The current authentication scheme works without creating a public download endpoint for a private bucket as in the B2 official blog. On the contrary, if the existing authorization header gets duplicated in the Cloudflare Workers script, one might receive 401 Unauthorized errors.