g[] allowedDomains =34 PropsValues.REDIRECT_URL_DOMAINS_ALLOWED;35 I didn't test this patch but it seems pretty logical to assume that whatever the redirect.url.security.mode is set to, if there is a company or group using an address as it is virtual host it should be safe.What do you think?