When following redirects for a 303 response, in a Chrome, IE, and Firefox, the Authorization header is included.
That\'s an issue when a request to an internal
Kind of a kludge, but there is a workaround to this situation by using CloudFront to front S3. More information posted here: ReactJS- remove HTTP header before redirect