Sadly Cloudflare seems to treat client certificates as an optional nifty feature as opposed to the critical feature that it is. And even some of the settings that look secure aren’t:
https://medium.com/@ss23/leveraging-cloudflares-authenticate...
Authenticated origin pulls should not be “useful”. They should be on and configured securely by default, and any insecure setting should get a loud warning.