Background
When URL sanitization is disabled (introduced in #80), we should still implement basic security measures:
- Add basic URL validation for unsanitized redirect URLs
- Add logging when URL sanitization is bypassed
References
Requirements
- Implement basic URL validation using URL constructor
- Add warning logs when sanitization is bypassed
- Handle invalid URLs appropriately with clear error messages
/cc @DanielRivers
Background
When URL sanitization is disabled (introduced in #80), we should still implement basic security measures:
References
Requirements
/cc @DanielRivers