Safety
A bad destination is skipped, and a Super User stays in the administrator.
- A destination that points at the login page, or at the same page they are already opening, is skipped.
- An external address is refused unless the host policy allows it.
- A Super User signing in to the administrator is not sent to the public site.
- Add
rol=noto a login or return address when that single request should skip these rules. - Cookie and passwordless logins are remembered as seen, and they are not redirected by an after-login rule.