For Workes & Pages, what is the name of the domain?
none
What is the error number?
none
What is the issue or error you’re encountering
Possibility to bruteforce various flexibility variants
What steps have you taken to resolve the issue?
Cloudflare’s Images flexible variants feature allows users to request different versions of an image by specifying various parameters in the URL, such as width. However, a significant issue arises because Cloudflare doesn’t support URL signing for these flexible variants. This lack of URL signing means that anyone can brute-force the URLs by trying different widths (e.g., from width=0 to width=2000), potentially generating numerous image variants.
This brute-force method can lead to unexpected and substantial costs, as each variant requested is processed and billed by Cloudflare. Without the ability to sign URLs and restrict access to authorized requests, there is a risk of abuse, which can result in high expenses for website owners relying on Cloudflare’s image optimization services.
I also saw a similar topic from 2022, but it was never solved. It would be nice if you could implement this feature.