Some notes about it
- It should be specifiable on the redirect endpoint, ie. not hardcoded in configuration
- It should not allow redirects to any other hosts, so many just
&path=/account
I saw this as a ToDo on Docs - Authentication. I couldn't find an existing dedicated issue for this so decided to create one