✦ Continue with Google
AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

Supabase Storage S3 API Returns Transformed HTML Body, Causing Content-Length Mismatch In Rclone

Supabase Storage S3-compatible API responses for HTML objects are being modified by Cloudflare Email Address Obfuscation, causing a mismatch between the object metadata size and the actual response body length, breaking tools like rclone.

highConfidence 85%Supabase Storage

Origin Analysis

Supabase Storage S3 API does not set response headers to prevent Cloudflare from applying HTML transformations (Email Address Obfuscation). The Content-Type of stored HTML objects remains text/html, triggering Cloudflare's edge transformation, which rewrites mailto links and removes HTML comments, thereby changing the body size.
1. Upload an HTML file containing `<a href="mailto:test@example.com">test</a>` to Supabase Storage. 2. Configure rclone with Supabase S3 endpoint using `--s3-list-version 2`. 3. Run `rclone copyto supabase:dev.html ./dev-copy.html --s3-list-version 2`. 4. Observe failure with error: `net/http: HTTP/1.x transport connection broken: http: ContentLength=37322 with Body length 37473`. 5. Use `rclone cat supabase:dev.html > ./dev-copy.html --s3-list-version 2` and inspect the downloaded HTML; mailto links are transformed to `/cdn-cgi/l/email-protection#...`.

Fixing Code Block

Edge Case Audit

Forcing `Content-Type: application/octet-stream` may cause browsers to download HTML files instead of rendering them when accessed directly via the S3 endpoint. If browser preview is required, consider using the `response-content-type` query parameter or only apply the `Cache-Control: no-transform` header. Rollback requires removing the middleware or conditionally omitting the Content-Type override.

Ecosystem Topology