Repository navigation
fix: prevent edge cache from bypassing Cloudflare Access on SPA shell - #24
Merged
Merged
Conversation
…shell CF-Cache-Status: HIT was serving index.html to unauthenticated requests before Access could validate them, so no CF_Authorization cookie was ever minted and every /api/projects call returned 401. Add Cache-Control: no-store to /* so the SPA shell is never stored at the edge (forcing Access to evaluate each navigation), then re-enable immutable long-lived caching specifically for content-hashed JS/CSS chunks and static font files. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This branch was previously deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
GET /was returningCF-Cache-Status: HITfor unauthenticated requests — Cloudflare's edge cache servedindex.htmldirectly, bypassing Access entirely. NoCF_Authorizationcookie was ever minted./api/projectscall hitrequireAccess()with no cookie →401 {"error":"Missing Access token"}→ SvelteKit load threw → styled 500 error page.Fix: Add
Cache-Control: no-storeto/*in_headersso the SPA shell is never stored at the edge, ensuring Access evaluates every navigation request. Re-enable immutable long-lived caching for content-hashed JS/CSS chunks (/_app/immutable/*) and static font files (/fonts/*) so asset performance is unaffected.Also picks up the
font-src 'self'CSP directive from the font-fix branch that hasn't landed onmainyet.Test plan
/_app/immutable/*.jsresponses still have long-lived cache headers (check Network tab →Cache-Control: public, max-age=31536000, immutable)/fonts/*.woff2responses have long-lived cache headers🤖 Generated with Claude Code