Lacking any other permissioning mechanism, we must simply reject unauthenticated HTTP-scry requests for now.