Well, not an issue for me though. Why not use your own headers?
Well, not an issue for me though. Why not use your own headers?
Ultimately, since I have customers relying on the standard Date header within the signed data, and they're in a variety of environments (some not easily updated), I'm unwilling to introduce a breaking change like this simply to keep CF enabled. I ultimately had to disable CF to resolve the issue, and am looking to fully migrate away from the platform soon.
Honestly, it just seems like odd behavior for CF to even do this and I thought I'd give others a heads up. I know startups like Cognito [0] follow that signature spec too, so this could effect other startups as well which implement HTTP response signatures. Especially if it eventually becomes standardized...