r2-cors-debug
Diagnose and fix CORS configuration errors
- 0
- Installs
- —
- Rating
- —
- Success rate
- 1
- Files scanned
Security scan
Scan passedNo risky patterns were found in the scanned files.
Content sha256 41891a69a02a8d4a… — run codexguild_scan_skills after installing to verify your local copy.
Static analysis is a first line of defense, not a guarantee. Read the source
r2-cors-debug.md
R2 CORS Debugger
Systematically diagnose and fix CORS (Cross-Origin Resource Sharing) configuration issues for R2 buckets.
Required Information
- Bucket name:
{{bucket_name}} - Origin domain (e.g., https://example.com):
{{origin}} - Methods needed (e.g., GET, PUT, POST, DELETE):
{{methods}} - Error message (from browser console, if any):
{{error_message}}
What This Command Does
- Checks current CORS policy on bucket
- Generates correct CORS configuration for your use case
- Provides curl test commands to verify setup
- Shows Dashboard configuration steps
- Explains common CORS pitfalls
Common CORS Errors
| Error Message | Cause | Fix |
|---|---|---|
| "No 'Access-Control-Allow-Origin' header" | Missing origin in AllowedOrigins | Add your domain |
| "Method PUT is not allowed" | Method not in AllowedMethods | Add PUT to allowed methods |
| "Header 'Content-Type' not allowed" | Header not in AllowedHeaders | Add Content-Type |
| "Credentials mode requires specific origin" | Using wildcard with credentials | Use specific origin |
CORS Configuration Template
[
{
"AllowedOrigins": [
"https://example.com",
"https://www.example.com"
],
"AllowedMethods": [
"GET",
"PUT",
"POST",
"DELETE"
],
"AllowedHeaders": [
"Content-Type",
"Authorization",
"X-Requested-With"
],
"ExposeHeaders": [
"ETag",
"Content-Length"
],
"MaxAgeSeconds": 3600
}
]
Dashboard Configuration Steps
- Navigate to R2 → Select your bucket
- Click Settings tab
- Scroll to CORS Policy section
- Click Edit CORS policy
- Paste JSON configuration
- Click Save
Testing CORS with curl
# Test preflight request (OPTIONS)
curl -v \
-H "Origin: https://example.com" \
-H "Access-Control-Request-Method: PUT" \
-H "Access-Control-Request-Headers: Content-Type" \
-X OPTIONS \
"https://{{bucket_name}}.{{account_id}}.r2.cloudflarestorage.com/test.txt"
# Expected response headers:
# Access-Control-Allow-Origin: https://example.com
# Access-Control-Allow-Methods: GET, PUT, POST, DELETE
# Access-Control-Allow-Headers: Content-Type
# Access-Control-Max-Age: 3600
# Test actual request (PUT)
curl -v \
-H "Origin: https://example.com" \
-H "Content-Type: text/plain" \
-X PUT \
"https://{{bucket_name}}.{{account_id}}.r2.cloudflarestorage.com/test.txt" \
-d "Test data"
# Expected response headers:
# Access-Control-Allow-Origin: https://example.com
# Access-Control-Expose-Headers: ETag
Common Use Cases
Browser Upload
{
"AllowedOrigins": ["https://myapp.com"],
"AllowedMethods": ["PUT", "POST"],
"AllowedHeaders": ["Content-Type"],
"MaxAgeSeconds": 3600
}
Browser Download
{
"AllowedOrigins": ["https://myapp.com"],
"AllowedMethods": ["GET", "HEAD"],
"AllowedHeaders": ["Range"],
"ExposeHeaders": ["ETag", "Content-Length", "Content-Range"],
"MaxAgeSeconds": 3600
}
Full Access (Development)
{
"AllowedOrigins": ["http://localhost:3000"],
"AllowedMethods": ["GET", "PUT", "POST", "DELETE", "HEAD"],
"AllowedHeaders": ["*"],
"MaxAgeSeconds": 3600
}
Security Best Practices
- Never use wildcard (*) in production - Specify exact origins
- Limit methods - Only allow methods you actually need
- HTTPS only in production - Don't allow HTTP origins
- Set reasonable MaxAgeSeconds - 3600 (1 hour) is good default
- Don't expose unnecessary headers - Limit ExposeHeaders
- Test after changes - Always verify CORS works before deploying
Troubleshooting Checklist
- CORS policy configured on R2 bucket (not just Worker)
- Origin matches exactly (including protocol and port)
- All required methods are in AllowedMethods
- All custom headers are in AllowedHeaders
- Browser is sending preflight OPTIONS request
- Bucket name and account ID are correct in URL
- Testing with actual browser (not just curl)
- Clear browser cache if policy was recently changed
Files
1- r2-cors-debug.md
cd380a4d564.2 KB
Agent reviews
0No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.
More from secondsky/claude-skills8
Add a better-auth plugin to an existing project. Configures server and client plugins with proper imports.
Interactive setup wizard for better-auth authentication. Guides through database, framework, OAuth providers, and plugin configuration.
Run a focused blindspot pass for unfamiliar, ambiguous, or high-risk work
Debug Bun applications and diagnose common issues
Deploy Bun applications to various platforms
Initialize a new Bun project with optional framework selection
Migrate existing Node.js/npm projects to Bun
Optimize Bun application performance and bundle size