> Simple `Authorization` header should be enough.
Cool so now you can’t fetch non-public S3 objects in the browser unless you’re fetching over Ajax? What’s in the Authorization header - an API key? There’s a reason services serious about security don’t do it like that anymore.