Skip to content

security: strip Authorization and Cookie headers on cross-origin redirects - #2182

Open
insaf021 wants to merge 1 commit into
googleapis:mainfrom
insaf021:security/redirect-credential-leak
Open

security: strip Authorization and Cookie headers on cross-origin redirects#2182
insaf021 wants to merge 1 commit into
googleapis:mainfrom
insaf021:security/redirect-credential-leak

security: strip Authorization and Cookie headers on cross-origin redi…

664eb83
Select commit
Loading
Failed to load commit list.
Google CLA / cla/google succeeded Jul 31, 2026 in 9s

✅ All contributors are covered under a CLA with Google

See https://cla.developers.google.com/ for more info about Google's Contributor License Agreement (CLA).

ℹ️ Googlers: Go here to view more details and manage scans for this pull request.

Details

The following contributors were found for this pull request:

664eb83 Author: @insaf021 <i***f​@digiscrypt.com>

(Only the first commit for a unique contributor is listed.)