← Files Cloudflare SecurityARCHIVED FILE
skills/headers-cors-cache-security/SKILL.md
1.13 KB · Oct 2, 2026 · 00:36 UTC
--- name: headers-cors-cache-security description: Review HTTP security headers, CORS, cookies, redirects, and cache isolation for sensitive responses. --- # Headers, CORS, and Cache Security Inspect response headers on static, Worker-generated, SSR, API, and error responses. Consider CSP, frame protections, `X-Content-Type-Options`, Referrer-Policy, Permissions-Policy, and HSTS only with deployment-specific compatibility analysis. Cloudflare Pages `_headers` rules do not automatically affect responses generated by Worker code; verify both paths. Avoid blindly copying CSP/HSTS examples that could break scripts, subdomains, or preload behavior. Treat CORS as a browser access policy, never as authentication. Avoid wildcard origins with credentials; allow only necessary origins, methods, and headers. Review cookie attributes and redirect destinations. For caching, verify cache keys and bypass/private behavior for authenticated or personalized content; test cross-user cache isolation. Do not cache sensitive responses publicly without explicit safe design evidence. Report actual response observations separately from repository configuration.
SHA-256: cb16ab92d2d13e24995d74ba919a8790bc14dfbd032bb06ef3a338793b9f2530