hi @kchaura ,Ideally, the best practice or the recommendation is to deny every thing and allow specific paths (e.g. DAM, etc.clientlibs, content etc.) which are needed as mentioned in the below example/0001 { /type "deny" /url "*" }
## Allow extensions for dam
/0002 { /type "allow" /extension '(g...