Do Not Trust a User Identity Header Just Because Caddy Forwarded It
Identity headers are safe only when clients cannot inject equivalent values around the auth boundary.
Identity headers are safe only when clients cannot inject equivalent values around the auth boundary.