colearendt
01/11/2024, 2:36 AMcurl -i https://cdn.btst.io/test.html
HTTP/2 200
date: Thu, 11 Jan 2024 02:34:45 GMT
content-length: 0
access-control-allow-origin: *
vary: Origin
access-control-allow-credentials: true
access-control-allow-headers: Content-Type, Vary, Origin, Referer, User-Agent, Authorization
access-control-allow-methods: GET, POST, PUT, DELETE, OPTIONS, PATCH, HEAD
report-to: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=8OA78wCnvcRLW8CC5ljmtce%2BUhoPFbwNekVtEOQFJR2pMlYT5PVokesuCbId8U2u05wrqi3%2FkxP3kUy3K92R%2BvEg3w7XGcMk5vQraiHBgoKxbYMbUfBYchbrM4woyQ%3D%3D"}],"group":"cf-nel","max_age":604800}
nel: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
server: cloudflare
cf-ray: 8439c3330d605cae-RDU
alt-svc: h3=":443"; ma=86400
I don't know how long this has been happening, but I don't see any evidence reported anywhere?
Is this an issue on y'all's side?colearendt
01/11/2024, 2:39 AMkian
01/11/2024, 2:41 AM200 OK
on /
despite /
having never worked on custom domains is weird.kian
01/11/2024, 2:42 AMkian
01/11/2024, 2:46 AMcolearendt
01/11/2024, 3:00 AMcolearendt
01/11/2024, 3:01 AMcolearendt
01/11/2024, 3:01 AM✗ curl -i cdn.btst.io/test.html
HTTP/1.1 200 OK
Date: Thu, 11 Jan 2024 03:01:17 GMT
Content-Type: text/html
Content-Length: 25
Connection: keep-alive
ETag: "68219c28daba0ca0e67295f1d71aaf37"
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=x4xcZfVXl5sGxXIIlP3uehMNGl7SfVRPkBu%2BF9WPODYldFIi%2FaGDLfUra4%2B6WjiF6nL%2F3B184A3k9pUj2cacA6nFS1mKa%2BkZ84y8jfpkg8%2Fx8tGRsMbTsn7hwyUn0w%3D%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 8439ea1278115cb1-RDU
alt-svc: h3=":443"; ma=86400
<html>
Success!!
</html>
✗ curl -i cdn2.btst.io/test.html
HTTP/1.1 200 OK
Date: Thu, 11 Jan 2024 03:01:22 GMT
Content-Length: 0
Connection: keep-alive
Access-Control-Allow-Origin: *
Vary: Origin
Access-Control-Allow-Credentials: true
Access-Control-Allow-Headers: Content-Type, Vary, Origin, Referer, User-Agent, Authorization
Access-Control-Allow-Methods: GET, POST, PUT, DELETE, OPTIONS, PATCH, HEAD
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=ioFpioSLw6%2B4yTuBiRiId5XFaKbmupwDEngFurqI00Psx6r77PrA68uWDly8vNZSbBuqTfIZpRsTaoOZttQMCoqP0REN3ytXbH4w1KKsckwtB791dE8qq3QuQ6Z0PGg%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 8439ea2cc8ed5ca1-RDU
alt-svc: h3=":443"; ma=86400
colearendt
01/11/2024, 3:02 AMcolearendt
01/11/2024, 3:04 AMcolearendt
01/11/2024, 3:04 AMcolearendt
01/11/2024, 3:05 AMcolearendt
01/11/2024, 2:49 PMkian
01/11/2024, 4:12 PMcolearendt
01/11/2024, 6:02 PMkian
01/11/2024, 6:05 PMkian
01/11/2024, 6:05 PMkian
01/11/2024, 6:05 PMcolearendt
01/11/2024, 6:11 PMcolearendt
01/11/2024, 7:45 PMcolearendt
01/11/2024, 7:45 PMkian
01/11/2024, 7:46 PM*/*
would be expected to match everythingkian
01/11/2024, 7:46 PMcolearendt
01/11/2024, 7:46 PMkian
01/11/2024, 7:46 PMcolearendt
01/11/2024, 7:46 PMcolearendt
01/11/2024, 7:46 PMChaika
01/12/2024, 2:50 AM*btst.io/*
, Service: none to stop it from taking over subdomains for that domain, the more specific one wins
docs: https://developers.cloudflare.com/cloudflare-for-platforms/cloudflare-for-saas/start/advanced-settings/worker-as-origin/colearendt
01/12/2024, 3:10 AM*
that matches SaaS domains, without matching domains on my TLD?
In my testing SaaS domains (i.e. user provided domains), I needed a matching rule defined in order for my worker to serve traffic to themChaika
01/12/2024, 3:24 AM*.<zonename>.com/*
service none along with the */*
for SaaS, and the more specific one wins (so service none will apply to your own domain)colearendt
01/14/2024, 11:38 PM