Escape URLs in text/plain res.redirect response
Escape the URL printed by res.redirect using URL encoding. This prevents some browsers (primarily old versions of IE) from attempting to sniff the Content-Type and evaluate it as HTML, which causes a cross-site scripting vulnerability.
G
Greg Methvin committed
ea5e254c7d620c41e515f30991dedc1d56097dc5
Parent: c70db96