authorization
header is not deleted on redirects to third party origins
#872
Labels
bug
Something isn't working
Bug Description
Security flaw.
Reproducible By
Expected Behavior
The
authorization
header should be deleted when redirecting to third party origin.Environment
The text was updated successfully, but these errors were encountered: