Insights / Technical notes
Security headers for Cloudflare Pages static assets and Functions
Distinguish static Pages responses from Functions and review _headers, CSP, and the current site configuration.

Table of contents
If CSP or cache settings appear ineffective on Cloudflare Pages, first identify whether the URL returns a static asset or a Functions response. Select the configuration location using Cloudflare Pages: Headers, then check error responses as well as successful ones to find gaps after adding APIs.
This article originally recorded the March 2026 move from a Worker-based contact form to an external form and static Cloudflare Pages delivery. The site has since changed. As of September 2026, Acecore’s corporate site uses Pages Functions alongside static pages for contact, comments, search, AI assistance, and CMS APIs. The earlier choice is historical context; the header boundary below still matters.
Distinguish static responses from Functions
public/_headers applies to static asset responses served by Pages. Cloudflare explicitly says these rules do not apply to responses generated by Pages Functions, even when the URL pattern matches. Set required CORS, caching, and security headers on a Function’s Response instead.
Do not assume that writing _headers secures every page and API. Check the actual response headers for static HTML and /api/* separately.
- Static asset response Configure with _headers; inspect the response Pages serves.
- Function API response Set headers on the Function Response; inspect API responses separately.
Where to inspect the current configuration
The current _headers file revalidates HTML while caching hashed _astro/ assets for longer. The CMS has a separate CSP, and X-Frame-Options is SAMEORIGIN. Do not copy the old article’s form-action https://ssgform.com, one-hour HTML cache, or DENY as current values.
Inspect Pages Functions for dynamic routes. Review CSP sources against scripts, images, frames, and network requests actually used by your own site rather than transplanting Acecore’s policy unchanged.
Deployment and verification
The corporate site publishes main through GitHub-connected Cloudflare Pages. The current Node version is recorded in .node-version; CI builds with npm run build from package.json. The March 2026 table saying “Node.js 22 / npx astro build” is historical.
Check the PR preview, main build, production Pages deployment, and public URL separately. Consult Cloudflare’s Pages headers documentation for the current platform behavior.