another concern of mine is people dos attack from localhost or unknown origins. is it possible to on

another concern of mine is people dos attack from localhost or unknown origins. is it possible to only allow traffic from tenant website domain in workers. IG maybe I have to set this up in my api domain security WAF /?
Was this page helpful?