A redirect target is taken from unvalidated input, enabling phishing.
Redirect only to allowlisted destinations; never reflect raw URLs.