Making the proxy serve pages.
WHY YOU MIGHT
By default every page request reaches us and runs your application. Caching HTML at Cloudflare means most requests never reach us at all.
That is a substantial speed and resource improvement, and it carries real risk.
THE RISK
Serving one visitor's content to another. On a shop, showing a customer someone else's cart or account page.
That is why HTML is not cached by default.
DOING IT SAFELY
Create a rule caching HTML, with explicit exclusions:
Cart, checkout and account pages The admin area Any page showing personalised content Anything behind a login
BYPASSING FOR LOGGED-IN VISITORS
Configure the rule to bypass cache when a session cookie is present.
Without that, a logged-in visitor's page can be cached and served to everyone.
TESTING
Thoroughly, in a private window and while logged in, on a shop especially.
Add to cart, check out, and confirm nothing leaks between sessions.
THE SAFER ALTERNATIVE
Server-side caching with proper exclusions, which understands your application.