What about the startsWith('/') part? This suggests previous patch may have failed to block absolute paths. Jamie, you seem to have some reproducer available, can you check that?
What about the startsWith('/') part? This suggests previous patch may have failed to block absolute paths. Jamie, you seem to have some reproducer available, can you check that?