I think you're confused. The only thing blocked would be client side fetch. You need to find another way to protect everything else.
Exactly what I need. My API is public I just don’t want someone other than my own website to consume it. Is it that hard to understand?
They just want to prevent hotlinking/leeching.