Service
Liveness check.
Diagnostics: shows exactly what reached the origin — method, headers, cf-ray, body. If an attack was blocked at the edge, this never fires.
Catalog (public)
List all customers (fake data).
Fetch one customer by id.
Schema validation demo (API Shield)
Valid payload — passes schema and reaches the origin (201 Created).
After enabling API Shield schema validation, attacks like the one below are blocked at the edge with 403 — Security Events shows the rule.
Malformed payload — invalid tier and string credit limit. Today the origin rejects it (422); with API Shield it is blocked at the edge before this server.
Auth flow (JWT)
Issues a demo JWT (HS256). The token is kept in your browser and used by the orders calls.
Protected route — requires a valid bearer token.