There have been recent discussions around how connection allowlists should intervene on redirects, including in the WebAppSec CG meeting this week (notes linked here). Given that if allowlisted ...