Also don't permit everything, use a secret for the permitted URLs
Also don't permit everything, use a secret for the permitted URLs