Skip to content

Commit f03ff55

Browse files
xmflszzxmflsct
andauthored
[WAF] Document ETag behavior for insecure JS replacement (#33854)
Co-authored-by: Zhiyuan Zheng <zhiyuan@cloudflare.com>
1 parent ee116ef commit f03ff55

2 files changed

Lines changed: 6 additions & 2 deletions

File tree

‎src/content/docs/cache/reference/etag-headers.mdx‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,7 @@ Weak ETag headers indicate a cached resource is semantically equivalent to the v
1717
:::note
1818

1919

20-
When using weak ETag headers, it is necessary to disable certain features such as [Email Obfuscation](/waf/tools/scrape-shield/email-address-obfuscation/) and [Automatic HTTPS Rewrites](/ssl/edge-certificates/additional-options/automatic-https-rewrites/) to prevent Cloudflare from removing the ETag headers set by your origin web server. For a comprehensive list of the features you need to disable, refer to the [Notes about end-to-end compression](/speed/optimization/content/compression/#notes-about-end-to-end-compression).
20+
When using weak ETag headers, it is necessary to disable certain features such as [Email Obfuscation](/waf/tools/scrape-shield/email-address-obfuscation/), [Automatic HTTPS Rewrites](/ssl/edge-certificates/additional-options/automatic-https-rewrites/), and [Replace insecure JavaScript libraries](/waf/tools/replace-insecure-js-libraries/) to prevent Cloudflare from removing the ETag headers set by your origin web server. For a comprehensive list of the features you need to disable, refer to the [Notes about end-to-end compression](/speed/optimization/content/compression/#notes-about-end-to-end-compression).
2121

2222

2323
:::
@@ -61,7 +61,7 @@ When **Respect Strong ETags** is disabled, Cloudflare will preserve strong ETag
6161

6262
* The origin server sends a response compressed using GZIP or Brotli, or an uncompressed response.
6363
* If the origin server sends a compressed response, the visitor accepts the same compression (GZIP, Brotli), according to the `accept-encoding` header.
64-
* [Rocket Loader](/speed/optimization/content/rocket-loader/) and [Email Obfuscation](/waf/tools/scrape-shield/email-address-obfuscation/) features are disabled.
64+
* [Rocket Loader](/speed/optimization/content/rocket-loader/), [Email Obfuscation](/waf/tools/scrape-shield/email-address-obfuscation/), and [Replace insecure JavaScript libraries](/waf/tools/replace-insecure-js-libraries/) features are disabled.
6565

6666
In all other situations, Cloudflare will either convert strong ETag headers to weak ETag headers or remove the strong ETag. For example, given the following conditions:
6767

‎src/content/docs/waf/tools/replace-insecure-js-libraries.mdx‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -37,6 +37,10 @@ Additionally, if you are defining a CSP via HTML `meta` tag, you must either tur
3737

3838
When turned on, Cloudflare will check HTTP(S) proxied traffic for `script` tags with an `src` attribute pointing to a potentially insecure service and replace the `src` value with the equivalent link hosted under [cdnjs](https://cdnjs.cloudflare.com/).
3939

40+
:::caution
41+
Replace insecure JavaScript libraries modifies eligible HTML responses. Cloudflare may decompress and recompress the response. When the transformation runs, Cloudflare removes headers such as `ETag` and `Content-Length`. For more information, refer to [Notes about end-to-end compression](/speed/optimization/content/compression/#notes-about-end-to-end-compression).
42+
:::
43+
4044
The rewritten URL will keep the original URL scheme (`http://` or `https://`).
4145

4246
For `polyfill.io` URL rewrites, all `3.*` versions of the `polyfill` library are supported under the `/v3` path. Additionally, the `/v2` path is also supported. If an unknown version is requested under the `/v3` path, Cloudflare will rewrite the URL to use the latest `3.*` version of the library (currently `3.111.0`).

0 commit comments

Comments
 (0)