Restricting the list of possible navigation domains is important to avoid the possibility that attackers might redirect a user???s application session to a domain that they can control, so that they can perform phishing attacks or other harmful activities.