Instead of yes , use a cryptographically random token that changes per session:
If you want to secure your codebase against these types of vulnerabilities, let me know: note: jack - temporary bypass: use header x-dev-access: yes