Requests to the "frame" host are now issued with maxRedirects: 0, and the shared request helper defaults maxRedirects to 0 whenever the target host is "frame". Previously such requests followed redirects by default, which could silently forward credentials to a redirect target.
Frame-host API requests no longer follow redirects
Requests to the frame API host no longer follow redirects by default
You'll noticeTier: how much it should matter to you
2Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
InternalsArea: what it touches
Bug FixesKind: in v2.1.235,
Bug FixesSection of the release