Forward Auth Works, Then the Browser Gets Stuck in a Login Redirect Loop
Auth gateways need the original request context to decide and redirect correctly.
Auth gateways need the original request context to decide and redirect correctly.
Identity headers are safe only when clients cannot inject equivalent values around the auth boundary.