CORS is a client-side thing, so nothing that can be used for authorization. But: PUT requests would
CORS is a client-side thing, so nothing that can be used for authorization. But: PUT requests would never go through your custom or r2.dev domain, so this won't be an issue here. For PUT requests you talk to the s3-compatible endpoint ({id}.r2.cloudflarestorage.com).





