Disable disclosing application names to unauthenticated requests?

I’ve set up an application in ZT and enabled the App Launcher. When I visit my team dashboard teamname.cloudflareaccess.com, I can log in and see the app listed - cool.

When I visit the application URL directly, e.g. appname.mydomain.com, I am dutifully prompted to login to Google if I wasn’t already, and then am forwarded on to the app. However that login page shows the application name - which I’d prefer not to have disclosed to unauthenticated visitors.

Is there any way of disabling displaying the app name to unauthenticated requests?

Some other details if relevant:

  • application is self-hosted, connected to Cloudflare via cloudflared
  • using Google for SSO, allowing only specific Google accounts by email address
1 Like

Bump.

I’d love to see this option as well, I think this a needed security addition. I don’t want to expose anything about my internal network publicly, and I don’t think this counts as security though obscurity.