Try using a modern well-known browser, like Chrome
Try using a modern well-known browser, like Chrome
cf-access-client-secret from being passed to my Worker?
cf-access-client-secret wasn't supposed to be exposed in the first place. I had a race condition somewhere I think, where I added the token before the rule.cf-access-jwt-assertion now 


12345a6c.demo.pages.dev, 12345a6c.demo2.pages.dev, demo.pages.dev , 12345a6c.demo2.pages.dev , demo2.pages.dev, etc.12345a6c.demo.pages.dev?
custom dropdown just lets you choose between free-text and the domain picker from before
*.workers.dev is a no-no

*.pages.dev. 

*.demo.pages.dev and one for demo.pages.dev.*.demo.pages.dev doesn't match demo.pages.dev.With this configuration and Includes subdomains enabled, incoming requests to http://a.example.com/about and http://a.b.example.com/about would also match, in addition to the specified domain with no subdomain (https://example.com/about).