Hey everyone, I'm trying to help my team fix a big problem with Cloudflare's Managed Challenge. We have it set up on our checkout page, but we're seeing a huge drop in successful orders. Our analytics show a lot of users bouncing right when the challenge appears, even though they seem like real people.
We're using Terraform to manage the WAF rules. Here's the basic rule we have for our checkout path:
```hcl
resource "cloudflare_ruleset" "checkout_challenge" {
zone_id = var.zone_id
rules {
action = "managed_challenge"
expression = "(http.request.uri.path contains "/checkout/")"
description = "Challenge on checkout"
}
}
```
Is this too aggressive? Should we be using more specific firewall expression to avoid challenging legit returning customers? Any tips on fine-tuning this? I'm worried our one-size-fits-all rule is the issue.