This is an important note about access controls. Host-based access control overrides client-based access control. This means that a client listed in /etc/Xn.hosts is permitted access even if they are denied access under xauth.