add disallowed header check and some comments