Block requests where the query field is not in the allowed list
Block requests where the query field is not in the allowed list