Is this issue already tracked somewhere, or is this a new report?
Current Behavior
This is a follow-on from #864. Because we have a hard-coded list of "allowed" hosts, when a valid host is not in the allow list, a valid Authorization header will be erroneously stripped, causing auth failure.
For a potential solution, see #864 (comment)
Expected Behavior
The Authorization header is not stripped.
Steps To Reproduce
See #864
Environment
Additional Context
No response