{"version":"2.1.235","anchor":"frame-host-api-requests-no-longer-follow-redirects","canonical_anchor":"frame-host-api-requests-no-longer-follow-redirects","heading":"Frame-host API requests no longer follow redirects","tier":"notice","area":"Internals","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.235\/e\/frame-host-api-requests-no-longer-follow-redirects","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.235","markdown":"### Frame-host API requests no longer follow redirects\n\nRequests to the frame API host no longer follow redirects by default\n\nRequests to the \"frame\" host are now issued with `maxRedirects: 0`, and the shared request helper defaults `maxRedirects` to 0 whenever the target host is \"frame\". Previously such requests followed redirects by default, which could silently forward credentials to a redirect target.\n\n- Area: Internals\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 1\/5"}