Added an HTTPS localhost in the whitelisted redirect URL list for debugging purposes
If the signin window is not the top most window (i.e., iframe), it will use postMessage() with the target origin being the redirectUrl. Useful for embedding in iframes.
Changes: