Skip to content

Fix data feed failing on Cloudflare preview - #182

Merged
richardthe3rd merged 1 commit into
mainfrom
claude/fix-cloudflare-data-feed-UEoy2
Dec 21, 2025
Merged

Fix data feed failing on Cloudflare preview#182
richardthe3rd merged 1 commit into
mainfrom
claude/fix-cloudflare-data-feed-UEoy2

Conversation

@richardthe3rd

Copy link
Copy Markdown
Owner

Resolves data feed failures when visiting PR preview URLs for the first time. The issue occurred because Cloudflare's edge cache was serving CORS responses without considering the requesting origin.

Root Cause:
Cloudflare's cache uses only the URL as the cache key by default. When different origins (pr-123, pr-184, etc.) request the same URL, they would receive the same cached response, including CORS headers meant for a different origin. This caused CORS errors when the browser rejected the mismatched Access-Control-Allow-Origin header.

The Fix:
Add Vary: Origin header to all CORS responses. This tells Cloudflare (and other caches) to include the Origin request header in the cache key, ensuring each origin gets its own cached response with correct CORS headers.

Additional improvements:

  • Reduce CORS preflight cache to 10 seconds for staging/preview environments (down from 5 minutes) to allow quick recovery from any deployment issues
  • Production keeps 5 minute preflight cache for optimal performance

This is the standard solution for caching origin-specific CORS responses.

Resolves data feed failures when visiting PR preview URLs for the first
time. The issue occurred because Cloudflare's edge cache was serving CORS
responses without considering the requesting origin.

Root Cause:
Cloudflare's cache uses only the URL as the cache key by default. When
different origins (pr-123, pr-184, etc.) request the same URL, they would
receive the same cached response, including CORS headers meant for a
different origin. This caused CORS errors when the browser rejected the
mismatched Access-Control-Allow-Origin header.

The Fix:
Add Vary: Origin header to all CORS responses. This tells Cloudflare (and
other caches) to include the Origin request header in the cache key,
ensuring each origin gets its own cached response with correct CORS headers.

Additional improvements:
- Reduce CORS preflight cache to 10 seconds for staging/preview environments
  (down from 5 minutes) to allow quick recovery from any deployment issues
- Production keeps 5 minute preflight cache for optimal performance

This is the standard solution for caching origin-specific CORS responses.
@richardthe3rd
richardthe3rd merged commit cb69c4f into main Dec 21, 2025
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants