How to prevent direct access to CloudFront origins with custom headers and AWS WAF