Access-control lists
Country, IP, referrer, and user-agent policies support two modes:- Allow all except listed: block the listed values.
- Deny all except listed: allow only the listed values.
Signed URLs
Secure-key protection requires a signing key and token type. Token type can include or exclude the client IP from validation.Defense in depth
- Validate authorization at the application origin.
- Keep origin services patched and restrict direct access where possible.
- Use HTTPS and origin certificate validation.
- Avoid caching denial or authenticated responses under a shared key.
- Review ACL values after network, vendor, or workforce changes.