Which policy takes precedence when overlapping Allow and Bypass rules are applied to a single application path?
24.5K reputation · 21 Feb 2022, 06:18 UTC
Cloudflare Access utilizes a set of policies to manage authentication layers for internal resources. When configuring these policies, administrators can define Allow rules to restrict access to specific identity providers and Bypass rules to permit traffic without authentication for certain criteria, such as specific IP ranges.
A design uncertainty arises when a single application path is targeted by both an Allow policy and a Bypass policy that both evaluate to true for a given request. Because the security goal is to prevent accidental public exposure, the resolution order of these overlapping rules is critical.
Does Cloudflare prioritize the Bypass rule over the Allow rule in this scenario? If so, what is the documented behavior for ensuring that an Allow requirement remains the primary gatekeeper for a specific path?