You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
buildRedirectRequest() copies every header of the previous request onto the next one, with no origin check
the Fetch standard drops Authorization when a redirect changes origin, and native fetch does; the manual redirect loop does not, so a token sent to one host is handed to whatever host it redirects to
relevant wherever sendRequest carries credentials and the redirect target isn't trusted
buildRedirectRequest()copies every header of the previous request onto the next one, with no origin checkAuthorizationwhen a redirect changes origin, and nativefetchdoes; the manual redirect loop does not, so a token sent to one host is handed to whatever host it redirects tosendRequestcarries credentials and the redirect target isn't trusted@crawlee/http-client@4.0.0-beta.165, Node 26.8.2.