experimental
|
Chrome 完整支持 61 | Edge 完整支持 ≤79 |
Firefox
完整支持
63
|
IE ? | Opera 完整支持 48 | Safari ? | WebView Android 完整支持 61 | Chrome Android 完整支持 61 |
Firefox Android
完整支持
63
|
Opera Android 完整支持 45 | Safari iOS ? | Samsung Internet Android 完整支持 8.0 |
完整支持
不支持
兼容性未知
实验。期望将来行为有所改变。
见实现注意事项。
用户必须明确启用此特征。
Accept
Accept-CH
Accept-CH-Lifetime
Accept-Charset
Accept-Encoding
Accept-Language
Accept-Patch
Accept-Ranges
Access-Control-Allow-Credentials
Access-Control-Allow-Headers
Access-Control-Allow-Methods
Access-Control-Allow-Origin
Access-Control-Expose-Headers
Access-Control-Max-Age
Access-Control-Request-Headers
Access-Control-Request-Method
Age
Allow
Alt-Svc
Authorization
Cache-Control
Clear-Site-Data
Connection
Content-Disposition
Content-Encoding
Content-Language
Content-Length
Content-Location
Content-Range
Content-Security-Policy
Content-Security-Policy-Report-Only
Content-Type
Cookie
Cookie2
Cross-Origin-Embedder-Policy
Cross-Origin-Opener-Policy
Cross-Origin-Resource-Policy
DNT
DPR
Date
Device-Memory
Digest
ETag
Early-Data
Expect
Expect-CT
Expires
Feature-Policy
Forwarded
From
Host
If-Match
If-Modified-Since
If-None-Match
If-Range
If-Unmodified-Since
索引
Keep-Alive
Large-Allocation
Last-Modified
Link
Location
NEL
Origin
Pragma
Proxy-Authenticate
Proxy-Authorization
Public-Key-Pins
Public-Key-Pins-Report-Only
Range
Referer
Referrer-Policy
Retry-After
Save-Data
Sec-Fetch-Dest
Sec-Fetch-Mode
Sec-Fetch-Site
Sec-Fetch-User
Sec-WebSocket-Accept
Server
Server-Timing
Set-Cookie
Set-Cookie2
SourceMap
Strict-Transport-Security
TE
Timing-Allow-Origin
Tk
Trailer
Transfer-Encoding
Upgrade-Insecure-Requests
User-Agent
Vary
Via
WWW-Authenticate
Want-Digest
警告
X-Content-Type-Options
X-DNS-Prefetch-Control
X-Forwarded-For
X-Forwarded-Host
X-Forwarded-Proto
X-Frame-Options
X-XSS-Protection
100 Continue
101 Switching Protocols
103 Early Hints
200 OK
201 Created
202 Accepted
203 Non-Authoritative Information
204 No Content
205 Reset Content
206 Partial Content
300 Multiple Choices
301 Moved Permanently
302 Found
303 See Other
304 Not Modified
307 Temporary Redirect
308 Permanent Redirect
400 Bad Request
401 Unauthorized
402 Payment Required
403 Forbidden
404 Not Found
405 Method Not Allowed
406 Not Acceptable
407 Proxy Authentication Required
408 Request Timeout
409 Conflict
410 Gone
411 Length Required
412 Precondition Failed
413 Payload Too Large
414 URI Too Long
415 Unsupported Media Type
416 Range Not Satisfiable
417 Expectation Failed
418 I'm a teapot
422 Unprocessable Entity
425 Too Early
426 Upgrade Required
428 Precondition Required
429 Too Many Requests
431 Request Header Fields Too Large
451 Unavailable For Legal Reasons
500 Internal Server Error
501 Not Implemented
502 Bad Gateway
503 Service Unavailable
504 Gateway Timeout
505 HTTP Version Not Supported
506 Variant Also Negotiates
507 Insufficient Storage
508 Loop Detected
510 Not Extended
511 Network Authentication Required
CSP: base-uri
CSP: block-all-mixed-content
CSP: child-src
CSP: connect-src
CSP: default-src
CSP: font-src
CSP: form-action
CSP: frame-ancestors
CSP: frame-src
CSP: img-src
CSP: manifest-src
CSP: media-src
CSP: navigate-to
CSP: object-src
CSP: plugin-types
CSP: prefetch-src
CSP: referrer
CSP: report-to
CSP: report-uri
CSP: require-sri-for
CSP: sandbox
CSP: script-src
CSP: script-src-attr
CSP: script-src-elem
CSP: style-src
CSP: style-src-attr
CSP: style-src-elem
CSP: trusted-types
CSP: upgrade-insecure-requests
CSP: worker-src