Hi Zhao, Thank you for your reply. I now understand how [AlwaysAllowedUrls] works and where the query string check is still performed on the allowed Urls. To clarify, here is what I would like to achieve. For instance, I would like the following 'url+query string' to be valid: http://www.domain...