Technical

HTTP 302

Also called Found.

HTTP 302 is the redirect status that sends the client to another URL for now, without saying the original has moved. The client is expected to use the original address next time.

How it is measured

`curl -I https://example.com/sale` shows `302 Found` and a `Location` header. With no `Cache-Control` or `Expires`, browsers do not store it, so every visit asks the origin again. Count 302s in the log by path per day.

Look for a 302 that has quietly been there for months. A temporary redirect that never leaves is a design smell, and it adds a round trip to every request.

Worked example

A ticketing site sends `/` to `/queue` with a 302 during an on-sale. 48,000 requests in the first minute are redirected, so the origin sees each visitor twice. When the sale ends the rule is deleted, and `/` serves directly again with nothing stale cached anywhere.

The same week, a rogue rule in a theme file sends visitors arriving from Google to a pharmacy site, using a 302 only when the Referer contains google. The owner types the URL directly and sees nothing wrong.

How it differs

An HTTP 302 is temporary. An HTTP 301 is permanent. The 302 keeps the original URL as the one to index and bookmark, and the 301 asks the world to switch. The wrong choice either hides a real move or locks in a one-off.

Common errors

Leaving a 302 in place for a permanent move. Using one for http to https. Expecting it to preserve a POST, when browsers historically switch to GET and only 307 keeps the method. Writing redirects that depend on Referer or user-agent, which look like cloaking. Missing a 302 injected into `.htaccess`.

In practice

List every 302 in the logs once a month. Convert any that have lasted longer than a month to 301s, or remove them. Test as a crawler and with a Google search Referer to catch conditional redirects.

See also

HTTP 301, Malicious redirect

Sources

Count this on a real site.

Watch my website