← Cloudflare SecurityCONTENT HISTORY

Update to Cloudflare Security

Snapshot Sep 30, 2026 · 23:17 UTC · version 0.1.0

Collection source: not recorded for this historical snapshot.

WHAT CHANGED · RULE-BASED ANALYSIS

First saved snapshot

No earlier snapshot is available to establish a change.

Compare saved observations

Download comparison JSON
Full technical diff · 0 changed fields
Full snapshot data
{
  "name": "headers-cors-cache-security",
  "description": "Review HTTP security headers, CORS, cookies, redirects, and cache isolation for sensitive responses.",
  "included_files": [],
  "skill_md_contents": "---\nname: headers-cors-cache-security\ndescription: Review HTTP security headers, CORS, cookies, redirects, and cache isolation for sensitive responses.\n---\n\n# Headers, CORS, and Cache Security\n\nInspect response headers on static, Worker-generated, SSR, API, and error responses. Consider CSP, frame protections, `X-Content-Type-Options`, Referrer-Policy, Permissions-Policy, and HSTS only with deployment-specific compatibility analysis. Cloudflare Pages `_headers` rules do not automatically affect responses generated by Worker code; verify both paths. Avoid blindly copying CSP/HSTS examples that could break scripts, subdomains, or preload behavior.\n\nTreat CORS as a browser access policy, never as authentication. Avoid wildcard origins with credentials; allow only necessary origins, methods, and headers. Review cookie attributes and redirect destinations. For caching, verify cache keys and bypass/private behavior for authenticated or personalized content; test cross-user cache isolation. Do not cache sensitive responses publicly without explicit safe design evidence. Report actual response observations separately from repository configuration.\n"
}

SHA-256: 54f1b435b4f07f4ae025fe0ddbe16ab8d4b46e5346b5ba7e0dad75b78ec61cd4