mod_expires gives each MIME type a lifetime and writes it twice: as Expires, an absolute date, and as Cache-Control: max-age, in seconds. The base is access (request time) or modification (the file's mtime).
# /var/www/example/.htaccess: how long a browser may reuse each type of file
# Needs: mod_expires; AllowOverride Indexes
ExpiresActive On
ExpiresDefault "access plus 1 hour"
ExpiresByType text/html "access plus 0 seconds"
ExpiresByType application/json "access plus 0 seconds"
ExpiresByType text/css "access plus 1 year"
ExpiresByType text/javascript "access plus 1 year"
ExpiresByType image/* "access plus 1 month"
ExpiresByType font/woff2 "access plus 1 year"Line 3 switches the module on; line 4 covers types the others do not name. Pages and API data get zero, so browsers revalidate them; the year for CSS and JavaScript is safe only because the build fingerprints those names (Cache-Control and ETags). At 07:54:44 UTC:
/ max-age=0 Wed, 23 Sep 2026 07:54:44 GMT /account.php no-cache, max-age=0 Wed, 23 Sep 2026 07:54:44 GMT /assets/index-DMFBxjQs.css max-age=31536000 Thu, 23 Sep 2027 07:54:44 GMT /img/logo.png max-age=2592000 Fri, 23 Oct 2026 07:54:44 GMT
A month is 30 days. mod_expires stands back only when a response already has Expires, so it merged max-age=0 into the PHP page's own no-cache; for scripts, modification counts from the .php file's mtime. Under AllowOverride FileInfo alone: 500, ExpiresActive not allowed here.