To avoid a situation where other things running on localhost can control the server, could you verify where requests are coming from? Potentially via e.g. the `Origin` header?