Skip to content

Conversation

@arturobernalg
Copy link
Member

LaxRedirectStrategy now overrides isRedirectAllowed to always return true so that redirects are followed even when sensitive headers like Authorization are present.

… Override isRedirectAllowed(...) to always return true, ensuring LaxRedirectStrategy follows redirects regardless of Authorization or other sensitive headers.
@arturobernalg arturobernalg requested a review from ok2c July 15, 2025 13:30
@wherka-ama
Copy link

@arturobernalg : it's really refreshing to see how quickly you've managed to sort out this regression.

I'm sure many people appreciate your efforts! Thanks a lot ❤️

Kudos for @dani0600 for reporting it as well.

@dani0600
Copy link

Thanks a lot, @arturobernalg, for taking care of this so quickly! We really appreciate your responsiveness and the continued effort you put into improving these tools — it benefits so many of us!

@dani0600
Copy link

Included some more tests here: #677 that could be interesting for you

@arturobernalg
Copy link
Member Author

Included some more tests here: #677 that could be interesting for you

@dani0600 cherry picked 6fcd35c

@arturobernalg arturobernalg merged commit e907ae0 into apache:master Jul 16, 2025
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants