CF-CACHE-CONTROL - how to set to MISS or Hide this header

What is the name of the domain?

na

What is the issue you’re encountering

security team is asking us to secure this header by assigning a MISS value or is it possible to just hide this header?

What is the current SSL/TLS setting?

Full (strict)

it should be *CF-CACHE-STATUS

You cannot remove this HTTP header. Here are all possible responses:

You can set your Cace Rule to Bypass for your whole domain, therefrom Cloudflare wouldn’t cache anything and the request will always go the the origin server.

Helpful article how to create such Cache rule in the Dashboard for your zone:

Example in picture:

To make it work, make sure your DNS records for your hostname such as example.com and/or www are proxied and set to :orange: under the DNS tab of Cloudflare dashboard for your zone.

Your security team has an interesting request… Have they indicated why they believe this is a security issue? I made serious investments in :popcorn: after the last US election, I can open up a bag for this answer too.

2 Likes

This topic was automatically closed 2 days after the last reply. New replies are no longer allowed.