🛡️ Served THROUGH SecureProxypublic host legacy-app.mei-proxy.comyour IP as the origin sees it 216.73.217.25scheme httpsthe app itself is unchanged — only its DNS record points at the proxy

Security console

Every probe below is a plain fetch() from this page to this host — the same requests any part of the application would make. Run them here, then open the other door (direct vs. through SecureProxy) and run them again: the application is identical, the outcomes are not.

What the server receivedGET /headers — the rebuilt Forwarded / X-Forwarded-* headers, the X-SecureProxy-Forwarded marker; no x-api-key.
Partner API key, injected server-sideGET /partner/quote — 401 “missing” when direct; 200 “authorized” through the proxy, key never in the browser.
Try to spoof the keyGET /partner/quote with x-api-key: attacker — the proxy strips the client value and injects its own.
Admin consoleGET /admin — 200 direct; 403 through the proxy (per-API :allow-ips).
Customer profile (PII)GET /api/profile — real names, e-mail, phone, IBAN when direct; anonymized / masked through the proxy.
Burst: 15 requests in a rowGET /api/ping ×15 — all 200 direct; through the proxy the per-API rate limit (10 per 10 s per IP, shared across the proxy cluster) answers 429 to the rest.
Origin leaks the keyGET /partner/echo — a misbehaving origin reflects the credential; the proxy refuses the response (502).