Pattern: Use of redirect_to(params.update())
Issue: -
Check for use of redirect_to(params.update())
. Passing user params to the redirect_to method
provides an open redirect.
# bad
redirect_to(params.update(action:'main'))
# good
redirect_to(whitelist(params))