The session transfer handler was blindly redirecting to the continue URL from the signed token. Use saferedirect with a trust center domain check to prevent open redirects, and only trigger session transfer for known trust center custom domains instead of any non-base-URL host. Signed-off-by: Bryan Frimin <bryan@getprobo.com>