← Cloudflare SecurityCONTENT HISTORYWHAT CHANGED · RULE-BASED ANALYSIS
Update to Cloudflare Security
Snapshot Sep 30, 2026 · 23:17 UTC · version 0.1.0
Collection source: not recorded for this historical snapshot.
First saved snapshot
No earlier snapshot is available to establish a change.
Compare saved observations
Download comparison JSONFull technical diff · 0 changed fields
Full snapshot data
{
"name": "headers-cors-cache-security",
"description": "Review HTTP security headers, CORS, cookies, redirects, and cache isolation for sensitive responses.",
"included_files": [],
"skill_md_contents": "---\nname: headers-cors-cache-security\ndescription: Review HTTP security headers, CORS, cookies, redirects, and cache isolation for sensitive responses.\n---\n\n# Headers, CORS, and Cache Security\n\nInspect response headers on static, Worker-generated, SSR, API, and error responses. Consider CSP, frame protections, `X-Content-Type-Options`, Referrer-Policy, Permissions-Policy, and HSTS only with deployment-specific compatibility analysis. Cloudflare Pages `_headers` rules do not automatically affect responses generated by Worker code; verify both paths. Avoid blindly copying CSP/HSTS examples that could break scripts, subdomains, or preload behavior.\n\nTreat CORS as a browser access policy, never as authentication. Avoid wildcard origins with credentials; allow only necessary origins, methods, and headers. Review cookie attributes and redirect destinations. For caching, verify cache keys and bypass/private behavior for authenticated or personalized content; test cross-user cache isolation. Do not cache sensitive responses publicly without explicit safe design evidence. Report actual response observations separately from repository configuration.\n"
}SHA-256: 54f1b435b4f07f4ae025fe0ddbe16ab8d4b46e5346b5ba7e0dad75b78ec61cd4