Skip to content

fix: prevent edge cache from bypassing Cloudflare Access on SPA shell - #24

Merged
tbjers merged 2 commits into
mainfrom
fix/prevent-edge-cache-bypass-access
Jun 26, 2026
Merged

tbjers merged 2 commits into
mainfrom
fix/prevent-edge-cache-bypass-access

Conversation

@tbjers

@tbjers tbjers commented Jun 26, 2026

Copy link
Copy Markdown
Contributor

Summary

  • GET / was returning CF-Cache-Status: HIT for unauthenticated requests — Cloudflare's edge cache served index.html directly, bypassing Access entirely. No CF_Authorization cookie was ever minted.
  • Every subsequent /api/projects call hit requireAccess() with no cookie → 401 {"error":"Missing Access token"} → SvelteKit load threw → styled 500 error page.
  • This affected anonymous windows and any session where the edge cache was warm.

Fix: Add Cache-Control: no-store to /* in _headers so the SPA shell is never stored at the edge, ensuring Access evaluates every navigation request. Re-enable immutable long-lived caching for content-hashed JS/CSS chunks (/_app/immutable/*) and static font files (/fonts/*) so asset performance is unaffected.

Also picks up the font-src 'self' CSP directive from the font-fix branch that hasn't landed on main yet.

Test plan

  • Deploy and visit the site in an anonymous/private window — should be redirected to Cloudflare Access login instead of hitting the 500 error page
  • After authenticating, dashboard should load with projects and sparklines as shown in the design screenshots
  • Verify /_app/immutable/*.js responses still have long-lived cache headers (check Network tab → Cache-Control: public, max-age=31536000, immutable)
  • Verify /fonts/*.woff2 responses have long-lived cache headers

🤖 Generated with Claude Code

tbjers and others added 2 commits June 26, 2026 19:32
…shell

CF-Cache-Status: HIT was serving index.html to unauthenticated requests
before Access could validate them, so no CF_Authorization cookie was
ever minted and every /api/projects call returned 401.

Add Cache-Control: no-store to /* so the SPA shell is never stored at
the edge (forcing Access to evaluate each navigation), then re-enable
immutable long-lived caching specifically for content-hashed JS/CSS
chunks and static font files.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@tbjers
tbjers merged commit 07268fc into main Jun 26, 2026
5 checks passed
@tbjers
tbjers deleted the fix/prevent-edge-cache-bypass-access branch June 26, 2026 23:34

This branch was previously deployed

1 inactive deployment
preview — c61c8054 Deployed Jun 26, 2026 by tbjers via deploy #21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant