I've seen a bit of discussion lately about Mastodon's AUTHORIZED_FETCH and DISALLOW_UNAUTHENTICATED_API_ACCESS settings and since I had a hard enough time myself figuring out what they do based on the documentation and Discord comments, I wrote up what I hope is a more approachable explanation.
https://hub.sunny.garden/2023/06/28/what-does-authorized_fetch-actually-do/