Earlier quoted context omitted.
Or they'll (the site operators using Cloudflare proxy) make ill considered firewall rules like "If not Chrome, require security check".
What's your point? You can configure this in Nginx too
Even if it does, the point of Cloudflare's WAF is to avoid the traffic touching the origin if the security check doesn't succeed, so any nginx solution isn't really providing the same value.