After OIDC login, if the redirect targets a trust center custom domain, the callback now redirects through a session-transfer endpoint on that domain. The endpoint verifies an HMAC-signed, time-limited token and sets the session cookie on the custom domain before redirecting to the final URL. The continue URL is bound into the signed token payload to prevent open-redirect attacks via parameter tampering. Signed-off-by: Bryan Frimin <bryan@getprobo.com>
2.3 KiB
2.3 KiB