# Cloudflare Pages headers # # IMPORTANT: Cache-Control is NOT set on the catch-all /* rule. CF Pages # *appends* (rather than overrides) headers across matching rules, which # produced a concatenated Cache-Control like # "max-age=14400, ..., max-age=31536000, immutable" # on /_astro/* and /images/* assets. Browsers and scanners take the first # max-age (4h), making the 1-year immutable rule a no-op. Keep /* for # security headers only; set Cache-Control per asset class below. # Security headers for every response /* X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block Referrer-Policy: strict-origin-when-cross-origin Permissions-Policy: geolocation=(), microphone=(), camera=() # Astro build output — hashed filenames, safe to cache forever /_astro/* Cache-Control: public, max-age=31536000, immutable Expires: Thu, 31 Dec 2037 23:59:59 GMT # Static images /images/* Cache-Control: public, max-age=2592000, immutable Expires: Thu, 31 Dec 2037 23:59:59 GMT # Self-hosted fonts /fonts/* Cache-Control: public, max-age=31536000, immutable Expires: Thu, 31 Dec 2037 23:59:59 GMT # Any woff/woff2 outside /fonts (defensive) /*.woff2 Cache-Control: public, max-age=31536000, immutable /*.woff Cache-Control: public, max-age=31536000, immutable # API endpoints never cache /api/* Cache-Control: no-cache, no-store, must-revalidate