It would be a security improvement if clients could be made to authenticate optionally, based on a flag provided when the proxy started up.
Something like --client-auth, which then causes the proxy to require credentials from clients that match those used to connect to Astra.