I noted that, even if i enable auth 'everywhere', the
/?asset=index.js
/?asset=index.css
/?asset=favicon.ico
are working without giving a Forbidden 401 error.
May be it would be 'more secure' to include all replies into the general authentication process?
Why are they excluded now?