Falls back to / for anything that isn't a single-slash-prefixed relative path. Locks out protocol-relative (//evil.com), absolute (https://evil.com), and javascript: redirects. 7 tests cover the full attacker matrix.
Falls back to / for anything that isn't a single-slash-prefixed relative path. Locks out protocol-relative (//evil.com), absolute (https://evil.com), and javascript: redirects. 7 tests cover the full attacker matrix.