Is there any way to set up CORS for r2 via api?

Is there any way to set up CORS for r2 via api?
15 Replies
Tojak
Tojak•11mo ago
can I use s3 protocol for custom domain or only http(s)?
dave
dave•11mo ago
So I implemented my own auth on a public R2 bucket, does this signed URL look sane to you?
https://azure-di-source-files.enam.ai.moda/83d6300e2bb85d71b49bedd61f19fc37?cache-control=private%2C+immutable%2C+no-transform%2C+max-age=31536000%2C+stale-while-revalidate=31536000%2C+stale-if-error=31536000%2C+s-maxage=0&expires=Thu%2C+01+Jan+1970+00:00:00+GMT&ttl=604800&verify=1711929600-AXsEtplmiIONuUwUTfXh%2BVbEtqDo4rE0kPjgyN37j6w=
https://azure-di-source-files.enam.ai.moda/83d6300e2bb85d71b49bedd61f19fc37?cache-control=private%2C+immutable%2C+no-transform%2C+max-age=31536000%2C+stale-while-revalidate=31536000%2C+stale-if-error=31536000%2C+s-maxage=0&expires=Thu%2C+01+Jan+1970+00:00:00+GMT&ttl=604800&verify=1711929600-AXsEtplmiIONuUwUTfXh%2BVbEtqDo4rE0kPjgyN37j6w=
boywonder350
boywonder350•11mo ago
Cloudflare indirectly announcing R2 events? 😃
No description
boywonder350
boywonder350•11mo ago
I didn’t know you could set up r2 events already wtf
fgggfhfjhdhfhj
fgggfhfjhdhfhj•11mo ago
Hi, can i ask u a question Its an important question though It's about people abusing the r2 dev hosting to launch phishing campagins
fgggfhfjhdhfhj
fgggfhfjhdhfhj•11mo ago
?
Flare
Flare•11mo ago
If you feel that a site is engaging in illegal or inappropriate activities, you can submit an abuse report at https://abuse.cloudflare.com/. The Trust and Safety team will review the details and reply if appropriate. You can also report the site to your relevant local authorities. Reports cannot be filed via Discord or with individual employees or Champs.
fgggfhfjhdhfhj
fgggfhfjhdhfhj•11mo ago
Do u not read
Hello, I’m Allie!
What was the question?
fgggfhfjhdhfhj
fgggfhfjhdhfhj•11mo ago
So in this specific case an abuse report wont do anything, you can not flag a site which uses r2.dev to host because it also hosts legit projects and sites. Each time their site gets reported, they just change the subdomain. Meaning it's kind of a bulletproof phishing host
Isaac McFadyen
Isaac McFadyen•11mo ago
Please keep this civil.
Hello, I’m Allie!
Well yeah, but they can also flag the account itself. And if they bypass that, there isn’t much Cloudflare can do either Other than accept reports as they come
clear
clear•11mo ago
Hi, I would like to ask if your S2 can have custom domains?
clear
clear•11mo ago
No description

Did you find this page helpful?