But that still doesn’t prevent a malicious actor from just setting the origin header to one of your

But that still doesn’t prevent a malicious actor from just setting the origin header to one of your tenant domains, bypassing the block
Was this page helpful?