Forward a whitelist of headers that you specify. CloudFront caches your objects based on the values in all of the specified headers. I had to whitelist a few things in Firefox where I run NoScript to get it to work. That problem is being worked around by putting NoScripts domains, Google AdSense and a few others on NoScripts default whitelist. With the hls.js flowplayer plugin, I had to add a CORS rule on the S3 bucket, whitelist the origin header in cloudfront and add xhrSetup to the flowplayer config. As of May 2009, the default NoScript whitelist contained some of the sites of the extensions developer, some domains of Google. Using NoScript Suite Lite can be a quick additional security measure that could help to prevent a disaster in the future.

Within CloudFront, we need to set a few things to get Laravel working properly. There are two main places to make adjustments: Cookie Whitelist. For each site listed by NoScript, you get the option to allow it temporarily or permanently. Allow site - whitelists the site so that it is allowed to run scripts locally or as a third-party connection. To tell NoScript to ignore specific sites, you need to add them to a whitelist. If you set up the behavior in cloudfront to forward the Origin header using the whitelist, cloudfront will cache separate copies for http and https, but both will work at the same time. Whitelist Headers: (This is the most important step, you need to select Origin header and add it to the whitelist in the right column). By doing this, CloudFront will cache properly. NoScript also provides the most powerful anti-XSS and anti-Clickjacking protection ever available in a browser. NoScripts unique whitelist based approach allows scripts only from trusted sites. Add these addresses to noscript whitelist to allow cloudfonts scripts globally.

By default, NoScript trusts a handful of domains, because blocking every script ever would break too much of the internet. The first problem is that the whitelist has a little cruft. NoScript is a great plug-in, both for security and for ad blocking. However, Ive found its whitelist can be challenging to manage. Even if you whitelist a domain, new scripts can be added to that domain, or existing ones could be changed. For example, if you allow one site to run scripts from cloudfront.net, every site can. It seems to only allow all scripts if theyre served from the same domain, but anything else (e.g. cloudfront, google-analytics, etc) still get blocked. When noscript is initially installed a predefined whitelist is included of which cloudfront.net is included. The guide explains why you want to check the NoScript whitelist, and how to manage sites that you find in it. Instead, CloudFront sends every request to the origin. Forward a whitelist of headers you specify: Specify the number of headers that you want CloudFront to base caching on. By adding these sites to the NoScript Whitelist, that functionality is restored. Over time, less and less websites show up with blocked content. cloudfront.net is not a web site. It is a redirect to Amazon CloudFront. If you are using Firefox try the NOSCRIPT plug-in.