CDN security
Security settings are managed from the Security tab of a CDN. Request blocking by country or IP address is available through edge rules.
CORS headers
When enabled, the CDN adds Access-Control-Allow-Origin: * to responses, which lets pages on other domains load your CDN assets. This is required for web fonts and for scripts that fetch data across origins.
An Allowed file extensions list limits which files receive the header. The default list covers fonts (eot, ttf, woff, woff2), css, js, images (jpg, jpeg, png, webp, gif, svg), and media (mp3, mp4, mpeg, webm). An empty list applies the header to every response.
Hotlink protection
Hotlink protection controls which websites can embed your content, based on the Referer header the browser sends.
| Setting | What it does |
|---|---|
| Allowed referrers | Hostnames that may embed your content. When the list is empty, all referrers are allowed. |
| Blocked referrers | Hostnames that are always denied, even if they would otherwise be allowed. |
| Block requests with no referrer | When on, requests without a Referer header are denied. Direct links, some privacy-focused browsers, and many API clients send no referrer, so enable this with care. |
