(note that I meant options not OPTIONS, since I think there are legitimate uses for having un-authed endpoints in webapps)