I don’t know why you straight up assumed that we are using some Cloudflare things to do this. But anyways, there is indeed a security system tampering with PWAs, and cannot be disabled.
By far only one user has worked out a workaround, but we still didn’t know how it is done.