>> Verify the Host and Origin request headers
>
> Yes. You should be doing that.
(Author here.) If I remember correctly, his browser of choice predates the Origin header.
(Author here.) If I remember correctly, his browser of choice predates the Origin header.
In general though the whole tone of parent of “I am owed access to someone else’s computer system on my and my terms alone” just doesn’t jive with me. It’s also not remotely comparable to Cloudflare’s approach of sitting in the middle snd then appropriating end-user compute resources without their consent to fuel their business.