Researching Cloudflare WAF bypass techniques. IP allowlists on origin seem ineffective, given that Cloudflare Workers are on those same PoPs and can make web requests from the same IP ranges? #infosec