Access Control Bypass, Explained: Why a 403 at the Proxy Is Not Authorization
A 403 Forbidden only proves that one spelling of a request was refused. Here is how trailing slashes, path parameters, rewrite headers like X-Original-URL, spoofed client IPs and alternate methods walk past gates enforced at a proxy or router, and why the decision has to live in the application.