ALLOW Traffic is reaching the origin through AFD.
/old-page REDIRECT/oldapi REDIRECT/new-page (via AFD rule)/api.html (via AFD rule)http:// – should 307 → https:// (via AFD HTTPS redirect)?id=1' OR '1'='1 → WAF should return 403 BLOCK?q=<script>alert(1)</script> → WAF should return 403 BLOCK