The policy now attaches to the application itself, not to the hostname. Which means it also covers the preview URLs somebody always forgets.
- On 14 August Cloudflare announced attaching Access policies directly to Workers applications.
- The policy applies to every address of the app, including the service and preview URLs.
- It can be switched on account wide, so every new app starts locked.
Anyone who has shipped a quick internal tool knows where it leaks. Not through the main address. Through the preview URL you gave one colleague and forgot.
The difference is in the order of things. Until now you ship the app and then remember to fence it. Now it is born fenced and you decide what to open.
We keep a client area and internal panels behind exactly this kind of door. If you have a tool running on a quick fix, this is half an hour of work today.