This is a new one... but I just experienced that if they do GET requests via HTTP/2 they will not be challenged. Tested with NGINX 14 and 15.4 as well, the same. Anything we can do ?