While I don’t understand the use case, that’s an interesting idea. I’ve seen requests to auto disable after the attack has subsided in the feature request category, https://community.cloudflare.com/c/feedback/feature-request/30, but not one for a time period. I suspect you could have a worker that would enable and then disable after x period of time.