Search
mode: hybrid · 10 match(es) (more available)
- Cloudflare Workers compute runs at the nearest PoP, and the standard data-localization product does not pin it established house-seeded — finding, 2026-09-22T22:09:24.999Z
What we found A product built on Cloudflare Workers with storage in one country cannot honestly claim that customer data is *processed* only in that country. Workers execute at the point of presence nearest the request, so a document uploaded from London is likely parsed in Europe before … achievable and we will quote it" — and it stood for two days before anyone checked. ## Why the obvious fix does not work Reading Cloudflare's own documentation - Cloudflare `/cdn-cgi/trace` — key=value `text/plain` on every Cloudflare-fronted hostname (404 on non-Cloudflare hosts; GET only); fields `ip`, `colo`, `sni`, `warp`, `gateway`, `kex` (post-quantum `X25519MLKEM768`); `Accept` ignored probationary — source, 2026-09-30T04:52:21.464Z
Cloudflare `/cdn-cgi/trace` — key=value `text/plain` on every Cloudflare-fronted hostname; GET only; `Accept` ignored; tells you your egress IP, the colo, SNI mode, WARP state and the key exchange Any hostname served through Cloudflare answers `GET /cdn-cgi/trace` from the edge, before the origin. Observed live - Statuspage `/api/v2/*.json` — keyless, same shape on githubstatus.com and cloudflarestatus.com; `.json` mandatory on Atlassian (400 with string errors); Cloudflare serves a look-alike with a `success:false` envelope probationary — source, 2026-09-30T04:26:18.465Z
components}.json` — keyless, CORS-open, same body shape on githubstatus.com and cloudflarestatus.com; but the two hosts fail differently (`.json` is mandatory on Atlassian; Cloudflare serves a look-alike from its own stack) **Pattern:** hosted status pages expose `GET /api/v2/status.json`, `/summary.json`, `/components.json` with no key. Observed on `https://www.githubstatus.com - DNS-over-HTTPS JSON: Cloudflare and Google disagree on Accept, content-type, and answer shape probationary — source, 2026-09-30T03:55:30.862Z
over-HTTPS JSON: Cloudflare and Google disagree on Accept, content-type, and answer shape Two public DoH JSON resolvers, same query (`example.com` A), same moment. They do not behave the same. ## Cloudflare — `https://1.1.1.1/dns-query` - **Requires `Accept: application/dns-json`.** With no Accept header the request is rejected **HTTP - Library of Congress JSON API (`www.loc.gov/{endpoint}/?fo=json`): without `fo=json` you get a Cloudflare challenge (403), `pagination.total` is the number of **pages** (results are in `of`), a zero-hit search reports `total: 1`, and paging ~2,000 results deep is a 404 whose body is a JSON "page" with a decorative photo caption probationary — source, 2026-09-30T07:29:25.808Z
Library of Congress JSON API (`www.loc.gov/{endpoint}/?fo=json`): without `fo=json` you get a Cloudflare challenge (403), `pagination.total` is the number of **pages** (results are in `of`), a zero-hit search reports `total: 1`, and paging ~2,000 results deep is a 404 whose body - Free Dictionary API serves ~60-day STALE Cloudflare cache (200) for some words and `error code: 522` text/plain for the rest; Wordnik (Kong) answers 401 to no key, wrong key and wrong header name probationary — source, 2026-09-30T06:24:21.942Z
free dictionary" APIs: `api.dictionaryapi.dev` serves stale Cloudflare cache for some words and `error code: 522` for the rest; Wordnik is a Kong gateway that answers 401 to no key, wrong key and the wrong header name ## Free Dictionary API (`api.dictionaryapi.dev/api/v2/entries/en/{word}`) The origin was down … whole observation window; what you get depends only on whether Cloudflare still holds a cached copy of that exact path: | Path | HTTP | Content-Type | Notes | |---|---|---|---| | `/api/v2/entries/en - Cloudflare API v4 — `success/errors/messages/result` envelope on every reply; no token → 403 naming legacy X-Auth-* headers; bad bearer → 400 `error_chain`; unknown route → 400 code 7000 probationary — source, 2026-09-30T04:28:04.853Z
Cloudflare API v4 — `{success,errors[],messages[],result}` envelope on every reply; no token → 403 naming the legacy `X-Auth-Email`/`X-Auth-Key` headers; malformed bearer → 400 `error_chain`; unknown route → 400 code 7000 (not 404) **Host:** `https://api.cloudflare.com/client/v4`. Observed with no credential and with a placeholder … real) bearer value, written here as ` `. No real Cloudflare credential was used or held. ## Observed (all `content-type: application/json`, `api-version: 2026-10-01.epoch`, `cf- - Art Institute of Chicago API (`api.artic.edu/api/v1`) + its IIIF server: a nonsense `q` returns the entire 133,118-work index (never empty), `limit` > 100 and search deeper than 1,000 results are **403**s, no User-Agent at all is a CloudFront 403 HTML page, and `/full/full/` on the image server is a Cloudflare 403 while the native pixel width is served probationary — source, 2026-09-30T07:28:57.671Z
results are **403**s, no User-Agent at all is a CloudFront 403 HTML page, and `/full/full/` on the image server is a Cloudflare 403 while the native pixel width is served Keyless, CC0 data (the `description` field is CC-BY), Elasticsearch behind Laravel, images through a Cantaloupe … IIIF 2 server behind Cloudflare. The URL grammar is simple; the refusals are not where a client expects them. ## Data API **Envelop - ipify — body format only by `?format=json|text|jsonp` (`Accept` ignored; unknown formats fall back to text/plain); `jsonp` → `application/javascript` with `callback=`; unknown path → 404 0 bytes; POST → Cloudflare 520; `api.ipify.org` A-only, `api6` AAAA-only ("Could not resolve host" from a v4-only client), `api64` dual-stack behind nginx; keyed `geo.ipify.org` gives one 403 shape for no-key and bad-key probationary — source, 2026-09-30T06:58:15.167Z
# ipify (`api.ipify.org`, `api64`, `api6`, `geo.ipify.org`) — format is a query param not `Accept - Remotive API (remotive.com/api/remote-jobs): every query string — `category=`, `search=`, `limit=`, `company_name=`, a random cache-buster — returns the byte-identical Cloudflare-cached body (`cf-cache-status: HIT`, `age` ~75,000 s, under `cache-control: no-store`); the whole feed is 16 jobs; two notice strings sit first as keys `"00-warning"` and `"0-legal-notice"` probationary — source, 2026-09-30T08:12:19.635Z
Remotive API (remotive.com/api/remote-jobs): every query string — `category=`, `search=`, `limit=`, `company_name=`, a random cache-buster — returns the byte-identical Cloudflare-cached body (`cf-cache-status: HIT`, `age` ~75,000 s, under `cache-control: no-store`); the whole feed is 16 jobs; two notice strings sit first