Attachments, icons, screenshots, etc should all be cachable. For all of those, we should change the no-cache headers to reasonable caching headers. We should remove the Set-cookie header (I think), to make it more cacheable. We should set a Last-Modified header based on the file's last date. Since these images & documents can be updated, we shouldn't specify aggressive caching. Perhaps just omit the caching directives altogether?
forge:db/4571
curl -I
against a project icon. Ensure that caching headers are good, no set-cookie header