Captured 2026-07-22 04:02:54 UTC · server-side from the public-safe controls endpoint
1 / 4WAF
Stop hostile traffic at the edge
Inspect the active custom-rule branch and its isolated attack-lab target.
Proof cue: the edge returns 403 before the Worker can return application JSON.