Deprecating the __cfduid cookie
blog.cloudflare.com
blog.cloudflare.com
Cloudflare's default behaviour upon detecting a "malicious bot" is to serve a captcha for these requests which will break your site. You should probably only be using this for top-level navigation where the captcha will be visible to use user.
This is a bit complicated for API endpoints, in this case all of your JS must be ready to receive an HTML captcha page instead of whatever your API should return. It is unclear what to do in this case. Send the request again? Reload the page and hope that the user gets a captcha on the HTML?
I've had Google down-rank my pages because Cloudflare served a captcha instead of the CSS file and Google decided that they weren't "mobile friendly".
Side-note: This is extra painful for https://cloudflare-ipfs.com as you can't disable security since Cloudflare has picked the settings, it makes that service unusable for hosting website assets.
Ref A: 61309E4A8D95406182A0470174AF6ECC Ref B: YMQ01EDGE0515 Ref C: 2020-12-13T12:23:56Z
ackers in my PC
They could describe better why the cookie is not needed anymore