Thanks for the explainer.
And yep, this had crossed my mind - did wonder whether privacy rules are absolutely required, when you visit most of the videos online of people teaching privacy rules the message is generally “you must have privacy rules setup before going into production, no ifs or buts”.
I did check devtools on a fair few parts of the app and at no point can my test user see information that they shouldn’t be allowed to see.
And presumably someone can’t manually send a HTTP post to
https://%appname%/version-test/elasticsearch/msearch to request information they shouldn’t ordinarily be able to see, these requests need to come from the elements I assume.