Troubleshooting
Domain Protection Blocking
Your script is blocked by domain protection rules.
Symptom
A deployed script returns a 403 (Forbidden) response when loaded from your site, but works when accessed directly in a browser tab or from localhost. The browser console may show Failed to load resource: the server responded with a status of 403.
Likely Causes
- Domain not in allowlist: The domain serving the page is not in the project's domain protection list. Only domains explicitly added to the list (plus
localhost) are permitted. - Wildcard mismatch: You added
*.example.combut the page loads fromexample.com(no subdomain). Wildcard patterns match subdomains, not the root domain itself. - Propagation delay: You added the domain less than 60 seconds ago. Domain rules are stored in Cloudflare KV and take approximately 60 seconds to propagate globally.
- Referer header missing: The browser does not send a
RefererorOriginheader (e.g., due toReferrer-Policy: no-referreron the page). Without a referrer, the Worker cannot determine the requesting domain and may block the request. - Wrong domain format: The domain was entered with a protocol (
https://example.com) or a trailing slash instead of just the domain name (example.com).
Checks
- Open the Protection panel in the Odyn editor (Protection icon in the left activity bar).
- Verify the domain serving your page is in the list. Check for exact matches and wildcard coverage.
- Check the page's
Referrer-Policyheader. Open the Network tab, find the HTML document request, and check theReferrer-Policyresponse header. If set tono-referrer, the browser suppresses theRefererheader on script requests. - Check the time since you last modified the domain list. If it was within the last 60 seconds, wait for propagation.
- Open the CDN URL directly in a browser tab (not embedded on a page). If it loads successfully, the block is domain-protection-specific.
Fixes
Add the correct domain
- Open the Protection panel.
- Add the exact domain:
example.com(no protocol, no trailing slash). - If you use subdomains, add both
example.comand*.example.comto cover the root and all subdomains. - Wait approximately 60 seconds for propagation.
- Reload the page.
Fix wildcard patterns
| Pattern | Matches | Does not match |
|---|---|---|
example.com | example.com | www.example.com, staging.example.com |
*.example.com | www.example.com, staging.example.com | example.com |
| Both entries | All of the above | Other domains |
To cover all cases, add both the root domain and the wildcard.
Fix referrer policy
If your page uses Referrer-Policy: no-referrer, the CDN Worker receives no domain information and cannot validate the request. Options:
- Change the referrer policy to
originorstrict-origin-when-cross-origin(both send the domain without the path). - If you cannot change the referrer policy, consider whether domain protection is necessary for this deployment.
Verify on localhost
localhost is always allowed. If the script loads on localhost but not on your domain, the issue is in the domain list, not in the script itself.
What to Capture for Escalation
- The CDN URL being blocked.
- The domain serving the page (from the browser's address bar).
- The domain protection list from the Protection panel.
- The
Referrer-Policyheader from the page's HTML response. - The HTTP status code and response body from the blocked CDN request.
- Whether the CDN URL loads when opened directly in a browser tab.