@joeyh once again the ocap people are right that "perimeter security is eggshell security"
(This is also why CORS is a failed security model)