Skip to content
FeaturesPricingAffiliateBlogHelpAboutContact
Get StartedSign In
Back to Blog
industry2026-05-236 min read

Your file header is not a spec — how worker handlers become silent CDN leaks

A Cloudflare Worker handler header said "serves affiliate/ prefix only" — the code enforced no such gate. SOC2 evidence + backup metadata were publicly fetchable. thMenu's PR #551 QQ F4 fix: a single-line `decoded.startsWith(affiliate/)` check.

th

thMenu Team

thmenu.com

Found this helpful? Share it.