Open pyrooka opened 11 months ago
This commit modifies the Python core so that it will include "safe" headers when performing a cross-site redirect where both the original and redirected hosts are within IBM's "cloud.ibm.com" domain.
I've converted this PR to to draft, to prevent merging it before the necessary CISO approvals.
@padamstx I've made the tests more robust, but it may be overkill...:) let me know what you think!
This commit modifies the Python core so that it will include "safe" headers when performing a cross-site redirect where both the original and redirected hosts are within IBM's "cloud.ibm.com" domain.