Thanks for your answer, but it is the connection to the OData source that is concerning me, not protecting the front end, which, as you've suggested, has some pretty straightforward and well-known 'solutions'.
I'm interested in ways to protect the connection to the data, given a cloud OData...