Steps to reproduce
Try to import RTC Southern Nevada's GTFS feed in production, or request the proxy directly:
$ curl https://map.lasvegasfortransit.org/api/gtfs/rtc
{"error":"RTC GTFS feed unavailable (403)","upstreamRay":"a285a1e5b942ac04-LAS"}
Expected behavior
The Worker should download the feed and complete the import. The same feed URL returns 200 from ordinary client connections.
Actual behavior
RTC's server returns a live 403 to the Worker, so the import is unavailable to every user. The remaining meaningful difference is the request origin: TransitMapper runs on Cloudflare, and RTC's site is also behind Cloudflare. RTC's WAF appears to reject the Cloudflare-originated request regardless of its headers.
Additional context
The application-side causes we checked do not explain the failure. The feed's current size and processing time remain within the import deadlines. Adding a User-Agent in v0.3.0 did not change the response. Since v0.3.1 stopped caching upstream errors, the changing cf-ray value confirms each refusal is current.
The practical next step is either to ask RTC Southern Nevada to allow the request, using Ray a285a1e5b942ac04-LAS to find it in their logs, or to choose and credential a feed mirror such as Mobility Database (mdb-2351) or Transitland.
Steps to reproduce
Try to import RTC Southern Nevada's GTFS feed in production, or request the proxy directly:
Expected behavior
The Worker should download the feed and complete the import. The same feed URL returns 200 from ordinary client connections.
Actual behavior
RTC's server returns a live 403 to the Worker, so the import is unavailable to every user. The remaining meaningful difference is the request origin: TransitMapper runs on Cloudflare, and RTC's site is also behind Cloudflare. RTC's WAF appears to reject the Cloudflare-originated request regardless of its headers.
Additional context
The application-side causes we checked do not explain the failure. The feed's current size and processing time remain within the import deadlines. Adding a
User-Agentin v0.3.0 did not change the response. Since v0.3.1 stopped caching upstream errors, the changingcf-rayvalue confirms each refusal is current.The practical next step is either to ask RTC Southern Nevada to allow the request, using Ray
a285a1e5b942ac04-LASto find it in their logs, or to choose and credential a feed mirror such as Mobility Database (mdb-2351) or Transitland.