If your client supports NIP-42 AUTH, consider adding an option to turn it on/off per individual relay.
I think there are many great use cases for AUTH (protecting some/all REQs) but always responding to any AUTH from any relay can exacerbate the user/relay privacy problem.